3 ms·
If you're lucky enough to install well-written (or self-written) plugins which withstand major version updates, you can set `WP_AUTO_UPDATE_CORE` to `true` in y
by grrowl 9y ago
If you're lucky enough to install well-written (or self-written) plugins which withstand major version updates, you can set `WP_AUTO_UPDATE_CORE` to `true` in your wp-config and it will auto-update to any latest version. There's an added risk of plugins not working, but you'll stay up to date.
- toast0 9y agoWP auto update is sort of nice in that you stay updated (but who the heck knows what will happen if you have one MySQL server and multiple www servers), except it means that your webroot is writable by PHP, which is not a great thing, because someone who finds an arbitrary file write issue before it's patched (or before auto update triggers) will be able to add their own files to your webroot -- weather that's defacement, malware installers, warez drops, bitcoin mining, shells for later; it's all pretty nasty.
- prepend 9y agoThere are risks with all security protocols and you called out valid ones with auto update. Do you have ideas for superior methods? A bit upthread someone mentioned clients paying him a monthly security retainer to monitor and update. This might be good, but pretty expensive so would price out lots of users.
- toast0 9y agoStatic generators are clearly superior from a security point of view -- the webserver doesn't have to execute any code. But, assuming wordpress exists; it would be best if the code ran in the a user context that could not write anything to the filesystem; and the code was installed with another user, which could do auto-upgrade via a crontab. An exploit could certainly leave persistent data in the database, but not on the filesystem at least. It would also be great if the database had separate credentials for the user facing site (mostly read only) and the admin facing site. On the other hand, I don't know how possible that would be to setup for inexperienced site admins on commodity hosting.
- prepend 9y agoI agree on the security superiority. I use Wordpress because my wife can maintain and update it almost entirely herself. I’m searching for a plug-in that generates static based on the edits in Wordpress, but haven’t found any that work cleanly. I think that Wordpress is good for its users who will never use build processes for deployment unless automated well.
- illuminea 9y agoWe created Strattic to allow anyone to use WordPress (and eventually other CMSs) as static site generators. It's the best of both worlds. We're in private beta but you can check it out here: https://www.strattic.com https://www.strattic.com.
- illuminea 9y agoWP auto update is nice...until a WP update breaks the functionality! Lol. https://www.wordfence.com/blog/2018/02/broken-auto-update/ https://www.wordfence.com/blog/2018/02/broken-auto-update/