Jul 29, 2026 · 39 min · 11 segments
Maciek Palmowski is on the podcast today to discuss his WordCamp Europe presentation on whether "secure hosting" lives up to its claims in the WordPress ecosystem. He described penetration tests of…
Maciek PalmowskiGuestNathan WrigleyHost[crowd murmuring] [objects clattering] [upbeat music] Welcome to the Jukebox Podcast from WP Tavern.
Does the marketing match the reality? If you'd like to subscribe to the podcast, you can do that by searching for WP Tavern in your podcast player of choice, or by going to wptavern.com/feed/podcast, and you can copy that URL into most podcast players.
If you have a topic that you'd like us to feature on the podcast, I'm keen to hear from you and hopefully get you or your idea featured on the show.
Maciek is based in Poland and works at Patchstack, one of the companies in the WordPress ecosystem dedicated specifically to security.
At Patchstack, Maciek collaborates with other security professionals on industry reports, bug bounty programs, and solutions for agencies, product owners, and hosting companies aiming to secure their client sites.
I met up with Maciek at WordCamp Europe, and we discussed his presentation there.
It examined the claims of secure hosting made by many WordPress hosting providers.
He describes how Patchstack set out to test these claims with real-world penetration testing using 30 known plugin vulnerabilities across multiple hosts, employing standardized methodologies and validating their results independently.
The majority of WordPress specific attacks still get through, and there's a significant gap between the marketing hype and real protection.
The conversation starts with Maciek's background and how his journey in the WordPress security space led to a focus on the promises made by hosts.
From there, the discussion gets into the research approach, the selection of well-known vulnerabilities, consistent testing across different hosting environments, and the surprising result that even hosts with identical security tooling produce drastically different outcomes, showing it's not just about the tools you use, but how you use them.
Every layer will have holes, so you need multiple overlapping defenses and honest communication from hosts about their limitations.
We also explored whether an industry-wide standard or badge for secure hosting is feasible or even desirable, given how easy it is for strong marketing claims to outpace reality.
AI also enters the conversation, increasing both the speed and sophistication of attacks, and making patching and processes even more important, especially as the volume of vulnerabilities continues to rise and the time to exploitation drops.
If you're interested in understanding what secure hosting really means, how to ask intelligent questions of providers, and the realities of WordPress security in 2026, this episode is for you.
If you'd like to find out more, you can find all of the links in the show notes by heading to wptavern.com/podcast, where you'll find all the other episodes as well.
Read the full transcript.
Create an account to read the whole episode, search across every transcript, and follow the shows you care about.