3 ms·
You're absolutely correct. However, according to WP core devs, nothing should ever be done to inconvenience the user. Moving to a new version of PHP when appare
by kalenjohnson 11y ago
You're absolutely correct. However, according to WP core devs, nothing should ever be done to inconvenience the user. Moving to a new version of PHP when apparently, user's who have websites don't even know the name of the language their website is built in, should not be put off by having to upgrade this strange thing.
I can't agree enough though, WP can be a huge driving force in making all hosting providers utilize modern versions of PHP. However, instead of using that weight to make a difference, they're completely content to hold PHP back. All at the expense and detriment of the user, in the name of the user.
- mgkimsal 11y ago"nothing should ever be done to inconvenience the user." Having sites hacked due to old version of PHP is an inconvenience. Why not just tell everyone to chmod 777 the entire website too, just so they're not inconvenienced? Tongue-in-cheek, of course, but there's a balance to be struck between convenience and security, and I think they're somewhat on the wrong side. I was really mixed on the 'auto-update' wordpress core stuff. While I get it - it keeps some people up to date - it also means my system needs to be left in a state where software can be altered, and that means it can be maliciously altered too. The "moving to a new version when they don't know the language" argument - I don't buy it. Almost everyone I know who has wordpress installed who is not a techie has a host that manages it, or presses a button on a control panel. Pressing another button, or having the host do some more stuff - neither of these are inconveniences that outweigh the security benefits - not just to that site owner, but the rest of the internet.
- kalenjohnson 11y agoYep... we're on the same page
- technion 11y agoWhy not just tell everyone to chmod 777 the entire website I run a cron job on my hosting server that detects clients that have done that. I alert several a week regarding the state of their security. I'm nearly always told they followed some "Wordpress installation guide" they found online and won't be changing it.