4 ms·
Alternate viewpoint: I keep several WordPress sites online, mostly for testing & experimentation. They are all configured to auto-update. They have a mix of a
by trog 3y ago
Alternate viewpoint: I keep several WordPress sites online, mostly for testing & experimentation.
They are all configured to auto-update. They have a mix of a small number of plugins - mostly high reputation ones.
They sit there and work and require next to zero maintenance.
Yep, they are regular hack targets. The biggest risk is brute force attempts overwhelming the server (until recently, I ran them on a 256MB VPS, because I like suffering, I guess), but with some decent protection there (e.g., fail2ban) it reduces risk significantly.
I would say if your plugin mix is simple and you have auto-updates, there is almost nothing to worry about for the vast majority of people.
- x3sphere 3y agoYep as long as you remain up-to-date I've never had a WP install hacked. Not saying the security is good - but there a lot of vulnerabilities reported with other similar software too. Don't know if I'd say WP is worse. Given its market penetration, it is going to be targeted more often. I've noticed a lot of big companies are using WP for their blog as well... companies that could easily pay for something fully custom (such as Sony/Playstation), so they are arguably doing something right.
- xp84 3y agoHacking and brute force attempts, and the risks they pose to uptime are big reasons I advocate for this. And yes, plug-ins matter but a lot of sites tend to have them installed. My point is, there’s rarely any reason to have to deal with any of that stuff. Plain old Apache or Nginx or S3, serving HTML behind cloudfront, is impossible to hack and basically can’t even be DDOSed. There’s little reason not to. It’s not like anybody even uses the features of WP that need to be dynamic, like the commenting feature which can’t be turned on without a flood of bot spam.
- herbst 3y agoThat's what many of those hacked sites thought. And yet Google is full of hacked wordpress sites of any caliber.
- trog 3y agoThis is just confirmation bias though - what matters is the percentage of hacked WordPress sites. It's probably not as high as you think.