Hacker News new | ask | show | jobs
by winternett 980 days ago
WP has had so many major compromises over the years I gave up on it and adopted using Drupal as a framework. I think Drupal focuses far less on for-sale modules and themes, which makes it far less exploitable. The way themes and modules are implemented are more secure than WP as well, and there has been a pretty good community running Drupal for many years now.

A lot of people try to impose the same kind of "name brand" identity on open source software, and it just doesn't work. Underneath, it's based on the same code and libraries, and a lot of the time it's vulnerable to human agenda and human flaws.