WordPress is now 13 years old
wordpress.org
wordpress.org
- Whitelist IPs for access to your wp_admin and wp_login.
- If you have the skills to automate WordPress updates yourself, remove all write access (except for the uploads folder) from the user WordPress is running as (i.e. www-data). It's all just unzip and untar over the structure of the directory anyways.
- If you remove write access, you might as well block the "cron" as well.
- Limit the WordPress DB user to the usual crud operations; don't let it create or alter tables.
- If you feel like getting really into it, whitelist explicit URLs. Maintaining it isn't really too hard, and it reduces your attack surface significantly.
- Set up even a simple nginx cache in front of WordPress - even a 1-5 minute cache will let your site run on crappy hardware and handle HN or Reddit with a minimum of sweat.
That said, the steps above are the broad painting of exactly what we've done, and a few Google searches will help nail down the specifics.
I've seen too many old php apps fall due to files uploaded and executed from /tmp. Bulletin boards, blogs, but this was all 8 years ago.
nodev,noexec,nosuid
is how I've mounted /tmp (and several others) for going on two decades. I've never been a fan of installers creating a single partition by default and I wish they didn't do it.Years ago, like you, I saw an out-of-date web app get hit by an exploit but was "saved" because of some of those mount options.
I'm a big fan of SELinux on public-facing servers too (especially web servers, for the same reason), but that's an argument for another day.
Edit: Also a big fan of SElinux, high five!
It's likely better than no cache, but an external cache will be much more efficient under load.
What's the benefit over a straight use of mod_cache or mod_file_cache then?
If you know what you're doing with it, it can be a very nice admin experience.
Somebody maliciously making thousands of MySQL tables in your DB as some sort of DoS?
Some plugins create their own tables.
Another safety tip, don't use 'admin' as the administrator username, and don't have any posts associated with the administrator as an author.
The folder structure also adds some minor security through obscurity.
There are other niceties in there too.
And then the community management and plugin/theme ecosystem. For example, Drupal may have a more programmer-approved API, but (at least when I worked with it back in 2011) it was a hundred times more complex to make a custom content-editing form in Drupal than in WordPress. Again, product over technology.
Points 1 and 2 here basically sum it up:
https://www.smashingmagazine.com/2011/11/wordpress-cms-crown...
It's a pretty amazing accomplishment what Automattic has done by staying so popular and relevant for so long.
Looking at it from a non-hardcore programmer's perspective:
* Quick to learn backend
* Easy to use plugins for non-devs
* Painfully maintaining backwards compatibility overtime
* It just works. Built to run from basically a potato of a server. E.g.: HTTP/transport check [1]
[1]: https://github.com/WordPress/WordPress/blob/master/wp-includ...
I haven't looked into it recently, but as I remember it, in the last 13 years there have been abundant legitimate reasons to criticize WordPress (many in the categories you listed). Yes, some people will hate on something just because they don't like it (regardless of any merit it may have). But I wouldn't lump in all of the people with legit criticisms of WordPress into the same group as "haters".
<azonenberg> wordpress is an unauthenticated remote shell that, as a useful side feature, also contains a blog
However having an usable remote exploit gives you a shell on more than 20% of the websites.
Then I had my first major vuln and spend my week-end fighting fires. Then I had my first encounter with encoding mess ups... an add-on going wild...
Fond memories...
Blogger was bought by Google a few months before WP appeared.
If you hit its (admittedly broad) use case, you are great, but if you go even a little off, its a pain.
The easy retort is "just keep it patched and up to date", natch. The ongoing costs/technical debt involved in maintaining a Wordpress install sometimes ends up being greater than what it cost to roll the thing out.
Wow, I'm getting old and complainy.
What you are describing could be attributed to any poor quality code, it's not specifically WP core that is to blame, but rather poor quality code built on top of it.
In regards to managing WP sites being costly and taking up time, I manage many WP client sites and find the opposite to be true (I did write the code for all of them, though)
But maybe I just prefer writing and working in my own familiar codebases instead of spending a small amount of time in that of others, a curse that a lot of PHP developers have (the "I'll write my own framework / cms" curse)
Consider though that when its template system was "invented" there wasn't much else available and people back then used to mix code and html all the time (both PHP and ASP developers). In their attempt to keep it backwards compatible we still have to suffer through the template system.
Disclamer: I'm on the dev team
Same thing with Minecraft. The huge community of modders pushed Minecraft to be as huge as it is.
Developers flock to both because they themselves can gain recognition and make money off these platforms.
I personally love the success story of both because they both started off small and initially had no intention of getting this big.
Given it's popularity , i would assume wordpress is (by sheer force of Trial and error ) the safest choice.
More tips always welcome :)
...most of the sites with really important data have long since migrated away. Haha