Hacker News new | ask | show | jobs
by mattigames 2413 days ago
Well, is exactly the same for any npm package or any python package as do many other languages, a lot -if not all- bad security comes from 3rd party plugins.
2 comments

I'm perfectly capable of bad security on my apps without the use of 3rd party plugins, thank you very much!
Technically the same perhaps. But the actual history is pretty different. WordPress plugins are notorious for RCE type vulnerabilities.
I wrote one during my early years, in fact [1]!

1: https://jeremyaboyd.micro.blog/2016/11/20/that-time-i.html