4 ms·
They should try to figure out why people don't upgrade. Maybe there need to be clearer reminders, or separation between features and security. The same goes for
by stse 17y ago
They should try to figure out why people don't upgrade. Maybe there need to be clearer reminders, or separation between features and security. The same goes for why people aren't making backups. I would imagine it would be quite easy just to diff the releases and exploit whatever got fixed anyways.
- gchucky 17y agoThere are pretty clear reminders. If you log into the Wordpress control panel, there's a bar that says "The latest version is x. Click here to upgrade." And they also built an automated update script that downloads, unpacks and installs it all for you. My guess is that people don't update because they fear potentially breaking their styles or something.
- philwelch 17y agoIf you make a small change to the style you're using, it gets overwritten on each update as long as it's a built-in style. The workaround is obvious (rename your changed style) but, as an example, I have always been too lazy to do this and I'm always behind the latest version.
- photomatt 17y agoYou should check out "child theme" functionality, which allows you to make lazy changes to the style without modifying any core files, which is highly recommended against.
- _ck_ 17y agoPeople don't upgrade because they break some plugin compatibility with virtually every release, sometimes even cookie compatibility with every other release (seriously). The upgrade process may be simplified but who wants to spend hours trying to fix compatibility every time they discover a bug they introduced with the last patch because they've broken backwards compatibility yet again. What they should be doing is a general upgrade release for non-technical users and a technical bulletin about what exactly was wrong so technical users can manage older versions as desired. Instead you have to dig for an hour in trac notes to find what the heck they changed and why. I have version 2.3 & 2.5 installs running safe because I've manually patched them and locked down the server. Delete any XMLRPC interface which is where half the bugs are introduced. The other half is the open ended admin interface which even regular users are allowed into to escalate privileges, which is asinine - you can even run PHPINFO through the admin panel as a regular member on many WP installs.
- kalid 17y agoExactly. I was running a much older version of WP and it took 6 hours to upgrade, including making sure all the plugins worked correctly. I immediately got the "white screen of death" afterwards and had to do a binary search to figure out which plugin(s) were the culprit (and then try to track down newer versions or alternatives). Some API changes are not backwards-compatible, so your themes have to be upgraded also (for example, the "show comments" api will by default say "comments off" on every page that doesn't allow them, which it didn't before). I'm sure there's other such changes I haven't yet noticed. I'm glad I upgraded, but it was a major hassle and nearly a full day's work in my case.
- bmj 17y agoI was very lazy about upgrading my WP installations. I was lucky to never have been a victim of a vulnerability. For some reason, I thought the process would be a PITA, when, in fact, it took me about 15 minutes to upgrade three installations to the latest release. That said, I don't use any plugins, so I didn't have to worry about compatibility issues.