5 ms·
Wpcom – A curated directory of resources and tools for WordPress
- tyingq 7y agoProceed with caution. A fair amount of wordpress's reputation for bad security comes from 3rd party plugins. There aren't many (any?) restrictions on what they can do.
- atknoz 7y agoThat's right indeed but we're a curated directory where people discover or share their experiences on the resources. We're not encourage the peoples to use what we've curated.
- mattigames 7y agoWell, is exactly the same for any npm package or any python package as do many other languages, a lot -if not all- bad security comes from 3rd party plugins.
- jermaustin1 7y agoI'm perfectly capable of bad security on my apps without the use of 3rd party plugins, thank you very much!
- tyingq 7y agoTechnically the same perhaps. But the actual history is pretty different. WordPress plugins are notorious for RCE type vulnerabilities.
- jermaustin1 7y agoI wrote one during my early years, in fact [1]! 1: https://jeremyaboyd.micro.blog/2016/11/20/that-time-i.html https://jeremyaboyd.micro.blog/2016/11/20/that-time-i.html
- llarsson 7y agoHow slow does WP get if you load all of these onto it at the same time? How much would it resemble a Swiss cheese, security-wise?
- atknoz 7y agoLoad all of these? Why would you do that?
- greggturkington 7y agoNot sure why you'd do that, or why that's related. Caching would take care of any plugins on the backend.
- Ayesh 7y agoWordPress does not support PHP autoloading, and every plugin's main PHP file is included and run on every page load. If you have a 100 plugins, that is WordPress core files + at least 100 files to run. You will likely run into functions name collisions before you can run it. PHP also caches the opcode to the memory. So it's likely that you will hit memory or disk IO issues before you can do it. WordPress has wp-cli that you can download plugins from CLI. Give it a try yourself, although I don't see the point of it.
- social_quotient 7y agoKinda surprised not to see WPengine on the list.
- atknoz 7y agoThere is actually: https://www.wpcom.org/resource/wpengine/ https://www.wpcom.org/resource/wpengine/ Though we don't recommend it due to bad pricing policy, bad reputation on TrustPilot and from other testers, and personal experiences. There are way better hosting alternatives that is currently listed and marked with yellow background on our platform.
- Ayesh 7y agoThis is a shameless self-plug. I have written a few WP plugins because it is not as secure I wanted it to be: - WordPress does not come with proper password hashing, and uses the phpass library. https://wordpress.org/plugins/password-hash/ https://wordpress.org/plugins/password-hash/ will change this to use bcrypt/Argon2ID - Comment forms do not have CSRF tokens, and hackerone/tickets for them have been neglected as trivial. https://wordpress.org/plugins/comment-form-csrf-protection/ https://wordpress.org/plugins/comment-form-csrf-protection/ This plugin adds a CSRF token to comment forms.
- tednash 7y agoIs the Wpcom site itself a theme?
- atknoz 7y agoIt's a custom built theme by us.