Comment on Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

<- View Parent
sugar_in_your_tea@sh.itjust.works ⁨4⁩ ⁨days⁩ ago

That is far too basic for most websites

Well yes, but that’s my point. WordPress does everything, and I’m offering tools that do one thing well.

If all you need is a static site, use a static site generator, not WordPress. If all you need is ecommerce, use an ecommerce tool, not WordPress. And so on.

unless you’re exporting it to a file after using the UI to create it?

I’m saying that if all you need is a static site, but you want something simple and hosted, Squarespace would be a decent alternative. Whether it’s actually static is beside the point, it’s probably more secure than a self-hosted WordPress site since you can’t just throw on a dozen plugins serverside, only use one or two, and then get hacked.

A swiss army knife can do everything, but it doesn’t do everything well, and it’s easy to use it insecurely, which opens you up to these sorts of attacks. I’m not going to suggest a drop-in replacement for WordPress (they do exist) because the problem is fundamental to the “one tool for everything” approach.

source
Sort:hotnewtop