
The Million-Dollar Prompt (And A 5-Hour Hack Window)
Issue #593

Recent Issues
- Nobody Buys Book #12 For The PlotIssue #592
- 85% Traffic Loss Due To AIIssue #591
- Built My Own AI. It Sucks. 😜Issue #590
- A Video Per DAY?Issue #589
- Why So Many Membership Sites DieIssue #588
Well, we’ve got a meaty issue today. 😇 I hope you don’t mind. My goal is that each issue is genuinely something worth reading… and not the typical email that people send all designed to sell stuff. You know the ones. 😜
Anyway, last week was a really busy one. Below, you’ll find out why. I needed a weekend off… which I took. 😍
In this issue, let’s talk about how you prompt AI. Because, knowing this about how AI actually works will help you get far better output. Also, we’ve got a lot going on when it comes to WordPress security. So, let’s get into it…
The “Million Dollar Prompt”. Here’s What’s Actually Happening…
Saw a post on X recently from a copywriter bragging that an AI prompt he wrote was about to make him “his next milly.”
Bold claim. I rolled my eyes a little, not gonna lie.
Of course, he was just putting out a good hook to get people to pay attention. And, it worked. 🤪 But, when I read the full post, I saw it wasn’t just a hype-fest, but was actually a pretty useful technique on how best to use AI prompts for writing content.
Straight up… I know a LOT of people reading this don’t consider themselves awesome copywriters. You want to make a sales page that actually helps sell your offers, but actually writing a sales page can be a real challenge. And I really do think using AI as a writing assistant can really help get the juices flowing. I’m not saying go copy/paste whatever AI says (that’d be stupid), but it can really help.
But, knowing just a bit about how AI models actually work will make your usage of them way more effective.
This prompt told the AI to “embody the greatest ad creative mind alive” and write something “so powerful it makes people weep, buy immediately, and tattoo our logo on their body.” Over the top? Sure. Hustle-bro energy dialed to eleven? Also sure. 😂
But here’s the thing… the guy wasn’t wrong about why it worked. Knowing WHY telling AI to “pretend to be a genius” actually works can help you become way more effective in how you prompt your AI.
You’ve probably seen the advice before… tell the AI to “act like a world-class copywriter” or “write like Dan Kennedy.” Feels a little silly, right? Like you’re just asking a computer to play pretend. And clearly, a computer cannot role-play and mean it. But, that’s not really what’s happening…
An AI model doesn’t read your prompt as instructions the way a person does. It doesn’t read instructions and “understand them.” It breaks your words down into chunks (tokens), and it uses everything you’ve written as context to figure out which patterns, out of everything it was ever trained on, it should pull from next. Basically, these AI models are big prediction engines.
Here’s the part that makes it click. Each of those tokens gets turned into a big list of numbers… basically a coordinate. During training, the model quietly organizes those coordinates so words used in similar ways end up sitting close together, and words used differently end up far apart. “Greatest,” “world-class,” and “elite” cluster together. “Copywriter” and “advertiser” cluster together. Nobody sorts this by hand… it just happens from reading billions of examples of how words get used near each other.
So when you type “embody the greatest copywriter alive,” you’re not casting a spell. You’re landing your prompt’s coordinates in a specific neighborhood… the one packed with elite, persuasive writing patterns. From there, the model predicts the next word based on what’s statistically likely given where you’re standing, one word at a time. Different neighborhood, different odds, different output.
Here’s how I think about it. Imagine a library that contains every piece of writing on every topic ever created… mediocre stuff, brilliant stuff, all of it, shelved together. If you just say “write me an ad,” the model can grab from anywhere in that library. And since most writing in the world is average, “anywhere” usually means… average. Now say “embody the greatest ad copywriter alive.” You’re not summoning a ghost. You’re pointing the model at a much narrower, better shelf. Same library. Different aisle.
And that explains the weird, over-the-top part of the prompt too. “Make it emotional” is vague. “Make people weep” tells the model exactly how far to push. Specificity does the narrowing. Vagueness just leaves it defaulting to safe and forgettable… which, statistically, is most of what’s out there.
Alright, so knowing all that, here’s how to put it to work next time you’re prompting AI for anything… not just ad copy.
- Give it a real persona, not a job title. “Copywriter” is weak context. “A direct-response copywriter who’s run some of the most profitable campaigns of the last decade” is strong context. More specific tokens, more specific aisle.
- Tell it the outcome, not the vibe. Don’t say “make it compelling.” Say what compelling looks like when it lands… what should the reader feel, believe, or do by the end. It can’t hit a target it can’t see.
- Give it real constraints. Budget, audience, format, stakes. Constraints aren’t limits here… they’re more context, doing more work.
To drive the point home here (and make sure you understand how AI models work), let’s apply this to something OTHER than writing sales copy. Like so…
- Debugging code. Instead of “fix this code,” try: “Embody a senior developer who’s obsessive about catching edge cases and writes code other developers actually enjoy maintaining. Tell me exactly where this breaks under real-world use, not just where it looks wrong.”
- A tough support email. Instead of “reply to this angry customer,” try: “Respond as a support rep who’s genuinely good at defusing anger without sounding scripted. Get them feeling heard in the first two sentences, then fix the actual problem.”
- A hard business call. Instead of “should I raise my prices,” try: “Think like a founder who’s scaled a few businesses past seven figures and has zero patience for generic consultant answers. Tell me what’s actually holding back growth, not what sounds smart.”
Oh, and this works much better on more advanced models. More data points, bigger library. More material for the patterns we’ve been talking about.
Funny enough… it’s basically the same lesson as last issue. Vague, generic content gets ignored, whether the reader is a person or a language model. Specific and particular is what gets noticed. Turns out that’s true all the way down.
The Inside Scoop
Spent a chunk of last week leveling up something that’s been bugging me for a while… how fast I can actually spot and respond to a security issue across the whole Concierge fleet. About a hundred sites at this point. So I built myself a proper dashboard for it. Real-time view of every site, what’s flagged, what the actual CVE is, all in one place instead of piecing it together site by site.
Once it was up and running, I put the whole fleet through it for the first time and worked through what it surfaced… mostly licensing gaps and a few plugins overdue for a clean reinstall. Good problems to find on your own terms, before they find you.
One of them turned out to be more than that, though. A client site had an actual backdoor sitting on it… a file disguised as a plugin literally named “WordPress.” Traced the entry point back to a completely different plugin, an old dashboard tool that had gone forgotten and outdated on that site for who knows how long. Funny thing is… this particular plugin wasn’t even showing as needing an update at all, hence how it managed to slip through my tools. Nobody was even using it anymore, it was just… sitting there, unpatched, as an open door. Cleaned out the backdoor, found and removed a dormant unauthorized admin account that had apparently been planted back in April. Then went and hunted down that same forgotten plugin across the rest of the fleet, because if it was the entry point once, it was worth checking everywhere.
Had another security incident last week, too, where an old Administrator account was used to log in, upload a plugin… which then proceeded to infect the site with malware. This was some pretty tricky malware, too, because the moment you deleted any part of it, it would immediately regenerate. It literally planted a crypto hack into the site and back-published about 60 gambling posts across the blog in a way where it would have been hard to notice. But, I noticed. 🤪 Since it would re-generate the moment I deleted anything, I ended up having to temporarily block the entire site from the public so it couldn’t regenerate, got it all cleaned up, then back on again.
So, yeah, it was a busy week in the security department. 🤪 A couple lessons for all here:
- Having working licenses on premium plugins is pretty important. For instance, I still have a few clients running unlicensed BuddyBoss plugins. There are known security issues there, but with the nature of BuddyBoss’s licensing and complexity, I can’t just upload a ZIP file for these clients. The lack of license is literally a risk for these few clients.
- Scan your list of Administrator profiles and be sure to delete any old ones. Keep a very secure password for your own, too. I know sometimes people spin up Admin profiles for support people to log in and look at things… then that profile sits there. Forever. Bad idea. Delete that profile as soon as support is done with it.
More on the security front in the next article below… because this has been a busy one lately…
WordPress News & Updates
An old, forgotten server just gave Fluent users a painful lesson. A server left running after a platform migration got compromised and served tampered builds of Fluent Forms Pro and Ninja Tables Pro for about five hours before anyone caught it. What I’ll give them credit for… WPManageNinja posted a refreshingly candid public post-mortem instead of trying to quietly bury it.
Nearly half the WordPress plugin directory is quietly abandoned. A new analysis found 43.8% of plugins haven’t been touched in over two years, including 207 with more than 10,000 active installs each. If you’ve got no idea whether your plugins are still maintained, this is worth a look. Clearly, I don’t recommend people run such plugins on their site.
If you run ACF (and most of us do), go update it today. Six security fixes landed in 6.8.7, including one that stops unauthenticated visitors from pulling non-public post data and user email addresses. It’s one of the most-installed plugins on all of WordPress, so this one’s worth doing now, not eventually.
The “AI-native” plugin flood isn’t slowing down. This week alone brought an AI SEO plugin with its own built-in MCP server, an AI-first page builder, an AI admin agent, and an AI product-photo tool for WooCommerce. I’m not against any of it, but “AI-native” is becoming this decade’s version of “cloud-based”… say it enough times and it stops meaning anything.
A small plugin shop is closing, and giving the code away on the way out. Ronald Huereca announced back in July that DLX Plugins is shutting down, and instead of just letting the code rot, he’s open-sourcing the whole catalog. First one out the door is GB Extras for GenerateBlocks, now live and free on GitHub. Running a solo plugin shop is brutal, and his reasoning for the move is worth reading.
WooCommerce 11.0 shipped, and stores should actually feel it. Product object caching is on by default for new stores now, making variable product pages load 9 to 12% faster. There’s also a checkout recovery email in beta if you want to test it early.
WordPress 7.1 lands August 19th. Responsive styling without touching CSS, a real overhaul to Notes, and a smarter media uploader that survives a dropped connection are the headline features. One thing worth knowing… the planned Classic Block phase-out got called off at the last minute, so nobody needs to panic about that one.
FluentSMTP 2.3.0 is out, still free, still no upsell. New Cloudflare Email Sending option, plus a connection health check that actually alerts you the moment something breaks, instead of you finding out three weeks later when a customer never got a password reset email.
SEOPress 10.1 lets AI write your metadata the moment you hit publish. No extra click, no forgotten fields. It also picked up better WooCommerce structured data for variable products and revision history for robots.txt… one bad line in that file can deindex your whole site, so having an undo button there is a genuinely good idea.
FluentCommunity 2.7.7 is a security release. HTML embeds for media are now properly restricted and sanitized, after Patchstack flagged the issue. Worth updating soon if you’re running a community on it.
More Security Patches Isn’t A Red Flag.
Last week was a busy one on the “keep everything updated” front.
Tuesday, WooCommerce sent out an urgent notice… critical security issue in Stripe for WooCommerce. I had it pushed across every Concierge client site running it within a couple hours. Wednesday, WordPress core shipped 7.0.3, patching 12 more vulnerabilities. Once again, I was on it and updated all clients in the Concierge fleet within about an hour.
Two emergency-feeling updates, back to back, in the same week. And if you’ve been paying attention, this isn’t a one-off. It’s been happening more and more.
Here’s the thing though… I don’t think that’s a bad sign. I think it’s actually a good one. Let me explain…
WordPress runs a bug bounty program… security researchers report vulnerabilities, get credited (and paid) for finding them. For roughly a decade, that program got a steady 20 to 30 reports a month. Boring, predictable, business as usual.
Last month, it hit 450.
That’s not a typo. Reports jumped more than 15x, and it didn’t happen gradually… a rep from the WordPress Security Team shared a graph showing it basically flatlined for years and then shot straight up starting this past January and February. The people digging through WordPress’s code for weaknesses aren’t just people anymore. They’re AI.
That WordPress 7.0.3 release I updated everyone to? It credited Anthropic, pwn.ai, and Aikido Security among the reporters. Those aren’t hobbyists. Those are AI-assisted security research operations, and they’re finding real bugs at a rate a decade of human-only bug hunters never got close to.
I know how this sounds on the surface… “great, now there’s MORE stuff breaking.” But that’s backwards.
AI didn’t create these vulnerabilities. They were already sitting there, quietly, in plugins and in WordPress core, waiting for the wrong person to find them first. What’s actually happening is AI is finding them before the bad guys do, at a scale no human team could match. That’s not a new problem. That’s an old problem finally getting solved faster.
Yes, more code is shipping faster too, and some of it is AI-assisted (“vibe coded,” if you want the term everyone’s using). More code shipping faster naturally means more bugs entering the pipeline. But right now, the AI finding those bugs is outrunning the AI creating them. Net effect… I’d argue your site is safer than it was a year ago, not less safe. It just means the maintenance job looks a little different now.
Now, here’s what that means for you as somebody running a WordPress site…
The old “I’ll get around to updating eventually” habit doesn’t really work anymore. Here’s why that matters more than it sounds like it should: once a serious vulnerability gets targeted, researchers have found the median time before someone actually tries to exploit it can be as short as five hours. Yes, 5 HOURS.
So here’s what I’d actually do with that:
- Turn on auto-updates where you reasonably can, especially for anything touching payments or security. Waiting for a convenient afternoon isn’t a strategy anymore.
- Keep every plugin properly licensed. An expired license quietly cuts off your updates, and you won’t necessarily notice until something breaks. This is the one I see slip most often with solo site owners.
- Actually read the “update now” emails. They used to feel like noise. They’re not anymore. If a plugin vendor is emailing you directly about a security fix, that’s a five-alarm signal, not a someday task.
- If you don’t have the bandwidth to watch for this stuff constantly, that’s what I do for Concierge clients every week… it’s exactly why both of last week’s fixes were already handled before most site owners even knew there was an issue.
More patches showing up in your dashboard isn’t WordPress getting worse. It’s the immune system finally working the way it’s supposed to. Just make sure you’re actually taking the medicine when it shows up.

The WP Edge is the official weekly newsletter of the Blog Marketing Academy.
Sent every Monday.



