Comment by toyg
9 hours ago
TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
9 hours ago
TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
Yes and Wordpress is a pile of garbage.
How many times has Google been hacked? It's not zero, but just because something is popular doesn't mean it has to get exploited. Repeatedly.
There is only one Google and it is operated by professionals. Who do not need to disclose the vulnerabilities that they find.
Wordpress is pretty much the exact opposite of that.
We can say the same about most of open source.
It's the WordPress plugin ecosystem that's more often the security nightmare though.
nginx serves a third of web traffic.
Nginx also has cves.
Nowhere near what WP has, and nowhere near the crap design allowing it, and the clusterfuck of bad decisions WP has that enables them...
1 reply →
That's not really true.
Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.
You could've included a little more nuance. An interpretation of your response is "being the most popular remotely accessible software" != "the most attacked", which would need defending.
25 years ago alache hosted about 10 times as many sites as IIS, yet IIS was always the one being backed.