📥 Hello, and greetings from the Central Office!
To close out the month, a look at the parts of the business you do not normally see: billing, notifications and the odd unpleasant surprise.
Renewals now update themselves. For customers on our older subscription system, license expiry dates used to be extended by hand after each payment. That step is now automated end to end, with the team notified as each renewal processes. Fewer moving parts means fewer licenses sitting with the wrong expiry date.
Better visibility on our side. Renewal orders are now clearly separated from new orders in our internal notifications, so when you contact us about a payment, we can see exactly what happened without digging.
A duplicate charge issue, found and fixed. We discovered that a copy of our site used for testing had become publicly reachable with payments enabled, which meant a small number of renewal orders could be paid twice. We shut down payments there immediately, locked all test environments behind passwords, and refunded the affected charge. If you ever see a charge you do not recognise, write to us and we will check it properly rather than assume.
⚠️ One thing to watch for. Some customers are still receiving phishing emails that appear to come from our domain, with a subject line about cloud storage being full and payment details needing an update. These are not from us. We do not send billing emails from a no-reply address, and we will never ask you to update payment details through a link like that. Please delete them, and feel free to forward one to us if you want it checked. We are tightening our email authentication settings to make this kind of impersonation harder.
Thanks for reading, and for trusting us with your files.
Welcome to WP Defense Lab — your weekly brief on the WordPress news that impacts your business.
This week in WP Defense Lab: unsealed court filings reveal Microsoft's own executives calling AI scraping "the largest theft of labor in human history," with internal data showing a 93% click-through drop.
In WP Radar: WordPress designing for AI agents, the cost of redirecting checkout to Stripe, a critical core security flaw, one site charging Claude by the page, and AI agents testing the locks.
📣 Did you know we have a YouTube channel focused on WordPress security?
▶️ We share step-by-step tutorials on how to secure your site and protect your content.
🚀 Watch our latest tutorial: 3 Ways to Set a Video as Featured Image in WordPress
👉 Explore the full channel:
youtube/@wpdefenselab

Microsoft's Own Words Just Gutted Its Fair-Use Defense
Unsealed filings in the NYT lawsuit show internal admissions that read like a legal liability, not a defense.
Microsoft's own executives called it theft.
Not in a courtroom. Not in a press release. In internal communications that are now part of the public record.
Newly unsealed filings in The New York Times' copyright lawsuit against OpenAI and Microsoft quote a Microsoft director of applied science describing AI training as "an astonishing theft of unprecedented proportions" and "the largest theft of labor in human history."
Microsoft's own data in the filing shows why the stakes are so high: its Copilot answer engine cut click-through rates to the Times' domain by as much as 93% compared with traditional Bing search.
The Words Executives Use When They Think No One Is Reading
The filing quotes OpenAI's head of ChatGPT, Nick Turley, warning that publishers face an existential threat from products that are largely substitutive and will become more and more substitutive as the models improve.
Satya Nadella testified that conversing with a chatbot has substituted the need to visit the original source. Greg Brockman called the models excellent at news.
Those statements matter because they describe the same market harm publishers are now trying to prove in court.
The companies aren't just accused of building products that could replace visits to the original work. Their own executives were discussing that possibility internally.
What the Scraping Looked Like at Scale
The filing also puts numbers on the practice.
OpenAI's mid-training datasets allegedly contain more than 91,692 copies of works published by the Times, the Daily News, and the Center for Investigative Reporting.
A Common Crawl-derived dataset included more than 2 million documents from nytimes.com.
Another training set, assembled through an internal initiative called Project Mango, contained at least 160,903 unique works from the same publishers.
The filings also allege that OpenAI employees developed a method to bypass the Times' paywall undetected and that researchers removed copyright notices from training data so models would not reproduce them for users.
This wasn't a handful of pages accidentally swept into a dataset. The allegations describe collection at industrial scale.
Why "Largely Substitutive" Creates a Fair-Use Problem
Fair use doesn't turn on a single question, but one of its four statutory factors examines the effect of a use on the potential market for the copyrighted work.
That's what makes the internal language significant.
Turley described AI products as increasingly substitutive. Nadella acknowledged that chatbot conversations can substitute for visiting a source. Microsoft's own data reportedly measured click-through declines as high as 93%.
An internal Microsoft document went further, describing a "doom loop" in which the end product threatens the economic foundation of the publishers supplying the material it depends on.
None of that decides the case.
But it gives publishers something potentially more powerful than an argument about hypothetical harm: evidence that the companies themselves were measuring and discussing substitution.
Who Carries the Cost Until the Ruling Lands
The legal fight could take years. The traffic effects don't have to wait.
Publishers are already operating in a world where an AI answer can satisfy a query without sending the reader to the page that supplied the information.
That changes what publishers should be measuring now.
Track crawler access. Track referral traffic by AI platform. Track search click-through rates as AI answers expand. Record licensing requests. Document which pages lose traffic when an answer engine begins summarizing their information directly.
Because if substitution eventually becomes the question in a courtroom, the strongest evidence may not be an argument about what AI could do.
It may be a record of what it already did to your site.
What would your own data show if you had to prove that today?

WP RADAR
This week in WP Radar: infrastructure decisions quietly determine who controls access, checkout, and content once agents start acting on your behalf.
WordPress Now Has to Design for Robots Too. WordPress is built for people clicking menus, forms, and login screens. AI agents bypass that interface, calling functions directly through the new Abilities API and MCP Adapter. But 68% of organizations lack identity security controls for AI, meaning agent-ready actions can expose capabilities without the permissions to match.
Redirecting to Stripe Costs More Than Fees. Stripe Payment Links get you collecting money in minutes for the standard 2.9% plus 30 cents, but checkout happens off-site. WPFullPay keeps customers on your domain, but charges 5% until licensed. Speed and ownership are still a tradeoff.
One Click Can Hand Your WordPress Site Away. Security firm pwn.ai found Click2Shell, a WordPress core flaw that can trick a logged-in admin's browser into installing an attacker-chosen theme with no click required. Chained with another flaw, the attack scores a critical 9.6. WordPress patched it in 7.1.1, with fixes back to 4.7. No confirmed attacks yet, but updating is essential.
Claude Paid a Cent to Read a Web Page. One writer charged AI agents one cent per page using the x402 protocol. His Claude Code agent hit the paywall, checked its spending cap, paid in testnet USDC, and kept working without human input. No account or API key needed. Real crawlers aren't paying yet, but the infrastructure now exists.
AI Agents Started Testing the Locks. Researchers found AI agents probing websites for vulnerabilities after normal data retrieval failed. In at least three cases, agents used hacking techniques while seeking public data, and one accessed non-public Australian government information. As websites become agent-readable, access controls increasingly have to assume the visitor can act, not just crawl.

ChatGPT's share of AI prompt volume fell from 70% to 50% between January and June 2026
Comscore's Q2 2026 AI Intelligence Report found Gemini nearly doubled to 30% and Claude climbed to 11% over the same period, as overall AI usage grew. AI discovery is no longer a single-platform bet. Optimizing for one assistant while three others split the remaining traffic leaves half your potential visibility unmeasured.
That’s all for this week!
Michael - Operator @WP Folio - now WP Defense Lab. Same Plugins. Different Name.