Thomas Raef from We Watch Your Website argues that every hosting company should be analyzing access logs and scanning for threats in real time using AI, not waiting until a site is already compromised to review what went wrong. In part two of his conversation with Jesse Friedman, the two explore what it would actually take for hosts to bring that capability in-house and why farming security out to third-party vendors is not always the most cost-effective path.
The conversation turns to a thorny question at the heart of WordPress security and open source. Raef has built AI-powered skills files that detect vulnerabilities, but open-sourcing them could give hackers a roadmap. Jesse suggests that organizations like the Secure Hosting Alliance might provide a trusted channel for sharing these tools among verified hosting companies without exposing them to bad actors.
Beyond detection, Raef reveals that his plugin analyzer can produce corrective code when it finds a vulnerability, potentially cutting the WordPress plugin review cycle from weeks to days. Jesse and Tom discuss why this kind of contribution could be a game-changer for the volunteer-driven plugin review process, and why fixing the source of vulnerabilities is always better than handing out band-aids after the fact.
- We Watch Your Website
- Secure Hosting Alliance
- Patchstack
- Jetpack
- Wordfence
- What the Frick Is Managed Hosting (Season 1 Episode)
Click here to watch a video of this episode.