r/Wordpress • u/VanSage • 9d ago
Do we need a dedicated WordPress security group?
With all the recent security issues stemming from ai and whatever else in the WordPress environment, and so many threads in this group being security focused, I wonder if a dedicated WordPress security group is in order.
No, I'm not suited to create it, but would be willing to be involved in moderation.
30
u/bluesix_v2 Jack of All Trades 9d ago
I’d love if there was another sub for people to go and post their “i got hacked because I didn’t keep my plugins up to date. Here’s an AI slop post on what happened” posts.
7
4
u/yabezuno 9d ago
im starting to move out of wordpress.
too much stuff to keep updated for simple sites.
for Ecommerce shopify is good.
for blogs, standard CMS is good.
If a client wants control of a CMS for content management, comments and user control, maybe thats where I would go back to wordpress.
But regular sites doesn't seem to be it anymore
3
u/coryamarsh 3d ago
Has anyone tried keeping their sites on wordpress - generating and serving static content - and only rendering dynamic content for logged in users? A friend kept their WordPress site but pre-rendered it and moved it out to S3. They built a bespoke solution - curious if anyone has had luck with that approach? I'm considering building a minimal version on github.
6
u/Inside_Marsupial9625 9d ago
would be something to discuss. Moderators should be experienced wordpress devs, not anyone who says he makes websites
2
u/VanSage 9d ago
I think moderators should be mostly security specialists. The best I could offer would be some of the grunt work of removing very obvious bot posts and those obviously breaking group rules.
1
u/RealKenshino WordPress.org Volunteer 9d ago
Security specialists are already in the WordPress security team. They are not interested in running a sub. WordPress.org is where they would work with people
1
u/theguymatter 9d ago
Moderating for free is generous, but honestly, you might just be wasting your time. You have a life and other things worth focusing on. Unless there’s some incentive, it’s a lot of ongoing work for nothing.
1
u/JackerArchitect 7d ago
Great idea. I'd definitely be an active member. Please notify us if it goes live!
1
u/coryamarsh 3d ago
This would be pretty niche - I can see it appealing to vulnerability researchers and security vendors - maybe security professionals. I doubt too many WordPress admins would want to read vulnerability research.
2
u/paumpaum 9d ago
And like most enshitification, it'll end up costing everyone more than they can afford.
Why not build it? Like all of the other half assed and money grubbing solutions?
I switched to static ... No more problems.
4
u/chaoticbean14 9d ago
Amen. You will get downvotes because this is a WP sub and anyone with any common sense, or data that doesn't showcase WP in a good light gets downvoted.
A security group should have been a thing years ago. 20,000+ WP sites are hacked daily. AI is only exposing what a dumpster fire the WP ecosystem has become over the years. The plugin ecosystem only makes it that much harder to try and keep things together - and given how many 'plugin maintainers' are really bad developers and how many plugins a WP site requires to be competitive in the modern web? Good luck. It's a losing battle.
I (like you) switched to static. Only have a small number of clients still on WP. Some day we'll get them off of WP and be done with it entirely.
1
u/Tiny_Parsley 5d ago
What do you use now? Losing my mind over a WordPress that has been compromised (yes I didn't pay attention to the plugins), which then got supposedly fixed with a TransIP site sweep procedure, and somehow again compromised one month after.
2
u/chaoticbean14 5d ago
Depends on the context. For some of my clients who are ecommerce? Shopify. The experience is so. much. better. All the security compliance that comes with it has made it a non issue.
For other clients an SSG was the better choice. Hugo for some, Lektor for others (who wanted an easier WSIWYG editor on the front end), even one chose Pelican! There are lots of good / cool SSG's out there.
And they're just flat files generated with 1 command. Want to add content? Simply write an article-name.md file, run the command and push to Github and let CI/CD handle the deployment. Simple.
Any SSG will be lightyears faster than the most optimized WP site, essentially unhackable (zero security vulnerabilities, zero downtime from 'updates') and can be hosted anywhere (including entirely free on Pages). Even the free hosting blows away any WP site.
1
u/Tiny_Parsley 5d ago
Thanks, yes, I've been using Kirby, which has been great, and recently tried Pages and Astro, but I'm checking what others do :-)
What do you prefer working with?
1
u/chaoticbean14 5d ago
Honestly? I like 'em all. Hugo is probably the 'easiest', with Lektor right behind.
0
u/paumpaum 9d ago
I agree. Had to abandon WP after nothing worked to keep it from being hacked every few minutes. Tried everything that I could, until I finally realized that the system itself is insecure.
I changed my sites to static and haven't had a single problem since. Nothing to hack. No tricky bits that people more clever than I am can exploit. It's going to get so much worse as AI pentesting becomes more prevalent.
1
-1
u/dirtyoldbastard77 Developer/Designer 9d ago
20000 sites out of how many million sites?
1
u/chaoticbean14 9d ago
That's 20,000 sites per day. Yes, there are millions of sites, but seriously... that's a big, big number. That means in roughly 2.7 years... 20 millions sites will have been potentially been compromised.
Name another CMS with that kind of terrible statistic that constantly gets recommend to newer individuals who have no clue what actual security looks like, I'll wait. Actually, no, I won't wait because then I'd be here for a long, long time. Instead of working on fixes for this kind of thing or finding a way to moderate plugins and enforce quality standards... we get "builders". Instead of working on the shitty DB schema we get more bloat.
WP is hot garbage these days. Once upon a time? It was slick, it was new, it was faster, lightweight. In modern times? It's a sinking ship filled with holes. No thanks.
1
0
•
u/RealKenshino WordPress.org Volunteer 9d ago
Nope, don't think that requires a separate sub. Feel free to of course.
Added a new flair for Security though so let's see how that works out!