Author

Paul G.

Paul Goodchild is the founder and CEO of Shield Security for WordPress – a best-in-class security plugin for the protection of critical WordPress-based websites and businesses.

Paul focuses on security features that deliver realworld results for client through the prevention of security breaches before they can happen. Prevention is preferrable over busy-security-work that sees you putting out fires and cleaning up your sites after an infection has taken hold.

Paul maintains that while a security plugin for WordPress is absolutely crucial, “security” is a practice and must involve your entire website and WordPress hosting environment, including your own local device security and security hygiene.

Paul Goodchild Profile Picture

Latest blogs from Paul

ShieldNOTES
July 27, 2026 by Paul G.

4M+ WordPress Sites at Risk & Are You Protected From CSRF?

Stay alert to multiple new WordPress plugin threats, including an Avada Core CSRF risk, and discover how to protect against this type of vulnerability.

Continue Reading →
ShieldNOTES
July 20, 2026 by Paul G.

WordPress Core and Top Plugins Hit by New Vulnerabilities

Two critical WordPress Core vulnerabilities just landed, plus flaws in popular plugins. Get this security roundup and a maintenance guide to stay protected.

Continue Reading →
ShieldNOTES
July 13, 2026 by Paul G.

Plugin Security Red Flags and Safer WordPress Updates Guide

Weekly WordPress security roundup: key plugin and theme vulnerabilities, risk scores, and update guide to reduce threats across your sites.

Continue Reading →
ShieldNOTES
July 6, 2026 by Paul G.

Critical WordPress Plugin Risks & Smarter Spam Defence

Vulnerable WordPress plugins span critical to medium risk this week, some with no fix. Our guide shows how to lock spam out of your forms.

Continue Reading →
ShieldNOTES
June 29, 2026 by Paul G.

OMGF Pro, Elementor, MainWP & More; Spot the Biggest WordPress Threats

Critical 10/10 security risk in OMGF Pro, with others like Elementor and MainWP also flagged. Spot the biggest WordPress threats and learn what to do next.

Continue Reading →
ShieldNOTES
June 22, 2026 by Paul G.

WordPress Plugin Vulnerabilities & the Hidden OptinMonster CDN Attack: Detect What Others Miss

Critical WordPress vulnerabilities, the OptinMonster CDN supply chain attack, and how Shield uncovers the malware that traditional security tools can't detect.

Continue Reading →
Monster vs Shield
June 18, 2026 by Paul G.

Why the OptinMonster CDN Attack Is a Case for On-Site WordPress Security

On 12 June 2026, a compromised CDN credential turned OptinMonster and TrustPulse into malware delivery vehicles targeting WordPress admins. Cloudflare couldn't stop it. A WAF couldn't stop it. We look at why on-site WordPress security is the layer that actually matters here, and what Shield is building next to catch an attack technique most security tools can't even see.

Continue Reading →
ShieldNOTES
June 15, 2026 by Paul G.

20 Critical WordPress Vulnerabilities to Fix This Week

New WordPress plugin and theme vulnerabilities this week. Check the top risks, severity scores, fixes, and hardening solutions to keep your site secure.

Continue Reading →
ShieldNOTES
June 9, 2026 by Paul G.

OttoKit, WPvivid, Blocksy, and More WordPress Vulnerabilities & Lock Down App Permissions

Fresh WordPress plugin and theme vulnerabilities landed this week, some critically severe. Time to update, and time to restrict your connected tool access.

Continue Reading →
Mandate App Security Release Feature Image
June 2, 2026 by Paul G.

Introducing Mandate App Security – Scope What Your Connected Tools Can Do in WordPress

Mandate App Security is a new WordPress plugin that narrows what a connected tool can do after it authenticates with an Application Password. You choose which capabilities to allow, and Mandate enforces that scope on every request the password makes. It's built for sites connecting to AI tools, automation platforms, REST API clients, and MCP connectors.

Continue Reading →
Click to access the login or register cheese