Hacker News new | ask | show | jobs
by Tijdreiziger 755 days ago
Personally (and this is just based on my gut feeling), I don’t think WP core is more insecure than other CMSes.

The real problem is the plugin ecosystem, which is not impossible to navigate for the disciplined, but at times bears resemblances to the Wild West.

So, what ends up happening is:

1. Cheap ’experts’ install every plugin under the sun.

2. One of these plugins inevitably gets pwned.

3. Headline: ‘WordPress backdoored’.