5 ms·
Wordpress is great for rapid prototyping but as history has shown, relying on third parties for additional functionalities in production environments, comes wit
by sourcecodeplz 4y ago
Wordpress is great for rapid prototyping but as history has shown, relying on third parties for additional functionalities in production environments, comes with great risks.
Most usage of Wordpress today are definably not blogs, but full blown websites with many functionalities not found on a blogging software.
- claudiulodro 4y agoIt's the same tradeoff with any package ecosystem: improved convenience but less control over the codebase. Leave any JS project alone for a couple months and as soon as you `npm install` you'll see something like "30 vulnerabilities (4 low, 8 moderate, 14 high, 4 critical)" The core WordPress is one of the most secure software in the world: there are thousands of people trying all the time to find exploits and the codebase is public. Go take a look at what CMS whitehouse.gov (one of the highest-profile hacking targets out there) is using.
- bzzzt 4y ago> The core WordPress is one of the most secure software in the world: there are thousands of people trying all the time to find exploits and the codebase is public. Go take a look at what CMS whitehouse.gov (one of the highest-profile hacking targets out there) is using. While I believe the core is reasonably secure, lots of plugins and webhosts aren't. Simply making the website code read-only would take care of a lot of issues, but then your auto-update won't work.
- angst_ridden 4y agoYou can make the the code read-only (from the web-server's perspective) and have auto update if you use a tool like WP-CLI and a cron job. I've had a few customer's sites on WP for decades without any hacks. But I also carefully restrict their plug-ins, and disable PHP in any of the upload directories.
- jeroenhd 4y agoI wasn't surprised to read that once again the plugins were the cause of the security issues. I don't know what the dynamics are for WordPress plugin developers to write this much vulnerable code, but WordPress itself has had very few vulnerabilities over the years. Even still, the vulnerabilities this plugin exploits have CVE numbers starting with 2016 and 2019. I'd say that you can use WordPress for websites perfectly fine as long as you maintain your web server platform like any web server platform: with regular security updates and migration or mitigation plans if those updates are breaking anything. Running a website under your own control is not the one-time setup that many WordPress hosting sites promise customers. It usually doesn't take much time to hit the update button, but if you can't spend an hour a week/month making sure your website is still up to date, you shouldn't host your own stuff. Pay someone to manage it for you instead.
- acdha 4y ago> I don't know what the dynamics are for WordPress plugin developers to write this much vulnerable code, but WordPress itself has had very few vulnerabilities over the years. I think it’s a microcosm of the larger PHP problem: it’s a language and environment which is really easy to get started with, but requires significant skill and experience to use safely. The core developers of both have made some improvements but the community culture still has room to go and there’s a huge discoverability / training gap for all of the people who are just getting started — WordPress is incredibly popular so there’s a constant stream of people who just want to change their site and haven’t thought about all of the different angles for attack.
- thaumaturgy 4y agoWordPress's problems have nothing at all to do with PHP. WP is currently lagging PHP best practices by about a decade. You could in theory swap all the PHP out for, I dunno, Ruby, and if the WP architecture didn't change then it would still have all the same problems.
- jawngee 4y agoA decade is being kind of generous. But your comment is spot on.
- samuell 4y agoThe idea of tons of 3rd-party plugins, with WordPress and also Drupal, is just disastrous for security. Anyone with any ability to write a little PHP would be far far better off building their site in a CMS like ProcessWire [1], which has a very small core, but a extremely powerful content (PHP) API [2], which means you can replicate pretty much everything you have in Wordpress and Drupal with a few API calls in your templates. This means you build your listing and presentation-logic custom made with the minimal amount of code needed, and the attack vector shrinks to pretty much nothing, as long as you don't voluntarily do something stupid. [1] https://processwire.com/ https://processwire.com/ [2] https://cheatsheet.processwire.com/ https://cheatsheet.processwire.com/