|
|
|
|
|
by Saris
977 days ago
|
|
Surprisingly I've run a handful of WordPress sites for 10+ years now, some with quite a few plugins for e-commerce stuff, and haven't had any issues with sites getting hacked. I mostly think it's due to updating quickly, generally I update the next day and manage it all with a central service, and just not using unknown plugins that don't get updates. |
|
* Using a plugin written by a someone who has no idea how SQL injection attacks works.
* Failure to update WP/plugins after a known security vulnerability.
* Poor general security practices. Tip: don't use your domain name with the "o"s replaced by "0"s. Also, don't create a secret backdoor into your site because the owner has trouble remembering his password.
* Your web host itself has been hacked (https://www.bleepingcomputer.com/news/security/godaddy-hacke...)