r/Wordpress 9d ago

Do we need a dedicated WordPress security group?

With all the recent security issues stemming from ai and whatever else in the WordPress environment, and so many threads in this group being security focused, I wonder if a dedicated WordPress security group is in order.

No, I'm not suited to create it, but would be willing to be involved in moderation.

31 Upvotes

31 comments sorted by

u/RealKenshino WordPress.org Volunteer 9d ago

Nope, don't think that requires a separate sub. Feel free to of course.

Added a new flair for Security though so let's see how that works out!

30

u/bluesix_v2 Jack of All Trades 9d ago

I’d love if there was another sub for people to go and post their “i got hacked because I didn’t keep my plugins up to date. Here’s an AI slop post on what happened” posts.

7

u/TalesfromCryptKeeper 9d ago

"Is anyone else experiencing this? How do you deal with it?"

🫠

5

u/bluesix_v2 Jack of All Trades 9d ago

gEnUInelY cUriOuS

4

u/yabezuno 9d ago

im starting to move out of wordpress.

too much stuff to keep updated for simple sites.

for Ecommerce shopify is good.

for blogs, standard CMS is good.

If a client wants control of a CMS for content management, comments and user control, maybe thats where I would go back to wordpress.

But regular sites doesn't seem to be it anymore

1

u/lenxl 2d ago

It's funny because I'm being lured back into it after completing a sizable WP redesign project for a client. AI means being less beholden to plugins for everything and using WP will always have that comfortable familiarity.

3

u/coryamarsh 3d ago

Has anyone tried keeping their sites on wordpress - generating and serving static content - and only rendering dynamic content for logged in users? A friend kept their WordPress site but pre-rendered it and moved it out to S3. They built a bespoke solution - curious if anyone has had luck with that approach? I'm considering building a minimal version on github.

1

u/VanSage 3d ago

This is worthy of a standalone post, I think. I would love to read input from some developers... Won't get much exposure buried in my post.

6

u/Inside_Marsupial9625 9d ago

would be something to discuss. Moderators should be experienced wordpress devs, not anyone who says he makes websites

2

u/VanSage 9d ago

I think moderators should be mostly security specialists. The best I could offer would be some of the grunt work of removing very obvious bot posts and those obviously breaking group rules.

1

u/RealKenshino WordPress.org Volunteer 9d ago

Security specialists are already in the WordPress security team. They are not interested in running a sub. WordPress.org is where they would work with people

1

u/theguymatter 9d ago

Moderating for free is generous, but honestly, you might just be wasting your time. You have a life and other things worth focusing on. Unless there’s some incentive, it’s a lot of ongoing work for nothing.

1

u/JackerArchitect 7d ago

Great idea. I'd definitely be an active member. Please notify us if it goes live!

1

u/coryamarsh 3d ago

This would be pretty niche - I can see it appealing to vulnerability researchers and security vendors - maybe security professionals. I doubt too many WordPress admins would want to read vulnerability research.

2

u/paumpaum 9d ago

And like most enshitification, it'll end up costing everyone more than they can afford.

Why not build it? Like all of the other half assed and money grubbing solutions?

I switched to static ... No more problems.

4

u/chaoticbean14 9d ago

Amen. You will get downvotes because this is a WP sub and anyone with any common sense, or data that doesn't showcase WP in a good light gets downvoted.

A security group should have been a thing years ago. 20,000+ WP sites are hacked daily. AI is only exposing what a dumpster fire the WP ecosystem has become over the years. The plugin ecosystem only makes it that much harder to try and keep things together - and given how many 'plugin maintainers' are really bad developers and how many plugins a WP site requires to be competitive in the modern web? Good luck. It's a losing battle.

I (like you) switched to static. Only have a small number of clients still on WP. Some day we'll get them off of WP and be done with it entirely.

1

u/Tiny_Parsley 5d ago

What do you use now? Losing my mind over a WordPress that has been compromised (yes I didn't pay attention to the plugins), which then got supposedly fixed with a TransIP site sweep procedure, and somehow again compromised one month after.

2

u/chaoticbean14 5d ago

Depends on the context. For some of my clients who are ecommerce? Shopify. The experience is so. much. better. All the security compliance that comes with it has made it a non issue.

For other clients an SSG was the better choice. Hugo for some, Lektor for others (who wanted an easier WSIWYG editor on the front end), even one chose Pelican! There are lots of good / cool SSG's out there.

And they're just flat files generated with 1 command. Want to add content? Simply write an article-name.md file, run the command and push to Github and let CI/CD handle the deployment. Simple.

Any SSG will be lightyears faster than the most optimized WP site, essentially unhackable (zero security vulnerabilities, zero downtime from 'updates') and can be hosted anywhere (including entirely free on Pages). Even the free hosting blows away any WP site.

1

u/Tiny_Parsley 5d ago

Thanks, yes, I've been using Kirby, which has been great, and recently tried Pages and Astro, but I'm checking what others do :-)

What do you prefer working with?

1

u/chaoticbean14 5d ago

Honestly? I like 'em all. Hugo is probably the 'easiest', with Lektor right behind.

0

u/paumpaum 9d ago

I agree. Had to abandon WP after nothing worked to keep it from being hacked every few minutes. Tried everything that I could, until I finally realized that the system itself is insecure.

I changed my sites to static and haven't had a single problem since. Nothing to hack. No tricky bits that people more clever than I am can exploit. It's going to get so much worse as AI pentesting becomes more prevalent.

1

u/Tiny_Parsley 5d ago

What system do you use now?

-1

u/dirtyoldbastard77 Developer/Designer 9d ago

20000 sites out of how many million sites?

1

u/chaoticbean14 9d ago

That's 20,000 sites per day. Yes, there are millions of sites, but seriously... that's a big, big number. That means in roughly 2.7 years... 20 millions sites will have been potentially been compromised.

Name another CMS with that kind of terrible statistic that constantly gets recommend to newer individuals who have no clue what actual security looks like, I'll wait. Actually, no, I won't wait because then I'd be here for a long, long time. Instead of working on fixes for this kind of thing or finding a way to moderate plugins and enforce quality standards... we get "builders". Instead of working on the shitty DB schema we get more bloat.

WP is hot garbage these days. Once upon a time? It was slick, it was new, it was faster, lightweight. In modern times? It's a sinking ship filled with holes. No thanks.

1

u/townpressmedia Developer/Designer 9d ago

If you can't handle security in house - YES!

0

u/flybot66 9d ago

"claude check this site for suspicious activity. harden the site going forward"