idea 3 is to take a plugin and actually deconstruct it, demonstrate the tools all the way through to hunt for a sql injection to see if it can be hacked and model it.

This I can conceivably see a real devy WordPress group going for but its hard to keep it interesting while also making it realistic its also a lot of work if no one wants it.

@tnash I think this would be valuable as an article or series. Maybe even a course. Can’t see it working as a talk as it need close engagement and will the best will in the world WordCamps and meet-ups are distracting places.