4 ms·
I was never a big a fan of WP, but… I agree the ease of updates is an extremely important feature, especially for non-technical users. I'm working on a small co
by notlisted 11y ago
I was never a big a fan of WP, but… I agree the ease of updates is an extremely important feature, especially for non-technical users. I'm working on a small conversion project migrating content from a Joomla site to Wordpress. The original site was running on Joomla 1.5 (Support for this version ended in Sept. 2012!). The upgrade path was too cumbersome so the clients just "took the risk". It was compromised several times but "cleaned up as best we could". Needless to say, we're ditching that server.
Still not a fan of WP self-installs, but hosted on WPEgine with smart tech support, automatic daily snapshots with the option for non-technical people to back up or revert the whole thing with a single-click is super simple. For added security and performance we'll be using cloudflare DNS, applied a plugin to hide any evidence of wordpress use and use just a few well-known and maintained plugins. Nothing is perfect, but ease of use, ease of upgrades and ease of maintenance go a loooooong way. It's mighty budget-friendly too.
- edgarvaldes 11y agoWhat plugin are you using to "hide" Wordpress?
- jbeales 11y agoIt doesn't matter because it won't help much, if at all. The script kiddies are running scripts that check for known files in several popular CMSs, so unless the plugin makes major changes to WP's behaviour, WordPress will still be findable.
- shampine 11y agoOur boilerplate does a pretty good job of hiding that we are using WordPress. The only way you can tell via source is W3 Total Cache writing out a comment to the bottom of the page. Oh and WordPress SEO (Yoast) is a dead giveaway too. We see nowhere near the number of bots that our non boilerplate sites do. https://github.com/GunnJerkens/wp-boilerplate https://github.com/GunnJerkens/wp-boilerplate
- notlisted 11y agoI trust WPEngine's IDS to do a good job on these.
- greg5green 11y agoHell, I even had a non-important, BS Rails app get shut down on shared hosting (Webfaction) because someone tried random WP exploits on it (some plugin that accepted a POST and could be exploited via the payload). Rack stored the payload in a temp file and Webfaction saw the tmp file as a new file I didn't upload and suspended the app. The first time it happened, I just deleted the file and went forward. The second time, I just deleted the app. I know I could write a script to deal with this, but it was just a test, playground type app. All it did was make me say I needed to move my "blog" off WordPress and stop trying to host Rails apps on Webfaction. PS: The domain the Rails app was on had never hosted a WP site ever before. WP is just so ubiquitous that that they were just trying to hack any site -- even one that had like 3 organic visitors ever.
- notlisted 11y agoThis one: http://codecanyon.net/item/hide-my-wp-no-one-can-know-you-use-wordpress/4177158 http://codecanyon.net/item/hide-my-wp-no-one-can-know-you-us...