taquiones.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Mi instancia en el fediverso
Admin email
root@taquiones.net
Admin account
@victor@taquiones.net

Search results for tag #wordpress

The New Oil » 🤖
@thenewoil@mastodon.thenewoil.org

Adrián Perales (Gadi) »
@aperalesf@masto.es

Para quienes tengáis un blog WordPress pequeñito pero no queráis depender de Jetpack para ciertas funciones, el servicio ToSend (aún cerrado) promete un precio muy barato para la cantidad de correos que envía un blog pequeño.
tosend.com/

Seirdy boosted

Adam Varn »
@hotsauce@drupal.community

As if Matt Mullenweg wasn’t awful enough, there’s this

Link for context - make.wordpress.org/accessibili
(Credit to @dotgitignore for the original post and the alt text!)

Screenshot: Make WordPress Accessible

Matt Mullenweg 11:15 pm on August 1, 2026:
Actually, this is permanently delayed. The team has overstepped its authority, usefulness, and charter.

Matt Mullenweg, replying to Matt Mullenweg, one minute later:
Going forward, any other team or committer can override suggestions or requests from current accessibility team members.

Alt...Screenshot: Make WordPress Accessible Matt Mullenweg 11:15 pm on August 1, 2026: Actually, this is permanently delayed. The team has overstepped its authority, usefulness, and charter. Matt Mullenweg, replying to Matt Mullenweg, one minute later: Going forward, any other team or committer can override suggestions or requests from current accessibility team members.

Fedi.Tips »
@FediTips@social.growyourown.services

If you run a WordPress-powered blog, either on wordpress.com or on an independent hosting service, you can turn it into a Fediverse account that people can follow from Mastodon etc. More info about how to do this (and lots of questions answered) at:

➡️ fedi.tips/wordpress-turning-yo

You can follow the official account for the plugin that enables this at:

➡️ @activitypub.blog

You can also follow its lead developer at:

➡️ @pfefferle

dch boosted

stux⚡️ »
@stux@mstdn.social

Holy shit

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."

github.com/Icex0/wp2shell-poc

The New Oil » 🤖
@thenewoil@mastodon.thenewoil.org

The New Oil » 🤖
@thenewoil@mastodon.thenewoil.org

h3artbl33d »
@h3artbl33d@exquisite.social

🚨 Actively abused vulnerability in WP 🚨

WordPress has an actively abused SQL injection in the core in versions =<7.0.1. You should update to 7.0.2 as soon as humanly possible. Sites are already exploited.

Check whether the site has admin users that you don't recognize

More info: patchstack

Note: it has been a long time since there was a nasty vuln like this in the WP core.

IFTAS »
@iftas@mastodon.iftas.org

Let's see what platforms are responding to this year's Social Web survey, the annual questionnaire to see how and folks are doing:

54
17
15
10
9
platform 8
8
8
6
5
4
4
4
4
3
3
3
3
platform 3
2
2
2
2
1

Social Web Survey cover page "2026 Social Web Operations Survey
IFTAS' annual environment scan and needs assessment for the platform admins, moderators, and social web community builders safeguarding the open web."

Alt...Social Web Survey cover page "2026 Social Web Operations Survey IFTAS' annual environment scan and needs assessment for the platform admins, moderators, and social web community builders safeguarding the open web."

veroandi boosted

🏳️‍⚧️ Christin Löhner 🏳️‍🌈 »
@christin@lsbt.me

FediSuite - Fediverse Management Platform

Open-source platform for social media management and analytics

If you manage several Fediverse accounts, you're constantly juggling browser tabs, losing track of which input field belongs to which platform, and at some point you no longer know what you've already posted. brings everything together in one place.

Connect accounts from 19(+) platforms: , , , , , , , and more. The app detects your instance type automatically, loads the correct character limit and media rules straight from your instance, and sets up the composer accordingly. No manual configuration needed.

The analytics go way beyond plain follower counts: daily engagement charts, follower growth, your best posting times as a heatmap, hashtag performance, and a tips engine that evaluates your actual data and gives you concrete suggestions based on your own numbers.

Schedule posts down to the minute in your own time zone. Background workers handle publishing reliably, with resume handling for rate limits and atomic delivery.

FediSuite is free and under the GPL-3.0. Anyone can host their own FediSuite and get it added to the official list automatically.

If you find a bug, especially in the setup, feel free to report it. The project is being actively developed, and real-world bug reports are among the most valuable contributions right now. The CONTRIBUTING.md explains how it works.

The project lives on donations. Donations guarantee and make it possible for FediSuite to keep going and keep being developed. To support FediSuite, click the yellow button on the website.

More info: fedisuite.com

The New Oil » 🤖
@thenewoil@mastodon.thenewoil.org

The New Oil » 🤖
@thenewoil@mastodon.thenewoil.org

The New Oil » 🤖
@thenewoil@mastodon.thenewoil.org

Albert Cardona »
@albertcardona@mathstodon.xyz

If you are wondering what web crawlers want from your website, particularly those that fake their identity and ignore robots.txt and more, this is what they want, accessed thousands of times over the last 15 days:

/ip
/aaa.php
/.git/config
/xmlrpc.php
/wp-login.php
/sitemap.xml
/ioxi-o.php
/no_branch
/about.php
/admin.php
/defaults.php
/edit.php
/goods.php
/.env~
/wp-configs.php
/hehe.php
/_profiler/phpinfo
/favicon.ico
/load.php
/flower.php
/file.php
/index.php
/menu.php
//xmlrpc.php?rsd
//blog/wp-includes/wlwmanifest.xml
//web/wp-includes/wlwmanifest.xml

In other words: mostly attempting to hack your WordPress installation. Interesting to see also attempts at getting at backup files for python environments.

Working Class Berserker »
@rasczerker@mastorol.es

¿Aurora boreal? ¿En esta época del año? ¿A esta hora del día? ¿En esta parte del mundo y ubicada específicamente en su cocina?

Pues sí, ya tenemos otro scrapeo de bots que se traga Google Analytics.

Por si alguien usa un Wordpress, que sepáis que los datos que aporta Matomo son mucho más fiables (no se traga estas mierdas) y también más respetuosas con la privacidad.

Captura de Goggle Analytics, de la pestaña de detalle Usuarios activos durante los últimos 30 minutos, mostrando 8 visitas de Singapur.

Alt...Captura de Goggle Analytics, de la pestaña de detalle Usuarios activos durante los últimos 30 minutos, mostrando 8 visitas de Singapur.