Also, appreciate you still stopping into HN to chat :)
If the knock on that product is bloats, and the compromises adoption, how is X a benefit to those who refuses to abopt the whole alphabet?
HN =/= WordCamp etc.
Tia :)
Because that's always the catch with any script really. If you're using third party themes and plugins for anything, then you're putting trust in the developers of said themes and plugins that they know what they're doing coding and security wise.
The exact same situation is true of everything from WordPress to Drupal to vBulletin and XenForo to MediaWiki and Magento.
The "sheer breadth of the ecosystem" in self-hosted WP is also where so many of the problems come in (compatibility between products, security issues, etc).
I'd argue it really is worse in the WP scene vs Drupal, partially because of the 'ease' of the code for newbs to get started. There's no culture of automated testing in the WP community at large, but some other platforms at least allow for that. There are people who write clean and well-tested WP products, but they're likely a minority, if you're looking at the ocean of stuff released over the last 5-10 years in the WP space.
This isn't true. I've been running and managing 15+ WordPress websites for over 5 years now and not once run into any issues like you're describing, and I certainly haven't lost sleep or become 'tired' over it.
Using a good tool like ManageWP (or InfiniteWP, or any of the others, take your pick) makes managing multiple WordPress websites a breeze (e.g., it alerts you every morning with what updates are available), and with their paid backup/restore functionality there's really nothing to worry about if something did go wrong. Combine all this with a nice WAF or security plugin and you're fine. Or you can use a service like MalCare that combines both.
If you go months and years without updating, then yes you're asking for trouble like any other piece of software.
Too many people used WordPress over 10+ years ago and just stick to the same speech about PHP and WordPress and security and all that and how everything is so bad, and that a different CMS that nobody uses in a obscure language is sooo much better and secure (that won't be here in a couple of years in all likelihood.)
I think it is just wordpress' ubiquiti that has made it a security issue though. Attackers are quick to build exploit bots the moment a new vulnerability is found and they scour the web for unpatched sites.
So if you don't stay on your toes, you will get pwned sooner or later with a wp site.
Sorry for the confusion; I mean if there's a WP/Plugin/Theme update, I get notified every morning so I can go in and update (if needed.)
Many mom and pop type businesses find the lowest cost web designer they can find to build them a WordPress site then get upset with the hosting company when "the server gets hacked" and their site is redirecting to a malicious site.
WordPress is certainly a powerful platform but the fact that it is so easy for someone to get started is also a weakness because those people don't understand it isn't just set it and forget it.
I've screened / interviewed so many jr web "developers" who don't actually know how to develop a web app and they claim that installing WordPress plugins is development experience.
This setup lets me do 99% of my everyday work using the WordPress UI. For the remaining 1%, I can SSH and use the command line. I've had a scare or two in the past, but in general my websites haven't been large enough to be lucrative targets. Maybe someone who's running larger blogs can chime in on the security issues.
If you want a one click solution, DigitalOcean's WordPress droplet has a lot of security stuff pre-configured for you. They even integrate fail2ban with the WordPress login screen, which is something I never even considered of doing.