Most people assume WordPress sites get hacked because of outdated plugins or weak passwords. According to Tom Raef, founder of We Watch Your Website, that assumption is wrong. His data from monitoring over 3 million websites shows that more than 65% of infections come from stolen user credentials, not brute force attacks or neglected software updates. That finding alone should change the way hosting companies and agencies think about security.
In this episode, Jesse Friedman and Tom Raef walk through real examples of how hackers steal session cookies, mask their entry points with fake brute force attempts, and exploit developer accounts that should have been removed months ago. Raef explains how his team watches access logs in real time and traces infections back to their source, often uncovering plain text admin passwords stored in web-accessible files. The conversation also covers why local device hygiene, like running antivirus software on your own computer, is one of the simplest and most neglected lines of defense.s
Jesse and Tom also discuss the challenge hosting companies and agencies face when communicating security risks to non-technical clients. How do you educate someone without scaring them away from WordPress altogether? They explore practical approaches, from activity logs that provide forensic proof of what happened to free tools like Jetpack that offer brute force protection and vulnerability detection.
Links:
- We Watch Your Website
- Badware Busters
- Sophos
- Wordfence
- JustHost
- HostMonster
- Have I Been Pwned
- Jetpack
- Claude
- Quick Forget
- Patchstack
Chapters:
00:00 Teaser
00:22 Introduction
01:12 How did We Watch Your Website get its start in security?
02:46 How did a partnership with Bluehost help launch the business?
07:52 What are the most common ways websites actually get hacked?
09:36 How are hackers using brute force attacks to cover their tracks?
11:50 What should hosting providers teach website owners about local device security?
14:48 Why do website owners struggle to understand their own security risks?
18:10 How should agencies explain security costs to cautious clients?
20:22 How can activity logs help resolve blame when a site is compromised?
23:03 How is AI being used to find plugin vulnerabilities before hackers do?
26:50 Can AI help automate plugin review and code patching at scale?
Transcript
Jesse Friedman: Welcome to Impressive Hosting, a podcast about the role hosting plays in shaping the open web. I’m your host, Jesse Friedman. On the show we go deeper than uptime and dashboards. We talk about hosting as infrastructure, about ownership, independence, and what it takes to build ethical, high-end WordPress hosting that actually serves creators, businesses, and the internet itself. Before we dive in, head to impressivehost.net. That’s where you can comment on episodes, ask follow-up questions, and help shape future conversations. You’ll also find links to follow, like, and subscribe wherever you listen. Today, I’m very happy to say that we have Tom Raef from We Watch Your Website on the show. Tom’s here to talk to us about AI security and what it takes to keep the open web safe. Tom, thanks so much for joining. Tell us a little bit about yourself.
Tom Raef: Thank you for having me. Yes. I started doing website security back in 2007 and I had become a member of an organization called badwarebusters.org. It was started by Max Weinstein, who’s now at Sophos, the antivirus company. And I believe it was tied with Harvard and possibly Google. But anyway, it was an open forum. People could post like security issues. Their website had been hacked or whatever. And it could be anything, WordPress, Joomla, any platform. And they would ask questions on there and ask for advice on how to find the malware and remove it and possibly why it happened. So I just loved it because it gave me an opportunity to learn a lot. And I just kept at it. Eventually became one of the top contributors there. Daniel Cid, who’s one of the founders of Wordfence, was also one of the top members there too. And so we were just, you know, do whatever you could to help people out. Now you rarely did you get access to their site. You just had to try and help them and they would ask questions and so forth. So anyway, from there, I started blogging a lot about the infections that we were finding. One day I get a call from a guy and he says, my boss’s website just got hit by what you posted about yesterday. And so we talked for about an hour and a half. He calls me back the next day. He goes, hey, that information was spot on. He’s like, I see you host with us. I’m like, who are you? He’s like, I’m Alex Lundquist. I’m a level three here with Bluehost. My boss is Matt Heaton, the owner of Bluehost. How’d you like it if we started sending you some business? So I was like, oh, okay. You know, so, and yeah, they would send, like, they would tell all their terms of service people and all their tech support people, anybody calls in with malware issues, just send them to We Watch Your Website. So, you know, that helped launch us to a degree. But I also had to automate things and I’m a programmer from way back.
Jesse Friedman: I mean, that does go back to the early days of Bluehost. I mean, that’s a long time ago.
Tom Raef: Yeah. They had one guy in terms of service, Richie Jackson. Richie and I became very good friends and matter of fact, he invited me to his wedding. But so at any rate, yeah, we got super busy. And I said I’m a programmer from way back, you know, I started programming on IBM punch cards.
Jesse Friedman: Yeah.
Tom Raef: Way, way back. So anyway, had to automate processes because we were getting so much business and then Bluehost bought JustHost and we were also doing stuff with HostMonster and, you know, a bunch of them. Word spread. So yeah, we had to automate things and we kept going, but I always wanted to know how each website was infected. It’s just one of those things. And when I was a kid, I had to understand how a lawnmower worked, so I took it apart, couldn’t put it back together, but I took it apart and tried to figure it out, you know, the whole combustion engine thing. But so that helped me a lot to understand what we needed to do. So we added log file monitoring. We added, you know, scanning databases, you know, as the hackers progressively got better and better at attacks, we had to keep up. So we became really good with htaccess and PHP.ini files.
Jesse Friedman: Right.
Tom Raef: So back in the day.
Jesse Friedman: And so over that time, you’ve actually secured millions of sites, right?
Tom Raef: Yes. Yeah, we’ve removed malware from over 8 million websites since 2007. We actively monitor, it’s, I have to change our website because it says over 2 million, but, you know, we’re a little over 3 million websites that we actively monitor now. And that’s, you know, like I said, scanning the access logs live, scanning the database changes and any file changes. So we see stuff happening as it’s happening.
Jesse Friedman: Yeah, that’s interesting.
Tom Raef: That gives us the insight we need to tell people, yeah, okay, this user account on your WordPress site called developer, it was used here, you know, from this location, I’ll say San Francisco at this time. And then, you know, two hours later, somebody used that same account from Eastern Europe and it’s already authenticated, so we know for sure that it was a stolen session cookie. You know, you kind of develop this way of thinking about how hackers work. And we’ve seen instances where hackers actually log in and tunnel in from the developer’s desktop computer and infect a site while the developer’s logged in doing actual work. I mean, it’s crazy. So, but yeah. And then, you know, obviously over the past year or so, as AI has grown and we see more of it being used by hackers, we had to grow with that. So less of our stuff, in the early days, I had to learn regular expressions and we used those for identifying malware. But, you know, as things progressed, you can’t have a signature for every piece of malware. It’s just impossible. So we adopted machine learning and AI. And that’s core to our business now.
Jesse Friedman: Yeah, that’s really interesting and that’s actually how you and I connected. I want to circle back to AI and some of the things that you’re working on, especially around the way in which you’re trying to help out with the WordPress community as a whole. But before we dive into that, you had mentioned that, you know, you were the type of kid who had to figure out how the lawnmower works. I’m sure your toaster probably got taken apart a few times. When you think about this and you talk to someone who’s maybe a little bit less experienced, and the reason I ask is because we may not necessarily have that type of audience member on this podcast, but hosting companies and agencies are listening and they’re often building for novice users. And, you know, I think that those companies have a responsibility to make sure that they’re securing those sites, but at the same time, they have to balance that against not making WordPress look overly complex, making it look like it’s actually insecure or things like that. So I think sometimes they end up taking some security measures and trying to automate it, which is great. I think that’s good. But also sometimes I think they try not to over-educate in a situation where they might be a little bit more fearful, but like, if you were to tell a hosting company, what are the two or three most vulnerable areas once a user starts using a website, you know, what is it that they should be looking out for? What is it that they should be watching for?
Tom Raef: Well, it’s a great question. Too many times, you know, I see on LinkedIn, on Facebook and various groups, people say and they just start throwing out numbers. They’re like, 80% of WordPress websites are infected due to outdated plugins or nulled plugins. Everybody likes to throw out that term nulled plugins. But you know, our data, like I said, I’m a data guy. Our data shows that like over 60, 65% of websites are actually infected due to stolen user credentials. And it’s a part of security that few people talk about. And I talked to one guy, he’s over in England, and I talked to him about our report that we came out with a couple years ago, I think it was 2024, info-stealers and stolen authentication cookies. And he just bluntly told me, he’s like, yeah, he says, I’m not going to help you promote this. I was like, why not? You don’t believe my numbers? And he’s like, no, no, no, but there’s nothing I can do to prevent it, so why would I promote your data if I don’t have a solution for it? I’m like, okay. So yeah, getting back to your…
Jesse Friedman: I mean, I guess I would argue that making people aware of the problem is probably the first step towards solving it. Just for clarity, you’re saying the 65% are from stolen credentials. Does that include brute force incursions and other things? Or are you saying strictly that it’s people who have actually either through social ways or getting into your inbox and your email, things like that? They’re actually stealing the username and password.
Tom Raef: They’re actually stealing the username and password.
Jesse Friedman: Okay.
Tom Raef: And in fact, I just posted on LinkedIn that we’re seeing, rarely do we, because we’re watching the access log. So we see when somebody’s trying to log in, you know, we see these brute force attacks. And we just saw one a couple weeks ago we reported to the VPS provider. Again, I won’t name names. I don’t like doing that. One website over a 24-hour period, over 400,000 brute force attacks from one IP address to one website. I mean, that’s trying really hard.
Jesse Friedman: That’s a red flag, right?
Tom Raef: But I also think, and we report those to the VPS providers by the way, but we’re also seeing where the hackers try that and then, like there’s a break in the action, then they just log in. So you could think, okay, well they finally found the password.
Jesse Friedman: Yeah.
Tom Raef: But because a number of these, like, we got a chance to, we deal with a lot of small hosting providers, agencies, and so forth, but eventually we get a chance to talk to the people that own the website and like, you know, tell me about your password. And they’re like, no, you know. With some of these recent ones, it actually as the admins log in, it actually stores the username and plain text admin password in a file on the website that’s in the web folder. So hackers can just go to that file and boom, it’s right there.
Jesse Friedman: Oh, geez.
Tom Raef: And it’s, you know, it’s a good password. You know, 10, 12 characters, uppercase, lowercase, you know, the whole, everything everybody recommends. But yet it was used to infect that website. So you’re like, how does that happen? It wasn’t a brute force, but so it’s like they’re trying to mask their attack. You know, we’re just going to make this guy assume that, or make these people assume that, you know, we finally found out what the password was. No, no. Come on. You don’t have that in your dictionary, I guarantee it.
Jesse Friedman: Right.
Tom Raef: So I think they’re just trying to mask things. So, but the big thing…
Jesse Friedman: Oh, that’s interesting. So this is like in an effort to be kind of aloof or covert around the way in which they’re getting in. They start with a brute force attack just to kind of cover their tracks there.
Tom Raef: Right.
Jesse Friedman: Interesting.
Tom Raef: So, but the big thing I would tell hosting providers is they have to educate website owners on local hygiene. I don’t know what, you know, it’s an anti, you gotta have a local antivirus.
Jesse Friedman: Yeah.
Tom Raef: Nothing against, I don’t have anything against anybody unless you’re a Detroit Red Wings fan. I’m only kidding. Mac users have been told for years and they still believe it. I don’t need an antivirus, I’m on a Mac. That’s why I bought a Mac. ‘Cause it’s secure. But no, I mean, Macs are getting hacked all the time. So they have to educate the website owner and all admins must have a good anti-malware program running on their local device. No ifs, ands, or buts about it, they have to run full system scans because, you know, once you understand how antivirus programs work, you know, they get updates all the time. Well, if you get a virus after the last update, it’s not going to see that virus until you scan it again. Anyway, the local device hygiene is critical. Obviously, you know, keeping plugins and WordPress core up to date, you know, is critical. And enforce the fact that people need to maintain a minimum list of admins on their WordPress site.
Jesse Friedman: That’s a good one too. Yep.
Tom Raef: We just cleaned up a bunch where the developer, he’s got 14 servers, average of about 28 sites per server. And they were just getting annihilated with this recent issue with the plain text passwords in a file. And it was a developer that they haven’t used in over a year, the account that was compromised. Oh, come on. You know?
Jesse Friedman: Right. I mean, I’ve seen that a hundred times. Yeah. Actually, I can remember times where I used to help out with the local WordPress meetup here in Rhode Island and I’d ask someone to like, you know, add me to their account or something like that so I could help them out. And the reason I asked them to add me was because they actually just wanted to give me their username and password. And I was like, no, no, no, no, no. Please, please don’t do that. You know? And so they make me a user and then I would realize that like, you know, months go by. A year, a year or two go by and I’m still an admin on their site. And, you know, luckily I’m a good guy. I have no intention to do anything with it, but at the same time, it’s like, you know, you gotta be aware of who’s on your site. And I think that people don’t necessarily understand that. They don’t necessarily, I mean, we talk about this on this podcast a lot, that the barrier of entry to building a WordPress website has only gone down over the years, so you need less technical experience every year to be able to run a WordPress website. But at the same time, that means that you may not have taken a class on good password hygiene. You may not have taken a class on like how to secure your own personal computer half the time. I mean, you’re talking about people not necessarily remembering to take people off as admins, but half the time people don’t even know why they would even be at risk of having a website hacked. You know, they don’t understand, I’m running a small blog, why would anybody want to hack my site? Well, the reality of the situation is, and we say this all the time, is that they’re not necessarily always trying to get into your, like it’s not personal. It’s not necessarily that they’re trying to get into your site, it’s that they’re trying to get into all sites and they’re doing it very quickly. And I think the other thing too is that people don’t necessarily recognize, and I think this is something where the WordPress community could actually, either the WordPress community or hosting companies could do a better job of this, but we have services out there that identify when your username and password have been stolen off of another website. Like Have I Been Pwned, for example.
Tom Raef: Right.
Jesse Friedman: And people don’t necessarily recognize this, but if you are using the same username and password for your WordPress website or your Gmail account that you’re using for, you know, some like streaming service or some random website somewhere else, and that website gets hacked. They’ll take those usernames and passwords, they’ll sell them, and then they’ll just try those on any service out there, whether it’s a WordPress website or whatever. So if they can identify, which you can, that your email exists on a WordPress instance, then they can also just go out and see all the passwords that have been revealed from your previous accounts and just keep trying those. And so I think in the past, you know, we worked very hard, at least, you know, in my past in working on the UX of security for websites, I’ve worked very hard to try to teach people to create strong passwords. Now it feels like the messaging has changed to make sure you’re using a different password for everything. Don’t email people usernames and passwords like we have a service at Automattic that came over when we were working on Brute Protect and we joined Automattic, we had something called Quick Forget, which is a really nice little service. It’s basically, you can drop anything into it and it creates a URL that shares that information, and then it kind of has like a Mission Impossible style self-destruction that after X number of views that you’ve determined, it gets wiped out and is gone forever. And you know, people think about, well, why is that important? Well, think about it this way, if you need to email, if you actually do need to send credentials to somebody, if you’re doing that via email, then that lives in your inbox and their inbox for the rest of time until you actually delete it. Which most people don’t. So if I get access to your inbox, I can actually see everything that’s ever been passed along. But if they see a quick forget URL, they’ll click it and it’s gone. It’s gone forever. So, you know, things like that I think are really helpful. And I think that, you know, when we think about the responsibility that hosting companies have to this, I think they can be doing a better job of informing the customer. I think we’re all a little bit guilty of this because again, we don’t want to impose fear. You don’t want the customer to feel like it’s scary because I don’t think that fear works in this way. I think it just kind of drives them away. But at the same time, helping them to feel a bit more secure I think is a really good thing. Which actually leads me to my next question. You know, when we talk about agencies, a lot of times I talk to agencies who provide a service, even a management service for an end customer, a client, but they don’t necessarily pay for all these features for these customers. A lot of times what agencies do is they’ll provide their services. But the hosting, additional security tools, emails, things like that all get charged to the end client directly. And then a lot of times the agency’s left trying to explain to these customers why they should be buying security products, why they should be doing certain things. So, you know, I’ll ask you the kind of the same question about hosts, but to agencies, like, how would you advise an agency to make sure that they’re helping their customers to stay secure and if they have a very cautious customer, you know, how do they address that?
Tom Raef: That’s a good question as well. It’s kind of a double-edged sword because since 2007, people, when they found out that we were working with Bluehost. They actually would accuse Bluehost of hacking their website so they could sell them our service and then we would kick back money to Bluehost. I mean like, like, come on, just own the fact that, you know, you had “one” as your password and you got hacked. You know, I mean, come on. So it has always been, you know, a struggle there because it’s, years ago before I got into computers, I was selling copiers and people would always say, you know, copiers are one of those things that, you know, you can’t glamorize when you sell it. You just, if people have the need and they recognize the need, they buy it. And it’s kind of that way with website security too. But what they can also do is they can ask the customer, okay, you know, we do everything possible from our end to try and keep your site safe, but if your site gets infected and it’s displaying, you know, pharmaceuticals or redirecting people to this or that, or it’s trying to do a drive-by download on your visitors’ websites, you know, what would that cost you in downtime, in reputation management and so forth, versus what, you know, proactive security is going to cost you. And you know, just to be honest with you, you just have to lay it out to them like that, let them make the decision. But, you know, typically our clients have been, are ones that have already been infected and, but like I said, if they have a server and, you know, we, one of the sites on the server gets infected, they’re just like, yeah, just sign my whole server up for your service. You know, just cover them all. So it, and you can, you know, hosting providers and agencies can talk to their customers about, you know, that’s typically the way it happens. But you know, at that point, you know, then you’re in a scramble to clean the website, fix it, patch it, and get it back online. But then you still have the reputation management to deal with. So yeah, reputation management and downtime are the two biggest, you know…
Jesse Friedman: Yeah.
Jesse Friedman: I think you’re a hundred percent right on the reputation management. One of the things that I talk about all the time with, you had mentioned previously like having an activity log or other types of logs, Jetpack, you know, the plugin made by Automattic. Jetpack has an activity log that identifies exactly what user took what action on the site. And the thing I love about it is that it becomes a third-party unbiased claim as to who made what change. And I think you’re right. I think, you know, you mentioned earlier that customers were blaming Bluehost. I don’t think that’s rare. I think that’s quite common, that they’ll blame, they have no recollection in their head that they could be at blame either directly or passively. So, you know, who’s going to take the hit? It’s not going to be them. And so whether it’s the hosting company or the agency, you know, they’re going to point fingers and I think the agency’s kind of left with, well, it wasn’t us. We know it wasn’t us. How do we prove that? Well, an activity log can actually be quite helpful ’cause then you can just send along the activity that actually occurred, whether it’s something that went maliciously or just an accident that happened, you know? And I kind of think about security a little bit more than just purely the fact that something was injected or hacked, but also just like the integrity of your website and whether or not like the content’s moving around or you deleted something by accident or whatever. It’s obviously a different layer of security, but it’s still an important one. And I think having that activity log can be really good at, you know, making it so that those agencies don’t feel like the fingers are being pointed at them, they can actually diffuse the problem quite nicely. So that’s another tool that people can use in the communication with these customers and these clients. I think.
Tom Raef: You know, Jetpack has some great features. Some people say it’s outdated, it’s whatever, whatever. But I mean, if you look at the features that they have, it’s a great tool ’cause yeah, like for forensics of any type, you know, like you said, somebody changed something, who did it? When did it happen? What do we need to, you know, you’ve got those activity logs.
Jesse Friedman: Right. And to be completely biased. Like I think that Jetpack is also great in the sense that so many of its features are completely free too. So, you know, you have that brute force protection service. You have the ability to track other things that are happening. You have vulnerability detection that’s all free. And so, you know, it’s an opportunity to try and bring it to those customers in a way that makes it accessible so that money isn’t a problem there.
Tom Raef: Right.
Jesse Friedman: So, you know, we got connected on AI. I kind of want to pivot to that. We may not have enough time to finish in this episode. We might go on to another one. But you and I connected because you were talking about ways in which AI could help with identifying vulnerabilities and plugins. Let me pause there and just let me ask you this. How’s that going? What is it that you’re working on?
Tom Raef: It is, I’m hoping to have it done by next Wednesday for WordCamp. We’re going out there. I’m going out there. And it’s, you know, you think of AI as this all-knowing being, you know, the guy behind the curtain in the Wizard of Oz. And, you know, my first thought was, well, you just, you know, upload all the, like, upload an entire plugin to Claude and tell it to find vulnerabilities. Eh, it’s not quite that smart or automated. But, so what we did is, most of the programming that we do within our organization is all in Python. So we wrote a bunch of Python code that will trace like authentication tainting, all sorts of things, and it’ll trace it through. And then only if it finds something that meets a certain threshold will it involve an AI model. And we typically use Claude, although we’ve got some other ones embedded as well, so it’ll send it off to that, to the AI model for further analysis. And it’s amazing because straight, you know, programming logic, you know, in Python, it can find things that are suspicious, but when you submit it to AI and it comes back and says, no, because this, this, and this, you’re like, oh. Wow. Okay. Yeah, that makes sense. Now I can see it. Because it is funny, when we first started working with this, one of the guys on my staff actually submitted. He thought for sure it was a vulnerability. I don’t remember what plugin it was. So bam, he fires up Wordfence and submits it and like within 15 minutes they replied back, no. And you only get two more tries before they, you know, put a lock on your account. You know, we don’t have all day to be chasing rainbows and stuff, but, and sure enough, you know, once we involved the AI to actually analyze that section of code with the information that our Python program was able to supply it, it came back and said, no, this isn’t, you know, this, you need admin access and even then you need this and that. And so, you know, the stars have to be in alignment and you have to, it has to be the first Tuesday of the month. And then you might have a vulnerability there, but, so.
Jesse Friedman: So it’s been far more effective in actually identifying true vulnerabilities over false positives.
Tom Raef: Yes. Yeah. The other part that we built into it, and I’ve never developed a plugin, so this was just one of those things, talking to people in different groups on Facebook and LinkedIn, like, you know, I submitted a plugin to, you know, WordPress and I still haven’t heard back, you know, it’s been three weeks, it’s been four weeks, it’s been this, that, whatever. And I was like, you know what? I said, I’m an automation guy, so I’m like, there’s gotta be a way to automate this. So first thing we did was download the guidelines WordPress provides for plugins and like, okay, because we see a lot of plugins and a lot of them don’t meet those guidelines. So like, we’re going to build into our plugin analysis, does it meet the guidelines? And then we’ll start hitting it for vulnerabilities. But like I said, yeah, incorporating AI into the whole vulnerability analysis part has just been huge. And you know, when you think about it, you know, things you read, hackers are using AI to find ways to get into websites, whether it be pen testing, static code analysis, whatever. They’re using AI to find ways into websites. So why can’t that same AI properly managed and utilized defeat that, find it, find the vulnerabilities first. I have absolutely nothing but respect for Wordfence and what it does. But when you think about it from an IT perspective, you know, you’re paying for a service to protect your digital assets from something that should have been taken care of before it was even implemented. So, you know, if you had an automated process, you could have something that would scan all the plugins, and I know there’s what, 61,000 of them, scan them and then, you know, help people actually patch the code. That’s the other part that our system does. If it, when it finds a vulnerability, it’ll analyze the code and then produce code that will tell you, here’s how you should handle that. Here’s the changes you need to make in order to prevent this vulnerability from being exploited.
Jesse Friedman: Yeah, so you mentioned that there’s 60,000-something plugins. I think the problem is, is that because of the nature of our end users of WordPress, feeling a little bit nervous about keeping things up to date, sometimes they feel like hitting update on something might actually break something or that makes them nervous. We don’t actually have just 60,000 plugins, right? We have 60,000 plugins times, however many versions of those plugins exist in the wild, and that number gets quite large. I want to continue this conversation. This is such a good conversation. I want to know more about the way in which AI is going to play a role in protecting sites. Because I think we’ve had this long-standing kind of ethical battle with hackers where we’re trying to learn from them what they’re doing to infiltrate, and then how can we use that to harden things. And so now we’re using AI on both ends. How do we continue doing that? And I want to continue that conversation, but I think we need to take a pause here and come back at another, come back next week and have another episode to continue this conversation. Tom, thanks so much for joining.
Tom Raef: Yeah. Thank you very much. I love talking website security, so anytime.
Jesse Friedman: Great.





Leave a Reply