Tim Nash
tna.sh
Tim Nash
@tna.sh
Doomspeaker and Security Consultant for WordPress ecosystem.

🔗 https://tna.sh
🏠 https://timnash.co.uk
🎓 https://wpsecurity101.com
👔 https://agencystreamline.co.uk/
Still time for you to get on a train/plane/automobile and get to London for WPLDN this evening and come and be scared with WordPress horror tales!

Want a sneak peek here is my opening slide for tonight horror tale.
October 30, 2025 at 10:55 AM
Reposted by Tim Nash
Today 🎉Join us Nathan Wrigley, Michelle Frechette, Tim Nash and me
@nathanwrigley.com @michellefrechette.bsky.social @bsky.app/profile/tna.sh #TWiW #WordPress at 15:00 CEST (13:00 UTC) wpbuilds.com/live
WP Builds LIVE - Watch us live!
Watch us LIVE over at WP Builds. Something WordPress related coming your way!
wpbuilds.com
October 20, 2025 at 8:12 AM
What does Wapuu do?

Nothing. Absolutely nothing.
It doesn’t boost SEO.
It doesn’t compress images.
It doesn’t even have a block editor opinion.
It just sits there, hugging its WordPress orb like it knows the secret to the custom post type apocalypse.

I would point to wordpress.org/plugins/wapu...
October 9, 2025 at 9:16 AM
Reposted by Tim Nash
Join us LIVE for the 'This Week in #WordPress' show. It's fun, and we'd love your comments, really! Starts in a couple of hours, so 2pm UK time.
wpbuilds.com/live
This week, I'm with Michelle Frechette, Tim Nash and Courtney Robertson.
@michellefrechette.bsky.social @tna.sh @courtneyr.dev #TWiW
WP Builds LIVE - Watch us live!
Watch us LIVE over at WP Builds. Something WordPress related coming your way!
wpbuilds.com
October 6, 2025 at 10:36 AM
Ever wondered how random wp_rand() really is?

No? I'm not surprised I would be more surprised if you knew this function even existed in WordPress.

Now you do, are you curious?
So was I let's go on a random adventure!

timnash.co.uk/nothing-is-t...
Nothing is truly random by Tim Nash
A deep dive into how WordPress’s wp_rand() works, what a CSPRNG is, and why some warnings about it are misplaced.
timnash.co.uk
October 6, 2025 at 9:18 AM
Want something to read on your Sunday afternoon? Come join me on a random adventure into wp-rand()

timnash.co.uk/nothing-is-t...

#wordpress
Nothing is truly random by Tim Nash
A deep dive into how WordPress’s wp_rand() works, what a CSPRNG is, and why some warnings about it are misplaced.
timnash.co.uk
October 5, 2025 at 1:55 PM
Reposted by Tim Nash
It's here! Menu Designer has landed at WP.org!

Menu Designer is a powerful new way to build beautiful mobile menus and dropdown menus in the @WordPress block editor — no coding required. And now it's available right in your dashboard.

wordpress.org/plugins/oll...
September 29, 2025 at 2:39 PM
Reposted by Tim Nash
WordPress 6.8.3 is here! This crucial security release addresses vulnerabilities to keep your site safe. Update now and ensure your site is secure! Learn more about the updates and download it here: wp.me/pZhYe-4ZK.
wp.me
October 1, 2025 at 1:38 AM
I was lucky to present at #WCGdynia on automatic updates.

Even if you don't use them I encourage you to watch this talk, not to convince you, but to see what things you can do around updates in general to make them safer and more reliable. (Hint it's testing)

wordpress.tv/2025/09/30/t...
The Dark Side of Automatic Updates: Securing WordPress Supply Chains in CI/CD
Automatic updates in WordPress are a safety net, ensuring that sites are always running the latest code. But for development teams working with continuous integration and delivery (CI/CD), the real…
wordpress.tv
October 1, 2025 at 10:37 AM
Has yours?
If not what a sucky morning you must be having clicking an update button.

Coincidentally my talk on automatic updates just dropped on @wordpress.org TV

wordpress.tv/2025/09/30/t...
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site has updated to WordPress 6.8.3
Your site…
October 1, 2025 at 9:51 AM
Reposted by Tim Nash
NEW POST: On being inspired at #loopconf and hitting publish on a blog post I had half written....
Comment.
Like. Comment. Subscribe. That’s what the YouTubers say isn’t it? I miss folks commenting on blog posts really. At my peak I’d post a blog post at home, walk the half a mile from my student digs to university, and then be greeted with 4 or 5 comments. Now? I think I’ve had one comment … Continue reading
www.rhyswynne.co.uk
September 29, 2025 at 4:51 PM
Taking @ohhelloana.blog talk seriously and hit publish...
The long way to WordCamp Gdynia 🚀
Leeds → London (WPLDN + LoopConf) → Poland 🇵🇱
Turns out it’s quicker to get to Gdynia than London.
timnash.co.uk/the-long-way...

#loopconf #WCGdynia
The Long Way to WordCamp Gdynia: LoopConf, WPLDN and a Lot of Coffee by Tim Nash
From Leeds to London for WPLDN and LoopConf, then on to WordCamp Gdynia — turns out Poland is easier to reach than the capital. A week of security talks, AI debates, community, and flight delays.
timnash.co.uk
September 28, 2025 at 8:19 AM
Coming to #WPLDN but worried you don't know anyone? Events can be intimidating!

I really want to say Hi and I can hopefully gently introduce you to people.

If the idea of coming up to me is scary then just drop me a message and I will come to you even if it's outside of the venue.

This is me:
September 24, 2025 at 12:24 PM
The wonderful @mwug.uk is back! Very excited to be here in Stockport which is totally Manchester...

But so happy to see it happening congrats to @rhys.wales @jwo.ng on re-launch.
September 9, 2025 at 5:47 PM
Heads up!
If you make use of NPM there has been multiple packages compromised and distributing malware. List of effected packages github.com/advisories?q... including big ones like debug and chalk.

Some commentary on the event including from the Chalk dev news.ycombinator.com/item?id=4516...
GitHub Advisory Database
A database of software vulnerabilities, using data from maintainer-submitted advisories and from other vulnerability databases.
github.com
September 9, 2025 at 5:50 AM
The folks @weareag.bsky.social have rolled an update of one of my favourite features in their payment gateways, their Payment Failure Traffic Light system.

Making it so easy to understand payment issues, and identify potential fraud issues.

weareag.co.uk/tls-2-0-beca...
TLS 2.0 - Because “Address Failed” Just Isn’t Good Enough Anymore – We are AG
Remember our original Traffic Light System? You know, the one that gave you a few coloured circles and told you things like “Address failed”? It was useful, sure, but… it was basically the equivalent ...
weareag.co.uk
August 15, 2025 at 3:14 PM
Reposted by Tim Nash
Join us live in 15 minutes for a discussion about accessibility with Piccia Neri and Michelle Frechette.

This week's topic is Layout.

Future topics include: Legislation, Captions, Social Posts, Data Visualization, and Animations.

https://www.youtube.com/watch?v=fkfNIMQnQME

August 7, 2025 at 12:47 PM
Setting up a new blog/article section of a site, do you add comments on posts yay or nay?
August 5, 2025 at 11:59 AM
Reposted by Tim Nash
We shall be LIVE, so very, very LIVE in about 90 mins for 'This Week in #WordPress'. This week I'm with Mark Westguard, Jesse Friedman, Marc Benzakein. Starts at 2pm UK time. See you there?
https://wpbuilds.com/live
WP Builds LIVE - Watch us live!
Watch us LIVE over at WP Builds. Something WordPress related coming your way!
wpbuilds.com
August 4, 2025 at 11:29 AM
Reposted by Tim Nash
"All About Email", Issue 201 is out now! My guest author Sarah Gallardo takes us on a hugely comprehensive journey. Accessibility isn’t just compliance; it’s clarity, usability, and better results. Start building better emails with small, meaningful changes.

You can read the full newsletter now. 👇
Issue #201 All About Email
Accessibility isn’t just compliance; it’s clarity, usability, and better results. Start building better emails with small, meaningful changes.
newsletter.allabout.email
August 4, 2025 at 12:47 PM
What is a WordPress User?

wpsecurity101.com/lesson/what-...
Check out the free lesson from the wpsecurity101.com course

No signup, no email gate straight access to the lesson. You can check out the other free lessons as well.
What is a user?
Summary Transcript Resources What is a user? Let us unpack what a user really is in WordPress, not just a person, but a collection of database records stored across two key tables: Quick question.
wpsecurity101.com
July 14, 2025 at 10:22 AM
Reposted by Tim Nash
This week's Top 3 Links from Loop WP, Issue 165:

1) Personalize WP Pro - personalizewp.com/blog/announc...

2) WP Security 101 - wpsecurity101.com/?utm_source=...

3) WordPress Legal Updates - www.delta.blog/wordpress-le...

Feel free to read the full newsletter. 👇
Issue #165 Loop WP
Ollie Pro turns 1, PersonalizeWP Pro goes free, and WP Security 101 launches, and there are significant updates in WordPress tools and resources this week!
newsletter.loopwp.com
July 10, 2025 at 1:50 PM