3 ms·
Can you show some data? I'm interested to see how exploitable popular PHP frameworks (Laravel and Symfony?) and the language itself are over the years in compar
by c487bd62 8y ago
Can you show some data? I'm interested to see how exploitable popular PHP frameworks (Laravel and Symfony?) and the language itself are over the years in comparison to JavaScript, Python and Ruby web stuff. Not interested in anecdotes or bad code from bad programmers (aka Wordpress plugins) being used as an argument.
My company has some legacy PHP stuff that is rock solid, making money for years, survived every single audit (and PHP 7 cut our server costs by half).
- gravypod 8y agoWordPress is probably the most deployed php framework and it is extremely exploited.
- ceejayoz 8y agoWordPress is heavily hampered by a refusal to break backwards compatibility. https://wordpress.org/about/requirements/ https://wordpress.org/about/requirements/ > WordPress also works with PHP 5.2.4+ That's a nearly eight years end-of-lifed version.
- c487bd62 8y agoStill waiting for source for all those claims. I'm not being ironic or anything but people throw things under the bus so easily it would be nice to see the data (comparison). Their numbers are huge so of course the number of exploited servers will be higher in raw numbers, but is the core "extremely" exploited or is the plugins the real problem? We should be talking about the language/merits but I'll listen to arguments about the ecosystem. Just feels really dumb to talk about things like plugins. It's like saying JS is crap because 70% of the web extensions written in JS are sold to the botnet or are pure crap. Or how a popular operating system has more CVEs because it's popular. Not sure how to explain better what I want to say so let's just leave at that.
- edoceo 8y agoWP plugins are where these exploits are, less so in WP core