Skip to content

Comment on WordPress Core is Secureparent

Comments

Actually - I haven't had a single site hacked since implementing regular updates. And I'm managing hundreds of sites. With many plugins..

That's great, but all it means is that you just weren't in the crosshairs, not that you were actually secure. Automating updates is a wonderful way to open up an attack vector, as well - for example, a little while back, attackers got into the Wordpress SVN repo and back-doored a bunch of popular plugins[1]. Anyone performing "regular updates" without proper auditing would have installed malicious code that opened them up to full-scale breach.

[1] http://wordpress.org/news/2011/06/passwords-reset/

It is much more practical to secure a single repo administered by competent techs than it is to secure a zillion web sites run by people with no technical experience.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.