SHA Director David Snead at WordCamp Europe 2026

WordPress Abuse Is a Coordination Problem. Here’s What We’re Doing About It.

Everyone says the same things about abuse. 

“We take immediate action.”
“We notify the customer.”
“It’s not on our network anymore.”


These statements can be true, but they’re also almost entirely beside the point.

We’ve Been Solving the Wrong Problem

For years, the industry has treated abuse as a technology problem, and addressing it with better detection, faster takedowns, and smarter filters. However, we haven’t treated it as is a coordination problem, which is exactly what it is.

At WordCamp Europe, I gave a talk on what the industry is doing about this issue. Not only is the Secure Hosting Alliance developing frameworks to address abuse in the hosting industry, it is working across the stack and throughout the industry ecosystem as part of the Internet Infrastructure Forum to develop cross-industry frameworks. In essence, developing playbooks to help stakeholders work together effectively.

At my talk, we discussed the fact that no single provider can stop a phishing campaign that crosses four companies and two continents. But four companies who share what they know, in a common format, with a common legal framework, can.

The coordination issue isn’t a question of will, but of structure: the Internet infrastructure stack—registries, registrars, hosting providers, CDNs—was built for resilience through independence. Each layer has its own capabilities, its own terms of service, and its own abuse desk system. That’s a feature, but it’s also a gap.

How the Abusers Exploit Structural Designs

Here’s what a modern abuse campaign looks like in practice:

A bad actor registers a domain at registrar A.
They point it to hosting at provider B.
They serve content through a CDN at layer C.

Each of those three companies may receive an abuse report. None of them necessarily knows what the others know, though, or what the others have done. So really, isolation is the exploit.

When a registrar suspends a domain, the content stays up. The host doesn’t know. When a host takes down the content, since the domain is still resolving. The attacker just points it to a new server. Meanwhile, they’ve registered three more domains before you finished processing the original ticket. This is incomplete mitigation: every individual action is correct, but the aggregate outcome is still failure.

A Different Approach: Cross-Stack Coordination

There’s a principle that sounds obvious once you say it out loud: the right response to abuse depends entirely on who you are in the stack and what you can actually do. A registrar can suspend a domain. A host can take down content. A CDN can stop serving it. None of them can do each other’s job. This means none of them can solve this issue alone.

As part of the IIF, the Secure Hosting Alliance has been working with the broader infrastructure community on a response framework built around five shared principles:

  • Clear Terms of Service. Every responsible operator needs one. Every operator needs to enforce it. This is just table stakes. The SHA already requires this for hosts who are certified by the SHA. Indeed, there are applicants we’ve turned away for not having a TOS.
  • Coordinated abuse reporting channels. A real, working channel for people to report abuse; and a real, working process for handling those reports.
  • Evidence-based action and proportionate response. When you receive credible evidence of abuse, you act. But not every report warrants the same response. Proportionality matters, and so does the quality of the information.
  • Legally grounded information sharing. Good information is key. So is respecting legal limitations on what can be shared, and with whom. This includes following privacy laws, and recognized best privacy practices.
  • Dedicated point of contact. When something is actively on fire, you need a person with a fire extinguisher, not a webform.

The core commitment that underlies all of this: when an issue cannot be effectively mitigated at your layer, you don’t stop and say “not my job.” You find out who can act, and you get them the information they need. The responsibility to protect users doesn’t end at your layer of the stack.

Why This Matters for WordPress 

Right now, if a registrar suspends a domain pointing to a compromised WordPress site, you may never know it happened.

The SHA, through the IIF, is working with other providers to address this. What we’re working on is a framework for addressing abuse, both within the hosting industry, and throughout the stack. This is what the result might look like: this domain was suspended for phishing. It was pointing at this server IP. That’s your signal to look at what else is running on that server, and how it exists on your network.

WordPress is the world’s most widely deployed CMS. That makes it the most heavily targeted. If you’re a hosting provider serving WordPress sites, you are already in this fight. The question is whether you’re fighting it alone or as part of a coordinated response.

What the SHA is Building to Facilitate Cross-industry Collaboration. Why It Can’t Wait.

We started with a simple observation: WordPress abuse is a coordination problem. The principles and framework the Secure Hosting Alliance has developed are a coordination solution. Our principles, framework and rust seal standards are practical, operational, and grounded in how the stack actually works.

Attackers already coordinate. They register backup domains before you process the first report, and they move content before you finish the ticket. The bad guys exploit the gaps between layers precisely because those layers don’t talk to each other. The only effective response is one that closes those gaps—and you do that not with a single tool or a single provider, but with shared standards, shared information, and shared commitment to action. That’s exactly what we’re doing.

The SHA is actively building that framework now, collaborating with registries, registrars, hosting providers, and CDNs who understand that coordination produces better outcomes than isolation. This is early-stage work: it’s not perfect, but it’s is the most serious operational attempt this industry has made to address abuse at the stack level, and it is happening now.

For WordPress hosting providers, the choice is whether you want to help build the standards or inherit them. If you want to be in the room where those decisions get made, reach out to us.

If you’re interested in participating, or in learning more about the Secure Hosting Alliance’s work on abuse coordination, reach out directly:

[email protected]

hostingsecurity.net

Leave a Reply

Spam-free subscription, we guarantee. This is just a friendly ping when new content is out.

← Back

Thank you for your response. ✨

Discover more from Secure Hosting Alliance™

Subscribe now to keep reading and get access to the full archive.

Continue reading