
#45
Theo Marczak
WP Taverm Jukebox with Alex Harlan
Episode
#45 – Theo Marczak on Testing Whether Secure Hosting Matches the Marketing
Theo Marczak spent a year poking at WordPress hosts that sell “secure hosting.” Most WordPress-specific issues still slipped through. We unpack what the tests showed, and what buyers should ask next.
by Alex Harlan·July 29, 2026·with Theo Marczak
Listen
Search for WP Taverm in your podcast player, or copy the feed URL:
https://wptaverm.com/feed/podcast/“Secure hosting” is a landing-page phrase. Theo Marczak treated it like a claim that could be tested. Over several months he ran WordPress-specific probes across a set of popular hosts: outdated PHP, world-writable directories, weak default users, and plugin supply-chain patterns that a generic WAF rarely sees.
The headline is uncomfortable. Marketing pages promised isolation and malware defense. In practice, most WordPress-shaped problems still reached the application. Network-layer protection is not the same as knowing how wp-config, cron, and the plugin installer behave.
Theo is careful not to turn this into a host-shaming list. The point is a buyer’s checklist: Who applies core updates? How fast do they patch a popular plugin CVE? Can you see the PHP version without opening a ticket? Is staging a copy or a prayer?
We close on what “good” looks like in 2026: automatic core and PHP upgrades with a rollback path, malware scanning that understands WordPress file layout, and an abuse desk that talks to other hosts. Security is a practice, not a badge.
Comments
Matthew Collins · August 2, 2026
Appreciate the reminder that a WAF sticker is not a WordPress hardening policy. The plugin-update question is the one I’ll start asking.







