5 ms·
https://news.ycombinator.com/item?id=20998288 https://news.ycombinator.com/item?id=20998288 Someone submitted article about Wordpress alternatives like an hour
by flywithdolp 7y ago
https://news.ycombinator.com/item?id=20998288 https://news.ycombinator.com/item?id=20998288
Someone submitted article about Wordpress alternatives like an hour ago
For me the only issue with Wordpress is the security problems
Using wordfence atm
- josefresco 7y agoSecurity and performance is why we moved our WordPress clients to WPEngine about 5 years ago. If you can't move web hosts, Wordfence, WP Cerber and of course Sucuri make sense.
- x0x0 7y agoWe've declined to play and are using static html plus a headless CRM. It's a little clunkier but I can ignore the endless CVEs wordpress generates.
- petra 7y agoI work in a small business , and we have a lot of security issues with wordpress. So I'm looking for a solution. Did WPEngine solved all of your security issues ? What kind of expertise does it require , how does the process of using it looks ?
- kd3 7y agoCould you elaborate on security issues you encountered?
- winternett 7y agoDrupal has worked for me for many years, the modules are usually all free to use and to modify... There are very specific ways of doing things to ensure updates can happen without flaws, it has quite a learning curve, but the security benefits outweigh all of that. Drupal's abstraction layer is what keeps it secure. You also can restrict permissions granularity, and it's core functionality does most of what you need to create a simple site. Administration menus don't change with themes chosen (unless you specify it to). If you have a high traffic site, you can simply use cloud flare, or system caching, or pay for higher tier services like Akamai. I'm not an evangelist for Drupal though, it's not meant to fit every case, so I'll just leave it at that.
- dgb23 7y agoWP Security issues come from many things, including: * non-validated user input from ad-hoc code * not being up to date * plugins not being up to date * plugins not being understood, malicious code (eval, header manipulation and so on) * unsanitized output (wp offers sanitization for common types but you have to use it explicitly) * code being accessible that shouldn't be * users (clients) having too many capabilities
- josefresco 7y ago> Did WPEngine solved all of your security issues ? No. Because I'm paranoid and have been hacked before, I still apply additional "hardening" to WordPress. We use various plugins, and Cloudflare to further enhance our client's security. However hosting with WPE had allowed me to sleep at night, whereas previously I was constantly worried about performance and security of our VPS/dedicated boxes. I'm not a server admin, and if more webmasters were honest with themselves they'd admit that too. WPEngine takes care of running the infrastructure and I can focus on design and building great websites. The reason I still host and advocate for WPE is the quality support. It is by far the best hosting support I've ever worked with. I have other beefs with WPEngine (for another time) but am happy to continue working with them - never going back to a "VPS" model.