Skip to content

Comment on WordPress Core is Secureparent

Comments

You're right, the post is essentially meaningless. If it's secure why doesn't MI5, CIA, and banks use it as their CMS? Oh because it's not that secure.

In addition to your questions, I would ask

* What types of attack is it secure against?

* How much work is involved in doing all the ongoing maintenance?

* The risk tends to come from plugins, but those plugins are one of the main selling points of Wordpress. To what extent does this lessen Wordpress's value proposition?

* If you do ever get hacked, what kind of auditing is there? What help does it provide for damage limitation?

The OP is an overly-simplified response to typical boilerplate comments - [insert language or framework] is [fast/slow/secure/insecure]. Of course Wordpress is secure enough for the average professional site as long as it's maintained, but the OP sounds like a car salesman saying "Sure it's _real_ fast" without telling you the actual speed.

That's kind of an absurd statement - that logic implies that MI5 and CIA use everything that is secure.

As it happens, we have a number of Fortune-50 banks and financial institutions as clients who host their WordPress with us <shrugs>

The point is that secure is not an absolute, but a relative value. There will be many Fortune50 projects where Wordpress will be plenty secure enough.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.