📥 Hello, and greetings from the Central Office!
We believe in being upfront about what happens behind the scenes, so each month we're pulling back the curtain on the work our team put in over the past few weeks. No polish, just the real fixes, releases, and support wins that kept things running for you.
Here's what kept us busy in the first week of July:
We tracked down the source of a payment blocking issue some customers ran into during renewals. Turns out it was Stripe's own fraud detection doing its job a bit too aggressively, not anything broken on our end, and we worked directly with affected customers to get them sorted.
Shipped two releases: PDA Contact Forms Extension v1.2.2 and PPWP Passwordless Authentication v1.0.2.
Helped a steady stream of customers with license transfers, invoices, and payment troubleshooting.
Started digging into a tricky bug affecting protected file links on multilingual sites.
More updates coming your way over the next few weeks. 🛠️
Welcome to WP Defense Lab — your weekly brief on the WordPress news that impacts your business.
This week: a discoverability breakdown shows search clicks are mostly passive discovery now, not search intent, and only the owned layer of email, community, and habit-forming products holds up through the next platform change.
In WP Radar: a critical plugin vulnerability, a caught supply-chain backdoor, an AI citation shift, and what a course marketplace's fee math reveals about who really owns the buyer.
🎥 Did you know we have a YouTube channel focused on WordPress security?
We share step-by-step tutorials on how to secure your site and protect your content.
⚡️ Watch our latest video:
How to Unlock a Password Protected Page With Gravity Forms
👉 Explore the full channel:
youtube/@wpdefenselab
Don’t miss the next one 🚀

Search Isn't Where Discovery Happens Anymore
Discovery happens in many places. Ownership happens on our own platform.
Publisher reach no longer runs through a single channel. Audiences now find content through search, social feeds, AI assistants, podcasts, newsletters, and creators, and most of that discovery happens passively, when nobody is actively looking for a specific brand.
This happens in three phases: passive discovery, where content has to interrupt a scroll; active discovery, where a user engages once inspired; and owned discovery, where email, community, and habit-forming products keep someone coming back on the publisher's own terms.
Only one of those three phases belongs to the publisher.
Search Stopped Being the Filter
The numbers explain why this matters.
Up to 86% of Google clicks are discovery-led rather than driven by a specific search intent, and 52.3% of searches from 18-to-24-year-olds end without a click, compared with 42.7% for people ages 55 to 64.
Live sports searches hit a 70% zero-click rate. Older users click more and are seven times more likely to click an ad, but younger audiences are the ones publishers most need to reach next.
The Owned Layer Is the Only One You Control
Teenagers now spend 4 minutes a day on publisher websites, against 19 minutes for readers over 55.
That gap will not close by publishing more articles into a search results page that increasingly answers the question itself. The framework treats passive and active discovery as necessary but temporary.
A user who never converts to email, a habit-forming product, or a community relationship resets to zero the moment the algorithm, the feed ranking, or the platform's terms change.
Owned discovery is the one phase where a publisher decides the rules.
What This Actually Means for a WordPress Site
None of this is a WordPress problem to solve, and claiming otherwise would be dishonest.
A CMS does not change how Google ranks zero-click results or how a social platform's algorithm allocates reach.
What a WordPress site owner controls is the mechanism that converts passive attention into an owned relationship once it arrives: an email capture that actually fires, a membership or habit-forming product that gives someone a reason to return outside the feed, gated content that trades access for an address.
As audiences increasingly connect with recognizable voices, building the owned layer around people rather than a publication name alone becomes more valuable.
Run the Audit
Pull up last month's traffic. How much of it converted into an email address, a login, or a returning visit that did not originate from a fresh search or a fresh feed impression?
That number is the only one that holds up through the next platform change. Everything upstream of it, however large, is borrowed.
Build a digital marketing strategy that drives better results.
HubSpot Academy's Digital Marketing Certification covers SEO, email, paid ads, social, and AI — in just over 3 hours, at zero cost. Join 200,000+ professionals who have advanced their career with HubSpot Academy. Get started today.

WP RADAR
This week in WP Radar: a critical plugin vulnerability, a caught supply-chain backdoor, an AI citation shift, and what a course marketplace's fee math reveals about who really owns the buyer.
WordPress 7.0.2 Fixes Two CISA-Listed Bugs. WordPress 7.0.2 patched two actively exploited vulnerabilities, prompting forced updates. Sites on versions 7.0.2, 6.9.5, or 6.8.6 are protected. The same roundup also covers All in One SEO’s new hourly alerts for noindex flags and unreachable robots.txt files.
Your Course Platform Owns The Buyer, Not You. A fee comparison shows Udemy's default split leaves creators with about 37% of a sale, while a WordPress site running a free LMS plugin plus standard card processing keeps close to 97%. The bigger cost isn't the percentage. It's giving up the buyer's email, pricing control, and follow-up relationship to the marketplace.
Wordfence AI Catches Backdoor Before Users Did. A supply-chain backdoor hidden in a plugin with roughly 20,000 active installs was caught and removed before anyone downloaded the compromised version. The catch came from Wordfence, not WordPress.org's AI reviewer, underscoring that independent security layers still matter.
WooCommerce Login Plugin Bug Scores 9.8 Severity. A WooCommerce Social Login flaw lets unauthenticated attackers forge an Apple sign-in token and log in as any existing user, including administrators, with no password required. The 9.8-rated bug affects every version through 2.8.7, and store owners should update to 2.8.8 immediately. A feature designed to reduce login friction was also skipping the verification meant to protect accounts.
AI Engines Now Cite Creators Like Publications. Answer engines like ChatGPT and Gemini increasingly cite individual creators alongside traditional publishers, and the demand is growing: Forrester found 94% of B2B buyers used an LLM in 2025. HubSpot is already building a nano- and micro-creator affiliate program to earn more AI citations. The shift rewards trusted expertise over follower count, but the visibility still lives on someone else's platform.

57.5% of all web traffic is now bots, not humans.
Cloudflare Radar crossed that threshold in June 2026, up from 53% in 2025, years ahead of the company's own projection by its CEO's admission.
Kinsta's infrastructure logs show what that looks like on one WordPress store: bots hit add-to-cart URLs 7.67 million times in a single 24-hour period, including 3.75 million requests from ClaudeBot alone, none of which converted or sent a visitor back.
The cost lands as bandwidth and server load long before it shows up as an outage.
That’s all for this week!
Michael - Operator @WP Folio - now WP Defense Lab. Same Plugins. Different Name.
