Home/News/Claude AI now logs session URLs in your code commits by default
Web Dev

Claude AI now logs session URLs in your code commits by default

WHAT THIS MEANS FOR YOUR BUSINESS

Third-party URLs embedded in your code history could expose your workflow or vendor choices to clients, competitors, or auditors without you realising.

30 Aug 2026|3 min read|
Web DevSmall BusinessBusiness AutomationWebsite Security

A popular WordPress plugin that sits on millions of websites has been caught, or at least credibly accused, of quietly granting itself administrator access without asking permission. If your business website runs on WordPress, this is worth five minutes of your time right now.

Your Website Has a Back Door You Didn't Know About

Rank Math is a plugin used by a huge number of WordPress sites to help them rank better on Google. It is the kind of tool that sounds boring but does genuinely useful work in the background. The accusation, which has spread rapidly through the web development community, is that a recent update allowed the plugin to claim admin-level access to sites without the owner's knowledge or explicit consent.

To be clear about what "admin access" means: it is the highest level of control over your website. Someone with admin access can change your content, install other software, lock you out, or redirect your visitors anywhere they like. You hand that out to your web developer, maybe a trusted member of staff. You do not hand it to a plugin automatically.

Whether the behaviour was malicious, a genuine mistake, or a grey-area feature is still being debated. What is not debatable is that a plugin updated itself in a way that changed what it could do on your site without telling you clearly. That is a problem regardless of intent.

The Real Risk Is Not This Plugin Specifically

The Rank Math story is uncomfortable, but the bigger lesson is about the category of risk it represents. Most small business owners install plugins on their WordPress site and then forget about them. Updates happen in the background. Permissions creep quietly. And because nothing visibly breaks, nobody checks.

Your website is often the first place a potential customer forms an impression of you. If it gets compromised, whether through a dodgy plugin, an outdated bit of software, or a password that has not been changed since 2019, the consequences range from embarrassing to genuinely damaging. Customers who land on a hacked site that redirects them somewhere strange do not usually give you the benefit of the doubt.

“A plugin you installed and forgot about should not have more access to your website than your own staff do.”

We see this pattern regularly with clients who come to us after something has gone wrong. The site looked fine on the surface. Underneath, something had been quietly accumulating permissions for months.

What You Can Actually Do About It This Week

This is not a situation that requires a panic or an emergency call to a developer. It does require a bit of attention.

  1. 1.Log into your WordPress dashboard and look at your active plugins. If you see Rank Math and you are concerned, check which version you are running and look for any official statement from the Rank Math team. Do not uninstall anything in a rush without knowing what it does to your SEO settings.
  1. 1.Check your list of administrator accounts. In WordPress, go to Users and filter by the Administrator role. If there are accounts there you do not recognise, that is worth investigating immediately. Remove anything that should not be there.
  1. 1.Make sure automatic plugin updates are not happening entirely without oversight. Some hosting platforms and WordPress configurations update plugins silently. Consider switching to a setting where updates are flagged to you before they apply, or review them weekly.
  1. 1.Ask your web developer or agency when they last did a full plugin audit on your site. If they look puzzled by the question, that tells you something. A basic security review is not expensive and is worth doing once a year at minimum.

Your website is not just a brochure. For most small businesses, it handles enquiries, bookings, or sales. Treat access to it with the same caution you would treat keys to your premises.

SOURCES
[1] Claude Session URL appended to commit messages and PR descriptions by default
https://github.com/anthropics/claude-code/issues/66504
Published: 2026-08-30
[2] Rank Math WordPress Plugin Accused Of Secretly Taking Admin Access via @sejournal, @martinibuster
https://www.searchenginejournal.com/rank-math-wordpress-plugin-accused-of-secretly-taking-admin-access/587554/
Published: 2026-08-30
[3] Haiku R1/beta6 has been released
https://www.haiku-os.org/news/2026-08-26_haiku_r1_beta6
Published: 2026-08-30

GET THE WEEKLY BRIEFING

One email a week. What happened in tech and why it matters to your business.

NEED HELP WITH THIS?

That is literally what we do. Websites, automation, AI tools that actually earn their keep. One conversation, no jargon.

GET IN TOUCH