4 ms·
I am not aware of any serious vulnerabilities in an up-to-date WordPress site. Its security practices seem reasonable. Your link shows that most of the vulnerab
by allenz 8y ago
I am not aware of any serious vulnerabilities in an up-to-date WordPress site. Its security practices seem reasonable. Your link shows that most of the vulnerabilities come from plugins, plus WordPress is a big target.
WordPress is simple to set up, simple to use, and has a huge community. In the real world, it is often the best choice.
- Fellshard 8y agoExcept WordPress is almost completely founded on its plugins, so that's a non-trivial consideration. Specifically, if WordPress cannot provide proper abstractions, sandboxing, and protocols for plugins to be secure by default, the issue could be greatly reduced. As-is, its model both encourages such flaws to be included and provides its non-technical users with no viable way to identify which are likely to be vulnerable plugins.
- allenz 8y agoSandboxing would be nice, but I don't think it's practical. Do you know of any secure plugin systems that can replace WordPress?