Title: August 2026 – Making WordPress Secure

---

#  Monthly Archives: August 2026

 [  ](https://profiles.wordpress.org/rfaile313/) [Rudy Faile](https://profiles.wordpress.org/rfaile313/)
4:52 pm _on_ August 28, 2026      

# 󠀁[The Core Security Initiative](https://make.wordpress.org/security/2026/08/28/the-core-security-initiative/)󠁿

Over the past year, the WordPress project has seen a substantial increase in the
volume of incoming security reports. Much of this growth reflects the rapid advancement
of frontier AI models and their growing capability to assist with security research:
it has never been easier to analyze code for potential vulnerabilities, and reporting
volume across the whole WordPress ecosystem has risen accordingly.

This is a good problem to have: more eyes on WordPress makes WordPress safer, but
it requires the project to scale how we triage, validate, and resolve what comes
in. The topic came up during the security team meeting at [WordCamp US](https://us.wordcamp.org/2026/)
last week, and today we’re sharing more about the work underway.

The security team has begun a coordinated effort called the **CoreCore Core is the
set of software required to run WordPress. The Core Development Team builds WordPress.
Security Initiative** with one goal: a stronger, safer WordPress. It focuses a coordinated
effort under three pillars: **ABC**.

## A better release process

Building a tighter, more automated security release process, with improved end-to-
end testing, so fixes ship reliably and predictably. The security team is scheduling
upcoming security releases as a result.

## Breaking the backlog

Bringing on more team members and volunteers to work through the queue of open reports
and known issues, with the aim of driving open findings down to zero.

## Crush vulnerabilities with AI

Applying AI-assisted scanning and tooling to find vulnerabilities before they can
be exploited, complementing the reports received through responsible disclosure.

This work is supported by the WordPress core security team, longtime core contributorsCore
Contributors Core contributors are those who have worked on a release of WordPress,
by creating the functions or finding and patching bugs. These contributions are 
done through Trac. [https://core.trac.wordpress.org](https://core.trac.wordpress.org),
and contributors sponsored by companies across the WordPress ecosystem.

## How you can help

Security research and responsible disclosure remain the front line. If you believe
you’ve found a vulnerability in WordPress core, please report it through the official
channel at [hackerone.com/wordpress](https://hackerone.com/wordpress) and please
review the [reporting guidelines](https://make.wordpress.org/security/) before submitting,
as report quality matters more than ever at this volume.

 * [Login to Reply](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fmake.wordpress.org%2Fsecurity%2F2026%2F08%2F28%2Fthe-core-security-initiative%2F%23respond&locale=en_US)