Hacker News new | ask | show | jobs
by bell-cot 1009 days ago
Go with the one you know. "WP got hacked" is (~99% of the time, when on a competently-run web host) a case of (1) Webmaster used an iffy WP Plugin* or few (the plugin was obscure/orphaned, and not getting timely security updates), (2) Webmaster didn't bother installing Plugin security updates, (3) Webmaster disabled WordPress' own automatic security updates, or (4) Webmaster wasn't smart about his admin password.

*or Theme, or other 3rd-party code

1 comments

I'd say over 90% of it is #3 - if you have auto-update enabled, you're pretty close to secure, unless you run millions of unpopular plugins.