useWackyUnit ? 'F' : 'C'Use a common framework / stack don't update and you will likely be hit by an automated exploit.
None for yours.
Wordpress is a great example. It has better security than your average php blog.
Your average php blog doesn't get attacked by automated exploits attacking known endpoints either.
A determined hacker would find it easier to buy an expliot to a common framework compared to figuring out your custom framework.
We've seen redis and mongo boxes getting hit by no password logins within seconds of going on the public web. Joe's custom cache and database doesn't get hit.
a) 10,000 users of a common framework + 1 user of a custom framework.
and
b) 10,001 users of a common framework
I contend that (a) has a larger attack surface than (b).