Profiles

Bio

I’m Dr. Sahil Baghla — a cybersecurity advisor, published author, and long-time contributor to the WordPress ecosystem.

From 2011 to 2025, I served as an independent cybersecurity consultant and vCISO, working with over 55+ global clients to secure their high-traffic WordPress websites. My work focused on malware removal, blackbox/whitebox penetration testing, incident response, plugin audit, AWS hardening, and performance optimization.

In 2023, I authored “WordPress Security Secrets Revealed” — a practical guide to help WordPress site owners and developers prevent common attack vectors. I’ve also contributed to the WordPress Core security ecosystem by reporting vulnerabilities, and I’ve presented community sessions such as “WordPress Security Simplified” for the Nullcon Security Community in 2022.

I’m currently the Founder & CEO of EH1-Infotech Cybersecurity Pvt. Ltd., a DPIIT-recognized cybersecurity startup that provides Cyber Risk Assessments, Penetration Testing (VAPT), vCISO Advisory, Compliance Readiness (ISO 27001, DPDP, GDPR), and Employee Security Enablement Programs for modern businesses — including WordPress-powered platforms.

Before founding EH1-Infotech Cybersecurity Pvt. Ltd. in 2025, I also led a 10-year educational initiative under a former firm (now inactive) focused on ethical hacking workshops, website security training, and awareness programs for students, startups, and government officials.

Today, my mission continues: to help website owners and tech leaders protect digital trust, with a focus on ethical, service-driven cybersecurity.

You can learn more or connect via http://www.eh1infotech.com

Interests

1. Family Man
2. Yoga and Meditation
3. Following WordPress Hacking and Security news
4. Delivering WordPress Security Webinars
5. Writing WordPress Security Articles on Medium during my free time
6. Conducted more than 350 Ethical Hacking & Cyber Security Awareness seminars & workshops since 2010.

WordPress Origin Story

I started my journey with WordPress in 2010 when I was looking for a way to share my knowledge and passion for ethical hacking and cyber security with the world. I had already created a blog in HTML, but it was tedious and time-consuming to maintain. I wanted something more dynamic and user-friendly. That’s when I discovered WordPress, the most popular blogging platform on the internet.

As a cyber security expert, I knew that hackers were constantly targeting WordPress sites, looking for vulnerabilities and loopholes to exploit. I had seen many cases of WordPress sites being hacked, defaced, or infected with malware. I knew that I had to protect my WordPress site from these threats, or else I would lose everything I had worked for.

That’s why I decided to dedicate myself to learning and applying the best practices of WordPress security. Over the years, I have accumulated a wealth of experience and expertise in WordPress Security. I have helped hundreds of clients secure their WordPress sites from hackers and malicious attacks. I have also written two books, sharing my secrets and strategies with the WordPress and cyber security community.

My latest book, “WordPress Security Secrets Revealed”, is a comprehensive guide for anyone who wants to protect their WordPress site from hackers.

I am proud to be a part of the WordPress community, and I hope that my book will help you boost your WordPress Security and create a safer digital world. You can find more information about my book at https://amzn.to/3LBLoEM (International Availability) and at https://amzn.to/48snLZ2 (Available for India).

Thank you for your interest in WordPress Security! I believe cybersecurity is not just about tools and threats — it’s about protecting what matters most: people, purpose, and trust. Through WordPress, I found not only a platform — but a path to share that mission with the world. Thank you for being part of this journey toward a safer, more ethical digital future.

Badges

CODE
1 badge
Core Contributor '23

Current Job

Cyber Security Consultant
Present
EH1-Infotech Cybersecurity

Recent impact

Score weights high-impact work (commits, releases, approved translations, props) at 3x routine activity.

Last 30 days
0contributions
high0
medium0
score0
Last 90 days
0contributions
high0
medium0
score0
Last 12 months
0contributions
high0
medium0
score0

Team focus

Across 1 team, with no team-attributable contributions in the last 365 days

WordPress releases

Contributed to 2 releases
  • 6.3
  • 6.2

Contributions

Type
December 2023
Dec 10 Sun · 02:42
Forums med
Created a topic, Plugin Enhancement for Independent Restrict Country/Continent Option, on the site WordPress.org Forums:
Hi Rick, I hope this message finds you well. I have…
November 2023
Nov 20 Mon · 11:36
Forums med
Posted a reply to Query Regarding Traffic Rate-Limiting and Block Bad IP/Visitors Functionality, on the site WordPress.org Forums:
Hi Paul, Thank you for your prompt response. I acknowledge your message regarding the direct…
Nov 20 Mon · 09:17
Forums med
Created a topic, Query Regarding Traffic Rate-Limiting and Block Bad IP/Visitors Functionality, on the site WordPress.org Forums:
I am reaching out to seek clarification regarding the …
Nov 18 Sat · 19:59
Forums med
Created a topic, Integrating ‘Disable Content Copying’ Option, on the site WordPress.org Forums:
Hello, I am a regular user of your Proxy & VPN Blo…
September 2023
Sep 29 Fri · 07:02
Forums med
Created a topic, Bug – Simple Local Avatars URL Rewriting Issue, on the site WordPress.org Forums:
Hello Support Team, I am writing to report what app…
Sep 26 Tue · 06:34
Forums med
Posted a reply to Rewriting Local URL is not functionable for User Avatars Images, on the site WordPress.org Forums:
Hello WP Offload Media Support Team,I would be contacting "Simple Local Avatars" support team about…
Sep 25 Mon · 06:24
Forums med
Created a topic, Rewriting Local URL is not functionable for User Avatars Images, on the site WordPress.org Forums:
I am a regular user of the Offload Media Plugin. Rewri…
July 2023
Jul 11 Tue · 11:53
Polyglots med
Suggested 8 strings on translate.wordpress.org.
June 2023
Jun 21 Wed · 18:25
Core high
Mentioned in [55968] on WordPress SVN:
Administration: Add the `no-store` and `private` directives to the `Cache-Control` header when preventing caching for logged in users.
March 2023
Mar 14 Tue · 07:01
Forums med
Posted a reply to How to remove malware from wordpress site?, on the site WordPress.org Forums:
Carefully follow <a href="https://wordpress.org/support/article/faq-my-site-was-hacked/">this guide</a>. When you're done, you may want to implement some (if…