|
|
|
|
|
by dave1010uk
5431 days ago
|
|
Turning off the ability to execute arbirary code on your server through your webserver will also stop WordPress from being able to get security updates out to the millions of sites using it. While I much prefer going through SHH to manage my sites, there are likely 10x as many WP sites run by people who can only FTP. There isn't really an ideal solution in this situation (apart from education) so I think allowing easy updates by having weaker security may be best. Maybe there is a better solution that still works for FTP. If so, file a ticket. The WordPress Codex is a wiki and it looks like the docs on security could do with some improvements - sign up and help out. |
|