9 ms·
I recently had to take over a wordpress site for a volunteer project and it almost immediately got hacked with spam despite taking great pains to not have this
by babbledabbler 5y ago
I recently had to take over a wordpress site for a volunteer project and it almost immediately got hacked with spam despite taking great pains to not have this happen.
Thousands of SEO pages showed up in the DB after installing some well known marketplace plugins. I was able to remove the hacked plugin and fortunately, it wasn't a big deal as this was just a temporary site for an event, but I would never work on wordpress again and I dissuade people from using it when I hear that they are considering it.
It was great for its day, but times have changed and it's just not a secure platform.
Any benefit given by all the plugins is outweighed by "hack roulette" you are playing when you install and customize them.
There are now many other solutions out there that will be more secure and fit the need for most people.
- chillfox 5y agoThe key to running Wordpress securely is usually to set the file permissions correctly and protect all admin routes. Basically, don’t expose any write endpoints to the internet. And the easiest way is to use as few third party plugins/themes as possible. Base Wordpress is pretty secure if you put the admin panel behind a VPN and don’t install any plugins.