{"id":2686,"date":"2026-09-02T14:00:00","date_gmt":"2026-09-02T14:00:00","guid":{"rendered":"https:\/\/mailurdu.co.uk\/?p=2686"},"modified":"2026-09-02T14:00:00","modified_gmt":"2026-09-02T14:00:00","slug":"wptavern-232-aaron-d-campbell-on-navigating-wordpress-security-in-the-ai-era","status":"publish","type":"post","link":"https:\/\/mailurdu.co.uk\/?p=2686","title":{"rendered":"WPTavern: #232 \u2013 Aaron D Campbell on Navigating WordPress Security in the AI Era"},"content":{"rendered":"<details>Transcript\n<div>\n<p class=\"wp-block-paragraph\">[00:00:19] <strong>Nathan Wrigley:<\/strong> Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley.<\/p>\n<p class=\"wp-block-paragraph\">Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in this case, navigating WordPress security in the era of AI.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019d like to subscribe to the podcast, you can do that by searching for WP Tavern in your podcast player of choice, or by going to wptavern.com\/feed\/podcast, and you can copy that URL into most podcast players.<\/p>\n<p class=\"wp-block-paragraph\">If you have a topic that you\u2019d like us to feature on the podcast, I\u2019m keen to hear from you and hopefully get you, or your idea, featured on the show. Head to wptavern.com\/contact\/jukebox and use the form there.<\/p>\n<p class=\"wp-block-paragraph\">So on the podcast today we have Aaron D. Campbell.<\/p>\n<p class=\"wp-block-paragraph\">Aaron is a seasoned veteran in both the internet and WordPress space. With over 25 years of experience spanning agency work, security products, hosting giants like GoDaddy and Newfold, and now his role at Monarx, a company focused on malware detection and remediation, particularly for web hosts. He\u2019s led, the WordPress Security Team, has been involved deeply in shaping security practises, and remains tightly connected to the WordPress ecosystem.<\/p>\n<p class=\"wp-block-paragraph\">We talk about the rapidly changing landscape of WordPress security, specifically how the advent of AI has escalated the speed, scale, and complexity of attacks, moving the security game from a battle of wits to a battle of compute power. Aaron discusses how attacks that once required human ingenuity are now orchestrated by AI agents, capable of chaining vulnerabilities that humans would struggle to conceive.<\/p>\n<p class=\"wp-block-paragraph\">We get into the shift from a reactive to a proactive security posture across the WordPress ecosystem. Aaron explains how both attackers and defenders are now deploying AI leading to an arms race, where AI is used to combat AI, and where collaboration among security teams is just as crucial as information sharing among adversaries.<\/p>\n<p class=\"wp-block-paragraph\">Which chat about the motivators behind attacks, spoiler, it\u2019s almost always money. And the specific vulnerabilities WordPress faces as the most popular CMS on the web. Of interest is the narrowing window between when vulnerabilities are discovered and when they\u2019re exploited, how supply chain attacks are on the rise, and what the WordPress \u201cProtect the Shire\u201d innovation means for plugin security.<\/p>\n<p class=\"wp-block-paragraph\">Towards the end of the episode, we explore practical security advice for everyday WordPress users, with Aaron, recommending actionable tips on updates, choosing security minded hosts, and monitoring for Compromise credentials.<\/p>\n<p class=\"wp-block-paragraph\">If you are concerned about how AI is reshaping the WordPress security landscape, and want to know how the community is responding, this episode is for you.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019re interested in finding out more, you can find all of the links in the show notes by heading to wptavern.com\/podcast, where you\u2019ll find all the other episodes as well.<\/p>\n<p class=\"wp-block-paragraph\">And so without further delay, I bring you Aaron D. Campbell.<\/p>\n<p class=\"wp-block-paragraph\">I am joined on the podcast by Aaron Campbell. Hello, Aaron.<\/p>\n<p class=\"wp-block-paragraph\">[00:03:43] <strong>Aaron D Campbell:<\/strong> Hello, nice to be here.<\/p>\n<p class=\"wp-block-paragraph\">[00:03:44] <strong>Nathan Wrigley:<\/strong> Yeah. Thank you for joining me. We\u2019re in a corridor. I should say that at the very beginning. We\u2019re in a corridor at WordCamp US, and so if background noise becomes a problem, we\u2019re just going to have to cope with it. So apologies. But thank you for joining me in a corridor.<\/p>\n<p class=\"wp-block-paragraph\">[00:03:57] <strong>Aaron D Campbell:<\/strong> Absolutely.<\/p>\n<p class=\"wp-block-paragraph\">[00:03:58] <strong>Nathan Wrigley:<\/strong> We\u2019re going to talk today a little bit about WordPress security, and particularly about the advent of AI, and the way that certainly in the more recent past, it appears to have upended what once was normal, I think it\u2019s fair to say. I think things are happening at a rate of knots that perhaps a year or two ago we wouldn\u2019t necessarily have predicted.<\/p>\n<p class=\"wp-block-paragraph\">Do you want to just give us a little bit of background about yourself in terms of where you have worked, where you currently work, and what it is that you do for a living?<\/p>\n<p class=\"wp-block-paragraph\">[00:04:25] <strong>Aaron D Campbell:<\/strong> Sure. So I guess I have worked in the internet space for a very long time at this point. I guess 25 years-ish. Ran my own agency for a long time and then into security product in the WordPress space, and over into hosting at GoDaddy, at Newfold, at hosting.com.<\/p>\n<p class=\"wp-block-paragraph\">During that time I ran the WordPress security team for a couple years, have continued to be involved with it along the way, and now I am over at Monarx. We do malware detection and remediation, and have some security tooling for web hosts. So I\u2019m still very tightly tied into that space on a few fronts.<\/p>\n<p class=\"wp-block-paragraph\">[00:05:09] <strong>Nathan Wrigley:<\/strong> Is Monarx a new company? Because it\u2019s not one that may necessarily come into mind when we talk about security online, WordPress security specifically.<\/p>\n<p class=\"wp-block-paragraph\">So if you\u2019re willing, could you just give us a little bit of a potted history of Monarx and what specifically you do in the WordPress space? I think it\u2019s perhaps more related to hosting companies than it might be to end users. Just flesh that out a little bit.<\/p>\n<p class=\"wp-block-paragraph\">[00:05:33] <strong>Aaron D Campbell:<\/strong> Yeah. Monarx has been around probably longer than you expect, six or seven years. The name\u2019s may be not as recognisable, because a lot of times we are a white label in the background. Hosts run us, and you may not know that.<\/p>\n<p class=\"wp-block-paragraph\">We protect more than just WordPress, but obviously WordPress is a big part of that. And we help hosts keep their users, their end users, safe and secure and malware free by monitoring the files, the runtime, having a WAF layer, protecting it several different layers along the way.<\/p>\n<p class=\"wp-block-paragraph\">[00:06:08] <strong>Nathan Wrigley:<\/strong> So is this kind of like a white label solution? You are in talks with hosts, many of which I\u2019m sure we\u2019ve heard of, but their purchase of the products and services that you sell is white labelled.<\/p>\n<p class=\"wp-block-paragraph\">[00:06:20] <strong>Aaron D Campbell:<\/strong> Yes, they may sell us as their own security product. They may also just include us in higher end hosting packages so that the malware detection and remediation and all that kind of stuff is included in your package. It varies from host to host, but most of the time you\u2019re not seeing the Monarx name out in front, but you\u2019re benefiting from our services anyway.<\/p>\n<p class=\"wp-block-paragraph\">[00:06:40] <strong>Nathan Wrigley:<\/strong> So does that allow you to, because you are cross platform in terms of hosting company, hosting company X, hosting company Y, hosting company A, B, and C. Does that give you a larger depth of knowledge for want of a better word? So you can see that hosting company A\u2019s got this Linux set up, and these kind of things are happening.<\/p>\n<p class=\"wp-block-paragraph\">[00:06:59] <strong>Aaron D Campbell:<\/strong> Yes, it does. It\u2019s less about their specific setups. I think the most valuable thing of being across many hosts like that, is that we see attacks, or new and novel malware, or those kinds of things happening in pockets and can often then protect against it globally, even though maybe it first started at host A.<\/p>\n<p class=\"wp-block-paragraph\">By the time it spreads to host B X or Y in your example, we\u2019ve already been able to understand what that is and block it across the whole realm. So we get a bigger picture, which is super useful. Especially as we start talking about some of the AI stuff and how fast it moves. That\u2019s really necessary to stay ahead of that curve.<\/p>\n<p class=\"wp-block-paragraph\">[00:07:42] <strong>Nathan Wrigley:<\/strong> Okay, so let\u2019s move into that a little bit. And I think if we were having this conversation, let\u2019s go for four years ago, that seems like a long enough period of time where AI was not really on anybody\u2019s menu.<\/p>\n<p class=\"wp-block-paragraph\">And now we seem to be in the era where the human is really being surpassed in almost everything logical, let\u2019s go with that word. If it can be achieved with some kind of logic then AI seems to have surpassed humans.<\/p>\n<p class=\"wp-block-paragraph\">And, especially recently, there seems to have been an uptick, not just in the WordPress news cycle, but also just in the general news cycle about, okay, we need to be a little bit more mindful about the products and services that we buy. We need to be more mindful about the security and logging in and credentials and all of that.<\/p>\n<p class=\"wp-block-paragraph\">But specifically in the WordPress space over the last three or four months, I\u2019ve heard story after story, which was unlike anything I\u2019d heard before. These kind of chained attacks where, something that a human probably would never have conceived and pulled off is now possible. You spend 25 US cents on an AI agent, wait for six hours, and it\u2019s come up with these 14 overlapping things, and it can hack WordPress Core and various other things.<\/p>\n<p class=\"wp-block-paragraph\">So just paint the landscape of how alarming it is, and then presumably you can paint the landscape of how not alarming it is, because how you can mitigate against that.<\/p>\n<p class=\"wp-block-paragraph\">[00:09:00] <strong>Aaron D Campbell:<\/strong> That\u2019s fair. Let\u2019s explain the reality and then let\u2019s hopefully, help comfort people at least a little. It can be pretty scary. You\u2019re absolutely right. AI has dramatically changed the game. And the way I like to explain it is it hasn\u2019t changed the absolute core realities of the game in that there\u2019s still a bit of cat and mouse. They\u2019re trying to surpass us. We\u2019re, trying to stay ahead of them.<\/p>\n<p class=\"wp-block-paragraph\">But the scale and the speed and the complexity at which it is able to happen now is nothing we could have imagined four years ago. Honestly, even two, two and a half years ago. It has moved that fast. And what that looks like are, a few different things.<\/p>\n<p class=\"wp-block-paragraph\">One, the speed at which AI can find issues in code, potential exploits, vulnerabilities, et cetera, is so much faster than any human. Like the compute power of it doing those logical bits rather than humans doing those logical bits, makes that move so fast. So the number of things being found, and being either reported or exploited, or both, the volume has just gone up dramatically.<\/p>\n<p class=\"wp-block-paragraph\">And then on the complexity side of it, you are right. A simple example of that, one of the WordPress Core reports that I looked at recently, I needed to print it out and mark it up with a pen to wrap my brain around all these steps that it was taking. When I printed it out, it was 11 pages. 11 pages of like steps and instructions for an actual vulnerability that turned out to be real.<\/p>\n<p class=\"wp-block-paragraph\">If four years ago that had existed in your piece of software, you would consider your software absolutely secure. No human\u2019s ever going to find that. No one would ever know about it. And now AI is able to chain all those steps together into something that it can then write scripts to go automate and exploit.<\/p>\n<p class=\"wp-block-paragraph\">And so those two things have both really shifted the game in a way that feels like it can put software owners, software managers, SaaS services, all these things on their back foot. There\u2019s just such this flood, and such a complex flood coming at you.<\/p>\n<p class=\"wp-block-paragraph\">[00:11:10] <strong>Nathan Wrigley:<\/strong> So I guess also the problem is that these things never sleep. So four years ago, every human, maybe they could put 10 hours in at the computer and then they would have to rest. So you get a, breathing space, and and the human can do this one thing.<\/p>\n<p class=\"wp-block-paragraph\">But that\u2019s not the case here. With an AI, presumably it could have 10, 50, a hundred, a thousand, the sky is the limit, things happening simultaneously. Just testing absolutely every permutation of everything conceivable. And then coming back with something. I don\u2019t even know how we compete against that. And obviously we can get into that in a moment.<\/p>\n<p class=\"wp-block-paragraph\">Is this a moment of despair or is there genuinely a way of getting out ahead of it? Or is it always going to be a case looking into the future where you are going to be reactive instead of proactive? In other words, when you wake up in the morning and you print out the 11 and then next year, the 30, and then the year after that, the 80 page document, how does that make you feel? Are you sanguine or is it just a prophecy of doom.<\/p>\n<p class=\"wp-block-paragraph\">[00:12:08] <strong>Aaron D Campbell:<\/strong> I think it is a time of overwhelm, but hopefully not despair. Which is different. And I think that as big technology shifts hit, which AI is a big technology shift. There is often a significant adjustment. And we are at that time, and I am even one that maybe would say, I think it might get a little bit worse before it gets better, but it\u2019s definitely going to get better.<\/p>\n<p class=\"wp-block-paragraph\">And I see the path there in some of the foundations that we\u2019re laying in things that we\u2019re learning right now during this time of overwhelm, where we\u2019re feeling flooded like this, is going to put us in a place to start getting into that curve where everything gets better.<\/p>\n<p class=\"wp-block-paragraph\">And I think that, what\u2019s the right way to put this? I think that the path there is apparent, but takes some time. And part of that\u2019s because we have to shift from the being reactive to the being proactive all the time. Because agents move so fast to 24 hours a day, seven days a week. And the second they find a thing, they can immediately, automatically start trying to exploit it.<\/p>\n<p class=\"wp-block-paragraph\">We have to shift to being ahead. Because there is no longer a gap in between when a thing is found and when it\u2019s exploited, for us to fix the thing. We have to get ahead.<\/p>\n<p class=\"wp-block-paragraph\">[00:13:36] <strong>Nathan Wrigley:<\/strong> So, you are obviously deep in the weeds of this, and it sounds like you\u2019ve got an intuition that at some point in the near to midterm future, you feel like you are going to reach a point where things start to improve. That was the implication, I think of what you said.<\/p>\n<p class=\"wp-block-paragraph\">What is that intuition? How do you come to the conclusion that there is an opportunity for things to improve. Even if you need to go into the weeds a little bit. I\u2019m curious as to how it\u2019s not a prophecy of doom, and how you believe that a moment will arrive where, I can\u2019t answer that for you. I\u2019ll just open it up.<\/p>\n<p class=\"wp-block-paragraph\">[00:14:06] <strong>Aaron D Campbell:<\/strong> Yeah. So I think that some of this comes from historical experience, right? We\u2019ve had these kinds of experiences where say, a certain type of hash that we used for security became a thing that hackers could break with the level of computing power that they finally had access to.<\/p>\n<p class=\"wp-block-paragraph\">And that felt doom and gloom. But also we created better hashing algorithms. We created better things that were able to counteract that. We were able to shift to those, and we were also able to learn from them and think further forward.<\/p>\n<p class=\"wp-block-paragraph\">So now some of the algorithms that we\u2019re using aren\u2019t just better enough to handle current computing, but better enough that we think they\u2019re going to last a decent ways into the future.<\/p>\n<p class=\"wp-block-paragraph\">I think that there are similar things with AI now. Where we are leveraging the same kind of tools now that these bad actors are, and we\u2019re learning how to use them not just to protect against the way the bad actors are using them, but to get ahead enough to stay ahead of them.<\/p>\n<p class=\"wp-block-paragraph\">And the way that looks, because that sounds maybe too vague to be realistic I guess, is we\u2019re not just running those same algorithms against our code, or those same models against our code and hoping that we find the stuff before they find it. We\u2019re instead also looking at how can we push to a different part of the stack? How can we protect against things that we\u2019ve never seen? How can we start to recognise these patterns so that we can look at behaviours and protect against those, rather than just flaws that need to be patched. It\u2019s shifting our thinking some, but I think in a way that\u2019s going to help us get ahead in this game.<\/p>\n<p class=\"wp-block-paragraph\">[00:16:03] <strong>Nathan Wrigley:<\/strong> Okay. That\u2019s really interesting. I have a question surrounding how this kind of stuff happens, and I\u2019m thinking about it from the adversarial\u2019s point of view. What is that like? Because I have a notion that a decade ago it was individuals, perhaps offices, that\u2019s probably the wrong word, but, collections of people sitting in a space, but there would be a finite number of them. There may be 10 in a room, one in a room, a hundred in a room.<\/p>\n<p class=\"wp-block-paragraph\">But I don\u2019t know if that\u2019s still the case. Do the adversaries that you are dealing with, do they have a collaborative approach to hacking? Do they share information? And then the flip side of that is do you also, in the industry that you work in, do you share information?<\/p>\n<p class=\"wp-block-paragraph\">If you discover something, does Monarx treat that like it\u2019s your intellectual property? Or is there a, a whole system of sharing that amongst the community so that everybody benefits from the work that you do? You\u2019re giving away the hard work that you\u2019ve done. If that\u2019s the case.<\/p>\n<p class=\"wp-block-paragraph\">[00:16:59] <strong>Aaron D Campbell:<\/strong> So, first let me just say personally, one of the most important things to me is to raise the level of security across the whole internet, because that is better for humanity that relies on it so much, for all kinds of things in our daily lives, and for sharing information and making progress forward as people.<\/p>\n<p class=\"wp-block-paragraph\">I think that I\u2019m not alone in the space. Like I think that a lot of us that were drawn to this security space are drawn to it because it is a way to improve life for everybody. Will there be some intellectual property for individual companies? Yes, but I think it\u2019s a lot more in how we approach the thing, and less we\u2019re not going to tell people about this new vulnerability, or this new method that we found. Because we do want to be able to see the end user protected. Like that is the way we\u2019re going.<\/p>\n<p class=\"wp-block-paragraph\">Backing up to your, how do the adversaries work? It\u2019s been a long time, I think since they sat in rooms together. They\u2019re now virtual rooms, right? They can be spread all over the world, but still be working together. And they definitely do. They share information around. For us to be able to keep up with that, we have to share information around too. That is super important.<\/p>\n<p class=\"wp-block-paragraph\">Simple example of that, the WordPress Security Team. Let me step back from Monarx and talk more of the space in general. The WordPress Security Team. You talked about how for the last few months you\u2019ve seen maybe more security releases going out from WordPress and stuff. The way that the WordPress Security Team treats those, when we find out about them, and we triage them, and we realise that they\u2019re real, and we start figuring out what our approach is to patching them. We then have a whole private Slack channel that has other people in it that can help us get protection out. Broader, wider by sharing some of that information sooner.<\/p>\n<p class=\"wp-block-paragraph\">Cloudflare can maybe put some rules in place, and protect tonnes of people before the WordPress release goes out. So can some of the big hosts. So can some of the security groups. And so not only do we share that information, we\u2019ve built it into our processes as a must, because that\u2019s the only way to really do it right, and really protect as many people as possible. Because our adversaries are doing that. And so we have to as well. And we\u2019ve just realised that, learned from it and made that the right way to do it.<\/p>\n<p class=\"wp-block-paragraph\">[00:19:26] <strong>Nathan Wrigley:<\/strong> I\u2019m just going to flip back to the comment that you made a moment ago where you said that you woke up and you printed out this summation. Let\u2019s go with that. And it was 11 pages, and presumably that took a certain amount of your day to parse and understand.<\/p>\n<p class=\"wp-block-paragraph\">How likely is it that that process will begin to run away from humans\u2019 capacity to actually do it? So as an example, let\u2019s say that a year from now that thing that you print out is 50 pages or 80 pages. Just the reading of it would be a whole morning, let alone the understanding of how those layers, and the stacks and the way that they\u2019re overlapping and reliant upon each other.<\/p>\n<p class=\"wp-block-paragraph\">Have we now, or have you now as an industry, have you almost handed the responsibility to figuring that stuff out, figuring out what the adversaries are doing? Has that gone to AI from your part as well? So is it AI versus AI basically, which seems very dystopian.<\/p>\n<p class=\"wp-block-paragraph\">[00:20:18] <strong>Aaron D Campbell:<\/strong> We definitely pit AI against AI. It\u2019s an extremely useful tool to combat itself essentially. And yeah, even for that 11 page one. Yes, I had to read through it and figure it out. but I did use AI to help summarise that. What are the steps that I need to do? Where does this actually track to in the code base?<\/p>\n<p class=\"wp-block-paragraph\">I use it as an assistive tool in getting through that. And I do think that the longer the reports get, the more that\u2019s going to be necessary. And now I personally, and several other people that I work with, have built testing rigs in AI, in various models, that are purpose built to help with this.<\/p>\n<p class=\"wp-block-paragraph\">I can give it a report, in the repository and it can check its viability. It can see if that\u2019s simplified. Check certain things. Is this a thing that requires some level of authentication, all these things that we use to have to do manually. And now we\u2019re sharing around these sort of test rigs, or assessment rigs, that use this so that we can all use them, and grow them faster and make them better and make them more efficient. Because we are pitting AI against AI in many ways.<\/p>\n<p class=\"wp-block-paragraph\">And as human, I think that it\u2019s still important for the human to guide the process in a way that\u2019s ensuring the fix is forward thinking enough, and that it\u2019s in the right place and whatnot. Because in the end, the software is largely used by humans. But, in order to scale to the level that AI is pushing us to scale to, the human needs to be the decision maker, and possibly the opinionated one on form, and function, but not the logical power behind any of it now.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:01] <strong>Nathan Wrigley:<\/strong> Do you get the sense that WordPress itself is the target, or is WordPress just a bit of collateral damage? Are these adversaries of yours, are they specifically targeting WordPress because it\u2019s got this giant footprint? Or is it more a case of this is just the adversaries just spraying and scatter gunning, and it just so happens that every so often they stumble across a WordPress thing.<\/p>\n<p class=\"wp-block-paragraph\">[00:22:23] <strong>Aaron D Campbell:<\/strong> There is spray and scatter gun, just not running WordPress, or running your own bespoke thing is not enough to get away from AI trying to break your thing. But the bigger you are, the bigger the potential benefit from finding an exploit in you. And therefore, the more you are, like the bigger you are, the target is on you.<\/p>\n<p class=\"wp-block-paragraph\">So WordPress has a big target, but it\u2019s not just WordPress. Some big hosting companies also have a big target on their infrastructure in the same way that they\u2019re targeting WordPress, their targeting, maybe a Hosting or a GoDaddy or a Blue. Someone big that has many people on it, not because they think their security is lax, or that they have some reason to suspect that there\u2019s vulnerabilities, but because the payoff of finding a vulnerability there can be big. And so there\u2019s a big focus there.<\/p>\n<p class=\"wp-block-paragraph\">So yes, the bigger you are, the bigger the target. But that doesn\u2019t mean that the scattershot isn\u2019t also happening. And that they\u2019re not also hitting small targets.<\/p>\n<p class=\"wp-block-paragraph\">[00:23:24] <strong>Nathan Wrigley:<\/strong> Yeah. I suppose there would\u2019ve had to have been a lot of joined up thinking in the past from a human to discover that, \u201cOkay, this thing with Linux over here, okay we\u2019ll just store that somewhere. But then there\u2019s a PHP thing over here. Oh, and then curiously, there\u2019s a PHP thing in WordPress, which,\u201d that would\u2019ve all had to have been conjured up by a human. And the memory of that would be difficult to maintain over time. But presumably the AI can just remember that forevermore. Store that PHP thing for the next decade and suddenly whip it out when it\u2019s happens to coincide with some other thing. It\u2019s fairly bleak.<\/p>\n<p class=\"wp-block-paragraph\">Okay, so in terms of WordPress specifically, what is the incentive specifically? Why would somebody, let\u2019s say somebody was coming after WordPress. What is it that they gain? What could they possibly have that benefits them off the back of a, let\u2019s go for WordPress Core vulnerability which is, I don\u2019t know, you can successfully log in as an admin or whatever it may be. What do they actually gain?<\/p>\n<p class=\"wp-block-paragraph\">[00:24:17] <strong>Aaron D Campbell:<\/strong> It really comes down to money in end, if I\u2019m honest. WordPress Core powers tens of millions of sites all over the web. Some of those have valuable stuff on them. Many of them frankly don\u2019t. But that doesn\u2019t mean that they\u2019re worthless. They can be used, you\u2019ve seen pharma ads and stuff showing up on a site, and it\u2019s a pay per click kind of thing. And someone\u2019s making some money off of putting not great ads your site. Even if you don\u2019t get a lot of traffic, they\u2019re making something. And when you\u2019re looking at the potential of this vulnerability could apply to tens of millions of sites, you don\u2019t need to make much per site.<\/p>\n<p class=\"wp-block-paragraph\">But also, you could use that site as a way to have broad compute power to attack some other site. You\u2019re using tens of thousands of sites to do it. Each one of them is on some separate IP. So now you have a distributed attack that\u2019s harder to block than if you were doing the same attack from one place.<\/p>\n<p class=\"wp-block-paragraph\">But you\u2019re only doing that because it costs a lot to buy your own distributed power from everywhere. So you\u2019re essentially stealing it and it\u2019s making it, there\u2019s some sort of worthwhile monetary value from it.<\/p>\n<p class=\"wp-block-paragraph\">And so you may think, they can\u2019t make anything off my site. They don\u2019t have to. Your site\u2019s one small bit in a huge array of sites that they\u2019re trying to get, to get some monetary benefit in the end.<\/p>\n<p class=\"wp-block-paragraph\">[00:25:40] <strong>Nathan Wrigley:<\/strong> So there\u2019s no one size fits all. But money is essentially the broad overlapping thing?<\/p>\n<p class=\"wp-block-paragraph\">[00:25:46] <strong>Aaron D Campbell:<\/strong> I mean, there are exceptions to that, where people are doing it for some political reason. Or some moral directive that they have or whatever. But the vast majority can be traced back to there\u2019s money in it somewhere.<\/p>\n<p class=\"wp-block-paragraph\">[00:25:59] <strong>Nathan Wrigley:<\/strong> I wonder curiously, because you mentioned about things like, pay per click style, you take oversight and you flood it with, I don\u2019t know, nonsense about the thing that you\u2019ve got and you want the world to notice. I wonder if curiously, people\u2019s adoption of AI and that different way that we\u2019re searching for things will actually impoverish that way of monetizing, because simply nobody\u2019s actually looking on a search, well, increasingly people seem to be relying less and less on a search engine, and so maybe that kind of bit of it will dry up. Who knows?<\/p>\n<p class=\"wp-block-paragraph\">[00:26:27] <strong>Aaron D Campbell:<\/strong> I love the optimism there. And I would like to think that those ads specifically probably will at some point. But the root of how those work is, I\u2019ve broken into a site and I can inject some JavaScript ad, or some something like that.<\/p>\n<p class=\"wp-block-paragraph\">And if those ads stop being valuable, then maybe I can inject some AI directives so that when an AI agent of some kind hits that site, it\u2019s getting some sneaky thing snuck into its memory, or pulled in as a skill, that can then use that AI agent for nefarious purposes in the future.<\/p>\n<p class=\"wp-block-paragraph\">I think that we can\u2019t lower our guard against those things, because our adversaries will pivot and reuse it for something else. And so we will continue to protect against it.<\/p>\n<p class=\"wp-block-paragraph\">[00:27:13] <strong>Nathan Wrigley:<\/strong> I\u2019m going to peel back the contents of your head a little bit here. Because I\u2019ve often wondered what the characteristic is of somebody like you who constantly facing this tidal wave of things. You\u2019ve got to get up every morning, and every morning you could potentially wake up to the next big thing.<\/p>\n<p class=\"wp-block-paragraph\">How do you just remain calm in the face of all of it? It\u2019s a peculiar question, I realise, but tomorrow could be the next big thing. The day after that could be the next big thing. I\u2019m imagining on most days now there is not necessarily the next big thing, but there\u2019s a thing. It\u2019s like you\u2019re a fireman or something, except that there\u2019s a fire going off in every district of town, and you are constantly busy and you never get to put the fire hose down. You\u2019re just constantly at work.<\/p>\n<p class=\"wp-block-paragraph\">[00:27:52] <strong>Aaron D Campbell:<\/strong> Some of us love that little consistent regular shot of adrenaline, and we get it in different ways than the firemen. But, honestly, I love complex problems solve. I love the challenges. Do I get exhausted and burnt out at times when they really do come every day for X amount of time? Sure, I\u2019m human, I need to sleep, et cetera. But I think that it\u2019s because I enjoy figuring out those really difficult problems, that I enjoy being in this space. And even specifically on this side of the space, the white hat side.<\/p>\n<p class=\"wp-block-paragraph\">[00:28:26] <strong>Nathan Wrigley:<\/strong> Yeah. I suppose it\u2019s like playing a good opponent at chess. You enjoy the chess game, even though it\u2019s a hard thing and it stretches your brain. You play the chess over and over again because it\u2019s a pleasurable thing to have your brain exercised in that way.<\/p>\n<p class=\"wp-block-paragraph\">[00:28:39] <strong>Aaron D Campbell:<\/strong> And it\u2019s like the more you do it the better chance you have at winning at chess. And I think it\u2019s the same way in our game, right? Like the more you\u2019re doing it, the more ways you\u2019re finding to outmanoeuvre and to essentially win, and keep people safe online. And that\u2019s, that\u2019s exciting.<\/p>\n<p class=\"wp-block-paragraph\">[00:28:56] <strong>Nathan Wrigley:<\/strong> You get the fist pump moment do you, there\u2019s once in a while where you literally figure something out and you\u2019re like, I nailed that.<\/p>\n<p class=\"wp-block-paragraph\">[00:29:04] <strong>Aaron D Campbell:<\/strong> You absolutely do.<\/p>\n<p class=\"wp-block-paragraph\">[00:29:04] <strong>Nathan Wrigley:<\/strong> Okay. Yeah. That\u2019s really interesting. Your bio reads like an open source manifesto. I know that open source has been the thing for you throughout your career. I imagine that you could have gone into proprietary security and all of that.<\/p>\n<p class=\"wp-block-paragraph\">But how does open source, particularly WordPress, how does that approach to developing software, how does that benefit the position that we can take and the security posture that you can take, and the reliability that you can have in things like WordPress going forwards? In your head, does it offer a superior model for fighting the adversaries?<\/p>\n<p class=\"wp-block-paragraph\">[00:29:35] <strong>Aaron D Campbell:<\/strong> Yes, in my opinion it offers a superior model for fighting the adversaries. And the reason is actually still the same as it was 20 years ago when I started doing this. And I\u2019ll explain why in just a second, but first, the reason is because we are able to benefit from many intelligent people, many more than any single company could with their source code.<\/p>\n<p class=\"wp-block-paragraph\">Looking at our source code, and finding the weaknesses and even pitching in to help fix them. Hundreds of thousands, or millions, of people around the world are looking at our source code, finding those issues, and able to help pitch in and fix them, or report them to us so that we can, by having all that out there, it\u2019s sort of like a building\u2019s not less likely to collapse because no one saw the crack. It\u2019s actually better that people are inspecting it, and finding those things and making sure it\u2019s done right.<\/p>\n<p class=\"wp-block-paragraph\">Now, that has shifted a little bit now, where in the past our adversaries looked at our source code too, right? They would immediately look at our repository when new things went out. As a matter of fact, when I ran the security team, I stopped committing stuff for a while, because it turned out that was a tell that this thing was probably a security issue, and people would look at that and try to figure it out.<\/p>\n<p class=\"wp-block-paragraph\">So now the adversaries are using AI to watch our source code, which is also open to them, 24 7 and really look deep at it. But so are those many thousands of people using our source code for good. And so it\u2019s still true that we have so many people on our side in helping us out, because our source code is out there because we\u2019re open source, and it outweighs the bad. We find things faster because of that, and ultimately end up with more secure software more rapidly.<\/p>\n<p class=\"wp-block-paragraph\">[00:31:36] <strong>Nathan Wrigley:<\/strong> Is there ever going to become a time where the amount of time that a vulnerability is available becomes moot? So in the past, a six hour window, where something wasn\u2019t patched in WordPress Core, that\u2019s a thing, but it\u2019s not really a big thing. Maybe a month where something\u2019s unpatched, that\u2019s a big, I\u2019m just wondering if in the future with the nature of the adversaries that you described and the tooling that they can bring to bear, if even like a three or five second window is going to become a thing.<\/p>\n<p class=\"wp-block-paragraph\">[00:32:05] <strong>Aaron D Campbell:<\/strong> That is possible. We\u2019re not at the three to five second window yet, so that\u2019s good. I\u2019ll let everybody relax a little bit. But the time from vulnerability disclosure to exploitation has shrunk dramatically over the last few years.<\/p>\n<p class=\"wp-block-paragraph\">We did in fact used to have weeks, and then eventually days where it was okay to find out about the vulnerability, and responsible people, or responsible hosts, or responsible software companies could see that disclosure, patch the problem before there was much exploitation at all. And that\u2019s now hours for major vulnerabilities.<\/p>\n<p class=\"wp-block-paragraph\">As a matter of fact, we did a Monarx in conjunction with Patchstack, did like a year in review, thing looking back at last year. And we saw that for the more major vulnerabilities, it was about five hours. That\u2019s not enough time for, you know, what happens if it happens in the middle of the night for a host who\u2019s constantly monitoring that, immediately patching it, that\u2019s difficult. And I do think that it will continue to shrink. And that that time that causes risk will be shorter and shorter.<\/p>\n<p class=\"wp-block-paragraph\">And, we saw that with the recent wp2shell WordPress exploit. Once we released the patch, and everything was out there, the spike of exploitation that we as Monarx saw, like monitoring stuff happened within 30 minutes. Honestly, even a little bit faster than that. But the big spike started coming in about 30 minutes later, and that is just really fast.<\/p>\n<p class=\"wp-block-paragraph\">But on the flip side, all that coordination that I talked about that WordPress did, had many millions of people already protected by then. And that\u2019s how we have to look at it. We have to say, this is eventually going to get down to three to five seconds being a problem. How do we get ahead of it? And that\u2019s what we\u2019re trying to do.<\/p>\n<p class=\"wp-block-paragraph\">[00:34:03] <strong>Nathan Wrigley:<\/strong> So a timely thing at the moment is this new innovation in the WordPress space called Protect the Shire. And Protect the Shire is the, a time bound moment where a plugin that has an update, it can\u2019t be updated at the moment, I believe it\u2019s standing at something in the region of six hours. On the face of it, that seems like a really excellent posture. But then there\u2019s the flip side of that. If an exploit becomes discovered, and nobody can update their plugin for six hours, then that\u2019s a big six hour window we\u2019ve just painted. in the future where milliseconds may count. What do you think about that? It\u2019s a interesting innovation. It\u2019s something new. It was worth a try. Do you think that\u2019s the way forward?<\/p>\n<p class=\"wp-block-paragraph\">[00:34:41] <strong>Aaron D Campbell:<\/strong> I think it, was not only worth a try. I think it was a really good choice, and I think it will continue to be. We are seeing that a lot of current attacks are essentially supply chain attacks. How can we compromise whether it\u2019s some package, an NPM package or something like that. Or whether it\u2019s a plugin that\u2019s gotten sold to a nefarious person, or even just hacked into and taken over by a nefarious person. That is happening more and this six hour gap helps protect against that.<\/p>\n<p class=\"wp-block-paragraph\">But it can\u2019t be a hard and fast, locked in stone, can never have exceptions, rule. And the truth is, it\u2019s not. If there is a vulnerability in your plugin, or especially in a major plugin, reach out to the WordPress Security Team because we can coordinate a faster release, we can make an exception to that rule when it\u2019s necessary.<\/p>\n<p class=\"wp-block-paragraph\">And I think that for security fixes that are clearly security fixes that exception iss an easy one to make, because we do want to protect immediately. But slowing things down enough to make sure that there\u2019s not been some sort of supply chain issue that is actually going to cause a vulnerability rather than fix one, is smart.<\/p>\n<p class=\"wp-block-paragraph\">And so I think that it will find the right balance there as we continue to move forward, and figure out how to make better processes around this, to make it easier to do the right thing all the time, and know exactly which of those right things. But I think at the moment we\u2019re in a pretty good place there and continuing to find the exact right place.<\/p>\n<p class=\"wp-block-paragraph\">[00:36:18] <strong>Nathan Wrigley:<\/strong> It feels from the outside as if security\u2019s fairly binary. On the one hand, adversary on the other hand, good guys. On the one hand hacked, on the other hand, not hacked. It\u2019s black and white. But it seems from everything that you\u2019ve been talking about today, that you are occupying a really grey area. You\u2019re just trying to figure out what the path is forward. You\u2019re constantly staring into the future trying to figure out what the adversaries are doing. Trying to patch, trying to make sure that everything is as good as it possibly can be. And I hadn\u2019t really thought about it in that way. It\u2019s not, there is no destination here where everything\u2019s white. It\u2019s a journey and every day\u2019s going to be a bit grey. There\u2019s going to be a bit of black and a bit of white, but a lot of grey in the middle.<\/p>\n<p class=\"wp-block-paragraph\">[00:36:58] <strong>Aaron D Campbell:<\/strong> I don\u2019t really look at it as grey, but I can see where you\u2019re going there. But I think that there is this black and white, and then there\u2019s sort of the cloudy. The further forward you look, the more difficult it is to know exactly where the black and white are always going to be. And some of that sort of comes across as grey. It\u2019s a little blurry. You can\u2019t quite figure it out.<\/p>\n<p class=\"wp-block-paragraph\">But you\u2019re right. there\u2019s some prediction. There\u2019s some, we think that moving this way is going to cause more white and less black. And that\u2019s what we\u2019re, that\u2019s what we\u2019re constantly aiming for. But you can\u2019t just say turning right always makes things more white. Because sometimes there could be black over on that side somewhere, right? You\u2019re really trying to be predictive, but not just randomly predictive, right?<\/p>\n<p class=\"wp-block-paragraph\">Many of the people like myself that are trying to help guide this path forward, and even more than me, some of the people like Matt, who instituted that wait policy and some of the people that are running the WordPress Security Team, we have decades of experience watching this, that\u2019s helping to inform our predictions. And so it\u2019s not, we\u2019re not just willy-nilly guessing. And I think that\u2019s important to point out to the people that rely on us, to help guide them to the right space going forward.<\/p>\n<p class=\"wp-block-paragraph\">[00:38:02] <strong>Nathan Wrigley:<\/strong> Yeah. Okay. So my schooling in chemistry was pretty basic, but I know that if I want to understand chemistry, my quickest way to do that is to rely on an expert, is to go and find a chemist who has years of experience. And, the same would be true here. I think most of us have probably not got the capacity to actually get a hold of what you\u2019re saying. We, understand that your expertise is what we need to be listening to. But I\u2019m just wondering for a typical WordPress user of whom many listen to this podcast, they have a WordPress site, but they\u2019re not really interested in security, other than how it may impact their business.<\/p>\n<p class=\"wp-block-paragraph\">So I\u2019m going to ask for some very basic advice here. What would be the 1, 2, 3 things that somebody using WordPress with no security credentials whatsoever. What would be the few things that you would advise them to either go and read, or go and do, or go and think about?<\/p>\n<p class=\"wp-block-paragraph\">[00:38:51] <strong>Aaron D Campbell:<\/strong> Yeah, so I think the biggest thing that I would encourage them to do, is essentially position themselves in such a way that they are relying on the experts, right? You\u2019re not an expert and that\u2019s okay. No one can be an expert in everything. But there are some things you can do to position yourself such that you\u2019re benefiting from those experts.<\/p>\n<p class=\"wp-block-paragraph\">One of those is updating as fast as possible. So WordPress auto updates turned on, those kinds of things. This WordPress Security Team that I\u2019m talking about that has so much expertise in the area, and their whole focus is trying to make sure that WordPress is always secure. That lets you rely on them to help keep your site secure.<\/p>\n<p class=\"wp-block-paragraph\">I think in similar ways, you want to find the right host that is also doing those security focused things for you, so that you don\u2019t need to. And maybe that\u2019s asking your host, what do you do to keep me safe? We talk about security, like the best security is layered security. It\u2019s almost like having a gate at the complex, but also having a lock on your door, right? Those kinds of things. You can ask your host, what do you do to protect me in a layered way?<\/p>\n<p class=\"wp-block-paragraph\">And maybe that question doesn\u2019t make sense to you, and maybe even their answers don\u2019t make sense to you, but if they have an answer, that\u2019s good for you. It means that you can rely on their expertise.<\/p>\n<p class=\"wp-block-paragraph\">And then stepping out of the obvious space to give a third thing that people should be doing. And this is, this may sound out in left field, but you should get some form of dark web monitoring for yourself, for your own credentials. And whether that\u2019s going to someplace like, Have I Been Pwned, and looking at your own email address, and passwords and seeing if they\u2019ve been in some breached data from somewhere, and are now being sold on the dark web. Or whether that\u2019s using some service that offers it. I think that\u2019s important, more so now than it\u2019s ever been.<\/p>\n<p class=\"wp-block-paragraph\">Because one of the other things that AI is doing that it\u2019s particularly good at is collecting all this massive amount of breach data that\u2019s happened over the last couple decades, that\u2019s being sold on the dark web. Collating it all and saying, oh, we see that, gosh, 15 years ago, an account that Aaron had was in a breach. And we now know one of his passwords.<\/p>\n<p class=\"wp-block-paragraph\">And granted it\u2019s 15 years old, but it\u2019s very easy for that AI to then say, where is Aaron now? What\u2019s he doing? What can we learn about him? He works at Monarx. I wonder if this password works for his Monarx account. I wonder if this password works for the bank that he\u2019s at. Or this other tool that we see that he uses. Let\u2019s try all his social media accounts.<\/p>\n<p class=\"wp-block-paragraph\">And so knowing whether that\u2019s out there and being able to, you can\u2019t get rid of that data, but being able to do things to protect yourself because you now know it\u2019s out there is more important than it\u2019s ever been.<\/p>\n<p class=\"wp-block-paragraph\">[00:41:47] <strong>Nathan Wrigley:<\/strong> I hope you take this in the spirit in which it\u2019s offered, but I really do wish to live in a world where you don\u2019t have a job.<\/p>\n<p class=\"wp-block-paragraph\">[00:41:55] <strong>Aaron D Campbell:<\/strong> Me too.<\/p>\n<p class=\"wp-block-paragraph\">[00:41:56] <strong>Nathan Wrigley:<\/strong> But, am glad that we live in a world where you do, somebody like you does have a job. So I hope that landed correctly.<\/p>\n<p class=\"wp-block-paragraph\">[00:42:02] <strong>Aaron D Campbell:<\/strong> If I could work to the point where I could work myself out of a job, I would find a new career and I would feel so accomplished, you couldn\u2019t even imagine it. I\u2019m okay with that.<\/p>\n<p class=\"wp-block-paragraph\">[00:42:12] <strong>Nathan Wrigley:<\/strong> Yeah. Good. Aaron, just before we wrap up, is there a place where you hang out online where people could poll you if they\u2019ve got a question, or any thoughts about what we\u2019ve talked about?<\/p>\n<p class=\"wp-block-paragraph\">[00:42:21] <strong>Aaron D Campbell:<\/strong> Yeah, if you\u2019re looking for me professionally, you can find me Monarx.com, M-O-N-A-R-X.com. I also have aarondcampbell.com if you want some of my own more personal takes on security and things. And you can find me on Bluesky or the WordPress Slack. Those are probably the biggest places I\u2019m at.<\/p>\n<p class=\"wp-block-paragraph\">[00:42:40] <strong>Nathan Wrigley:<\/strong> What I will do, dear listener, into the show notes, if you go to wptavern.com and you search for the episode with Aaron Campbell, you\u2019ll be able to find the links. I will dig out the Bluesky, and the various social links and the Monarx website and what have you, so you don\u2019t have to hunt around too much. Go there wptavern.com. And Aaron, thank you so much for chatting to me today.<\/p>\n<p class=\"wp-block-paragraph\">[00:43:01] <strong>Aaron D Campbell:<\/strong> Thank you. This was a really fun talk.<\/p>\n<\/div>\n<\/details>\n<p class=\"wp-block-paragraph\">On the podcast today we have Aaron D Campbell.<\/p>\n<p class=\"wp-block-paragraph\">Aaron is a seasoned veteran in both the internet and WordPress space, with over 25 years of experience spanning agency work, security products, hosting giants like GoDaddy and Newfold, and now his role at Monarx, a company focused on malware detection and remediation, particularly for web hosts. He\u2019s led the WordPress Security Team, has been deeply involved in shaping security practices, and remains tightly connected to the WordPress ecosystem.<\/p>\n<p class=\"wp-block-paragraph\">We talk about the rapidly changing landscape of WordPress security, specifically how the advent of AI has escalated the speed, scale, and complexity of attacks, moving the security game from a battle of wits, to a battle of compute power. Aaron discusses how attacks that once required human ingenuity are now orchestrated by AI agents capable of chaining vulnerabilities that humans would struggle to conceive.<\/p>\n<p class=\"wp-block-paragraph\">We get into the shift from a reactive to a proactive security posture across the WordPress ecosystem. Aaron explains how both attackers and defenders are now deploying AI, leading to an arms race where AI is used to combat AI, and where collaboration among security teams is just as crucial as information-sharing among adversaries.<\/p>\n<p class=\"wp-block-paragraph\">We chat about the motivators behind attacks, spoiler, it\u2019s almost always about money, and the specific vulnerabilities WordPress faces as the most popular CMS on the web. Of interest is the narrowing window between when vulnerabilities are discovered and when they\u2019re exploited, how supply chain attacks are on the rise, and what the WordPress \u201cProtect the Shire\u201d innovation means for plugin security.<\/p>\n<p class=\"wp-block-paragraph\">Towards the end of the episode, we explored practical security advice for everyday WordPress users, with Aaron recommending actionable tips on updates, choosing security-minded hosts, and monitoring for compromised credentials.<\/p>\n<p class=\"wp-block-paragraph\">If you\u2019re concerned about how AI is reshaping the WordPress security landscape, and want to know how the community is responding, this episode is for you.<\/p>\n<h2 class=\"wp-block-heading\">Useful links<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/aarondcampbell.com\/\">Aaron\u2019s website<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.monarx.com\/\">Monarx website<\/a><\/p>\n<p class=\"wp-block-paragraph\">Monarx and Patchstack\u2019s <a href=\"https:\/\/patchstack.com\/whitepaper\/state-of-wordpress-security-in-2026\/\">State of WordPress Security In 2026<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/thehackernews.com\/2026\/07\/wordpress-wp2shell-exploitation-grows.html\">WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/wordpress.org\/news\/2026\/06\/pts\/\">Protect The Shire<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/haveibeenpwned.com\/\">Have I Been Pwned<\/a><\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/bsky.app\/profile\/aarondcampbell.com\">Aaron on Bluesky<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Transcript [00:00:19] Nathan Wrigley: Welcome to the Jukebox Podcast from WP Tavern. My name is Nathan Wrigley. Jukebox is a podcast which is dedicated to all things WordPress. The people, the events, the plugins, the blocks, the themes, and in <a class=\"read-more\" href=\"https:\/\/mailurdu.co.uk\/?p=2686\">\u0645\u0632\u06cc\u062f \u067e\u0691\u06be\u06cc\u06ba<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2686","post","type-post","status-publish","format-standard","hentry","category-pakistan"],"_links":{"self":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/2686","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2686"}],"version-history":[{"count":0,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/2686\/revisions"}],"wp:attachment":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2686"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2686"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2686"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}