Tim Nash
@tna.sh
190 followers 280 following 170 posts
Doomspeaker and Security Consultant for WordPress ecosystem. 🔗 https://tna.sh 🏠 https://timnash.co.uk 🎓 https://wpsecurity101.com 👔 https://agencystreamline.co.uk/
Posts Media Videos Starter Packs
tna.sh
What does Wapuu do?

Nothing. Absolutely nothing.
It doesn’t boost SEO.
It doesn’t compress images.
It doesn’t even have a block editor opinion.
It just sits there, hugging its WordPress orb like it knows the secret to the custom post type apocalypse.

I would point to wordpress.org/plugins/wapu...
tna.sh
Currently playing will I have made it to stable internet connection in time for the show! Not to scary @nathanwrigley.com to much.
Reposted by Tim Nash
nathanwrigley.com
Join us LIVE for the 'This Week in #WordPress' show. It's fun, and we'd love your comments, really! Starts in a couple of hours, so 2pm UK time.
wpbuilds.com/live
This week, I'm with Michelle Frechette, Tim Nash and Courtney Robertson.
@michellefrechette.bsky.social @tna.sh @courtneyr.dev #TWiW
WP Builds LIVE - Watch us live!
Watch us LIVE over at WP Builds. Something WordPress related coming your way!
wpbuilds.com
tna.sh
Ever wondered how random wp_rand() really is?

No? I'm not surprised I would be more surprised if you knew this function even existed in WordPress.

Now you do, are you curious?
So was I let's go on a random adventure!

timnash.co.uk/nothing-is-t...
Nothing is truly random by Tim Nash
A deep dive into how WordPress’s wp_rand() works, what a CSPRNG is, and why some warnings about it are misplaced.
timnash.co.uk
tna.sh
I hope it involves lavalamps?
Reposted by Tim Nash
mikemcalister.com
It's here! Menu Designer has landed at WP.org!

Menu Designer is a powerful new way to build beautiful mobile menus and dropdown menus in the @WordPress block editor — no coding required. And now it's available right in your dashboard.

wordpress.org/plugins/oll...
Reposted by Tim Nash
wordpress.org
WordPress 6.8.3 is here! This crucial security release addresses vulnerabilities to keep your site safe. Update now and ensure your site is secure! Learn more about the updates and download it here: wp.me/pZhYe-4ZK.
wp.me
tna.sh
p.s If you found it helpful, do share the video for some this might be the thing that makes them go, oh that makes sense.
tna.sh
I was lucky to present at #WCGdynia on automatic updates.

Even if you don't use them I encourage you to watch this talk, not to convince you, but to see what things you can do around updates in general to make them safer and more reliable. (Hint it's testing)

wordpress.tv/2025/09/30/t...
The Dark Side of Automatic Updates: Securing WordPress Supply Chains in CI/CD
Automatic updates in WordPress are a safety net, ensuring that sites are always running the latest code. But for development teams working with continuous integration and delivery (CI/CD), the real…
wordpress.tv
tna.sh
Has yours?
If not what a sucky morning you must be having clicking an update button.

Coincidentally my talk on automatic updates just dropped on @wordpress.org TV

wordpress.tv/2025/09/30/t...
remkusdevries.com
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site…
tna.sh
Tim Nash @tna.sh · 11d
Thanks! I'm off to hibernate for a week.
tna.sh
Tim Nash @tna.sh · 14d
You can send me a message on LinkedIn linkedin.com/in/tnash
or via the WPUK Slack wpslack.uk

Both are logged in on my phone.
Please don't use Bluesky chat feature as I have no access to it! So you will just be a message I can't access.
linkedin.com
tna.sh
Tim Nash @tna.sh · 14d
Coming to #WPLDN but worried you don't know anyone? Events can be intimidating!

I really want to say Hi and I can hopefully gently introduce you to people.

If the idea of coming up to me is scary then just drop me a message and I will come to you even if it's outside of the venue.

This is me:
Tim Nash in a coffee shop wearing a pink shirt.
tna.sh
Tim Nash @tna.sh · 29d
The wonderful @mwug.uk is back! Very excited to be here in Stockport which is totally Manchester...

But so happy to see it happening congrats to @rhys.wales @jwo.ng on re-launch.
MWUG in full swing.
tna.sh
Tim Nash @tna.sh · 29d
I don't know there possibly is to much Evan...
tna.sh
Tim Nash @tna.sh · Sep 9
Heads up!
If you make use of NPM there has been multiple packages compromised and distributing malware. List of effected packages github.com/advisories?q... including big ones like debug and chalk.

Some commentary on the event including from the Chalk dev news.ycombinator.com/item?id=4516...
GitHub Advisory Database
A database of software vulnerabilities, using data from maintainer-submitted advisories and from other vulnerability databases.
github.com
tna.sh
Tim Nash @tna.sh · Aug 8
I have been playing with wordpress.org/plugins/mela... as a replacement for User Role Editor. I didn't include it in the course as it was still Alpha and also the user module is very @melapress.bsky.social heavy!
Melapress Role Editor
The complete WordPress user roles plugin for everyone
wordpress.org
tna.sh
Tim Nash @tna.sh · Aug 8
How strange, they all use the same pattern so the links should not vary and the video control is also in the pattern. Will go take a look. Thanks for the heads up!
tna.sh
Tim Nash @tna.sh · Aug 8
I believe @melapress.bsky.social Login Security includes such a rule, but I would have to check.