Author: Celestio Engineering
-

A practical GDPR checklist for your WordPress site
Most GDPR advice for WordPress is either a scary wall of legal text or a plugin that promises to make you “compliant” with one click. Neither is honest. Compliance is mostly a set of practical habits, and a WordPress site owner can get the large majority of them right without a lawyer. This is a…
-

Schrems II and the US CLOUD Act, explained for WordPress owners
Two legal developments explain why “where is my data” became a serious question for ordinary WordPress owners: the Schrems II ruling and the US CLOUD Act. Neither is as complicated as the acronyms suggest. Together they say something plain: if a US-controlled company holds your data, that data can be reachable under US law, and…
-

Managed WordPress updates: what we handle for you, and why DIY updates fail
Most WordPress compromises start with something that was out of date. Everyone knows updates matter, and yet updates are the maintenance task that quietly slips, because doing them well is more work than clicking a button and hoping. This post is about what managed updates actually involve: the steps we run so an update improves…
-

Is your EU hosting really EU-owned? How to audit your host’s sub-processors
“EU hosting” is one of the easiest claims to make and one of the hardest to verify. A provider can host in an EU data centre, put an EU flag on the pricing page, and still route your data through companies that answer to laws outside the EU. The good news is that you can…
-

Cleaned but hacked again: why WordPress malware comes back, and how to stop it
You cleaned the site, checked it, and moved on, and a few weeks later the same warning is back. This is one of the most demoralising patterns in WordPress security, and it is also one of the most predictable. Malware that returns is almost never bad luck. It is a sign that the cleanup dealt…
-

WordPress hacked? What to do in the first hour
If you have just realised your WordPress site is hacked, the most useful thing you can do in the first hour is slow down. The instinct is to start deleting files and changing everything at once, and that instinct usually makes the cleanup harder. This is a calm, ordered playbook for that first hour: how…
-

Data sovereignty for WordPress: what it really means for a Swedish site
Data sovereignty is a simple idea wrapped in confusing language. Stripped down, it means this: the data your WordPress site collects should sit under a legal system you trust, and stay out of reach of foreign laws you did not agree to. For a Swedish site that usually means keeping personal data inside the EU,…
-

The best WordPress malware cleaning tools (and when to let engineers do it)
If you suspect your WordPress site has been infected, the first thing you will reach for is a tool. There are several good ones, and knowing what each is for saves a lot of time. Below is an honest roundup of well-known options, followed by the case for when a tool is not enough and…
-

Why WordPress malware comes from outdated plugins
When a WordPress site gets hacked, the instinct is to blame WordPress. Most of the time the core software is not the way in. The way in is a plugin or theme that was out of date, abandoned, or both. Understanding why that is the leading path to infection tells you almost everything you need…
-

Why keeping WordPress updated matters
Updates are the least glamorous part of running WordPress, and the easiest to put off. The dashboard nags, the notifications pile up, and nothing breaks the day you ignore them. That is exactly why deferring updates is so tempting, and why it goes wrong so quietly. Core, plugins and themes all ship fixes on their…