Paul G.
Paul Goodchild is the founder and CEO of Shield Security for WordPress – a best-in-class security plugin for the protection of critical WordPress-based websites and businesses.
Paul focuses on security features that deliver realworld results for client through the prevention of security breaches before they can happen. Prevention is preferrable over busy-security-work that sees you putting out fires and cleaning up your sites after an infection has taken hold.
Paul maintains that while a security plugin for WordPress is absolutely crucial, “security” is a practice and must involve your entire website and WordPress hosting environment, including your own local device security and security hygiene.
Latest blogs from Paul
4M+ WordPress Sites at Risk & Are You Protected From CSRF?
Stay alert to multiple new WordPress plugin threats, including an Avada Core CSRF risk, and discover how to protect against this type of vulnerability.
Continue Reading →
WordPress Core and Top Plugins Hit by New Vulnerabilities
Two critical WordPress Core vulnerabilities just landed, plus flaws in popular plugins. Get this security roundup and a maintenance guide to stay protected.
Continue Reading →
Plugin Security Red Flags and Safer WordPress Updates Guide
Weekly WordPress security roundup: key plugin and theme vulnerabilities, risk scores, and update guide to reduce threats across your sites.
Continue Reading →
Critical WordPress Plugin Risks & Smarter Spam Defence
Vulnerable WordPress plugins span critical to medium risk this week, some with no fix. Our guide shows how to lock spam out of your forms.
Continue Reading →
OMGF Pro, Elementor, MainWP & More; Spot the Biggest WordPress Threats
Critical 10/10 security risk in OMGF Pro, with others like Elementor and MainWP also flagged. Spot the biggest WordPress threats and learn what to do next.
Continue Reading →
WordPress Plugin Vulnerabilities & the Hidden OptinMonster CDN Attack: Detect What Others Miss
Critical WordPress vulnerabilities, the OptinMonster CDN supply chain attack, and how Shield uncovers the malware that traditional security tools can't detect.
Continue Reading →
Why the OptinMonster CDN Attack Is a Case for On-Site WordPress Security
On 12 June 2026, a compromised CDN credential turned OptinMonster and TrustPulse into malware delivery vehicles targeting WordPress admins. Cloudflare couldn't stop it. A WAF couldn't stop it. We look at why on-site WordPress security is the layer that actually matters here, and what Shield is building next to catch an attack technique most security tools can't even see.
Continue Reading →
20 Critical WordPress Vulnerabilities to Fix This Week
New WordPress plugin and theme vulnerabilities this week. Check the top risks, severity scores, fixes, and hardening solutions to keep your site secure.
Continue Reading →
OttoKit, WPvivid, Blocksy, and More WordPress Vulnerabilities & Lock Down App Permissions
Fresh WordPress plugin and theme vulnerabilities landed this week, some critically severe. Time to update, and time to restrict your connected tool access.
Continue Reading →
Introducing Mandate App Security – Scope What Your Connected Tools Can Do in WordPress
Mandate App Security is a new WordPress plugin that narrows what a connected tool can do after it authenticates with an Application Password. You choose which capabilities to allow, and Mandate enforces that scope on every request the password makes. It's built for sites connecting to AI tools, automation platforms, REST API clients, and MCP connectors.
Continue Reading →