Hi, I'm the dev behind Noshi-Kanamer 👋
I've caught things before handing off WordPress sites -- forgotten noindex, debug.log left behind, default admin usernames.
So I wrote down the 25 checks I use before handoff.
Free, no signup ↓
https://t.co/0UIe5alf0O
#WPDev#WordPress
Static screenshots only tell you so much, so I finally recorded Noshi-Kanamer in action. 🙌
Auto-detect issues, clean up, generate a report, then hand off. All in one short video. 🎉
Watch here ↓
https://t.co/p1yjB0MSvL
#WPDev#WordPress
We build WordPress plugins too, so posts like this always make me stop for a second.👀
We need to be careful about what we ship. And once a plugin is installed, it still needs to be watched and maintained.
Easy to forget when everything seems to be working fine.💦
"600K WordPress Sites affected by a vulnerability in Forminator Forms plugin."
Forminator became Terminator. This is what happens when website operators blindly trust plugin developers.There is so much tail risk in WordPress space.
Building a WordPress plugin from zero, this hit home.
Right now my audience is tiny, and getting anyone to notice what I'm building has been harder than building it.
But every popular plugin was unknown once. I'll keep showing up and doing the unglamorous work. 🌱
Interesting to read @RankingsWp's take on why we're growing.
✅ Building authority is slow, unglamorous work that looks like generosity long before it looks like strategy.
❌ This is 100% wrong, though:
"None of them launched cold. Every plugin still growing in a traditional category had a distribution advantage before it shipped a single line of code. An existing audience, an existing channel, or an existing reputation. Not one of them was a great product that clawed its way up from zero on merit alone. They all started with a way to reach people already in place."
If you read my blog post about marketing (link in thread), you know that when we launched Accessibility Checker, we did not have a reputation, email list, audience, or a way to reach people.
You don't have to already have an audience to create and grow a WordPress plugin. You just need to be prepared to put in the work.
https://t.co/yj5FjdnCtn
Completely agree.
WordPress has weaknesses. We know them.
That’s why maintenance, checks, and handoff matter. They’re what let clients enjoy WordPress without carrying all the risk themselves.
Our job is simple: keep protecting their sites from people waiting for us to get lazy
Most developers who call #WordPress "legacy tech" cannot describe why 40% of the web still runs on it in a way a WordPress user would agree with.
Here is the steelman, written by someone who's still developing and launching new WordPress websites weekly.
If you expect to make money in web design/dev the same as you've been for the last 10+ years, you are hugely mistaken. We exist in an industry that was literally created from nothing. Why would we expect it to not change?
A good reminder for all of my WordPress friends. 💻💪🚀
wp2shell makes headlines, and WordPress dies all over again.
Strangely, the client sites keep needing maintenance.
So we play canary and hope we start screaming early enough.
#WPDev#WordPress
Everyone jokes about leaked API keys until it's their API key.
Years ago, one got exposed on a pretty large site I was working on.
Luckily, the repo was internal, so nothing happened.
Still scared the hell out of me😱
#WPDev#WordPress
Someone told an AI agent to "keep going" without reviewing the plan.
24 hours later: EC2 instances, load balancers, Lambda functions everywhere. $6,531 in AWS charges.
It didn't malfunction. Real credentials, no usage cap, nobody reading the plan.
#buildinpublic
A developer who audits AI-built apps for a living reviewed 10+ SaaS projects this year.
Same issue kept showing up: no row-level security. Anyone with an API token could read every user's data.
200+ emails and phone numbers, wide open.
#WPDev#WordPress
Hi, I'm the dev behind Noshi-Kanamer 👋
I've shipped WordPress sites (coded or AI-built) with something unchecked -- forgotten noindex, exposed debug.log, default admin username.
So I wrote down all 25 checks. Free, no signup.
https://t.co/0UIe5alf0O
#WPDev#WordPress
@Gustafssonkotte 10 hours, $25, and it's core WordPress -- not some obscure plugin. That's the part that should worry defenders more than the number itself.👀
A security team documented a ransomware attack run start-to-finish by an AI agent -- no human typed a command after the breach.
It broke in, stole credentials, encrypted the database.
When a step failed, it diagnosed and fixed itself in 31 seconds.
#vibecoding#buildinpublic
A WordPress site goes live with debug logging still on.
The log sits at a predictable path. Bots check that exact spot within hours of launch.
DB credentials. API keys. User data fragments. All in plain text.😇
Ever checked what your debug log exposes? 👀
#WPDev#WordPress
Sent a couple of replies from this account so far, and this one landed straight into "probable spam" -- invisible unless someone clicks to expand.
New account life, apparently 🥲
@tobi_salami_@X Hey! I'm an engineer in Japan. I shipped a WordPress plugin that catches what you'd miss before launch, and I'm still actively improving it.
English isn't my first language (translating with a little help), but hoping to get it in front of more people🙂
A founder ships a SaaS built entirely with AI, no code hand-written.
Two days later, the API key was exposed in client-side code.
Attackers maxed out usage and corrupted the database overnight.
AI writes fast. It doesn't always know what "public" means.
#AI#buildinpublic
The default WordPress admin username feels harmless... until you check the login logs.
Bots don't hesitate. Hundreds of attempts a minute, guessing 'admin' + a password list.
One night is enough for five-digit attempts.
Ever looked at your login logs? 👀
#WPDev#WordPress
@ifahimreza AI search really feels like it's becoming the main way people look things up now.
The vaguer my question, the more I reach for AI first these days 🤔