The EssentialPlugin attack — why your website's biggest security risk is its plugins
How an attacker quietly bought 20+ WordPress plugins on Flippa, shipped a dormant backdoor to 400,000 sites, and waited eight months to pull the trigger — and what it means for how you choose a web stack.
Daniel John Keefer