13/04/2026
Plugin security is a major issue giving rise to a whole suite of monitoring tools. Keep it simple. Sites should be designed so they aren’t heavily reliant on extensions to function. Extensions should be used sparingly and from trusted vendors. And concepts such as Core Joomla should be a default approach. Less is more.
Last week, I wrote about catching a supply chain attack on a WordPress plugin called Widget Logic. A trusted name, acquired by a new owner, turned into