Script kiddies have awesome tools
dow.ngra.de
dow.ngra.de
* Reliance on ad-hoc hand-coded SQL.
* A system that registers psuedonymous Internet commenters in the same user table as Wordpress administrators.
* Mishandling of internationalization.
Yes, Wordpress is also the most popular blogging platform, and yes, it's also much more dynamic than its competitors, but phpBB and vBulletin seem to have had better track records than Wordpress have. It's just not very secure.
Let's look at the roots of PHP: it was never designed as a programming language, it was a tiny script language used to create Rasmus Lerdorf's website. Thus, it has a lot of oddities like the === operaor.
Do you know why it it is there? Because they wrote a broken instr() wrapper and messed up the error handling. And instead of doing one thing right, they added another obfuscation layer. Great design.
Then, PHP was traditionally used by webdesigners, not programmers. This lead to tons of bad code and bad practices. It is not that you cannot write elegant code in PHP, but there is so much more bad code around that it is hard to find the good code.
So, why do wonder about this?
Real hackers can appreciate every damn language out there. If it weren't for Basic in the early 80s, I wouldn't be programming now.
PHP is a wonderful gateway language for a generation of web programmers. It is installed on every webserver and is always ready to rock-n-roll. No other language has achieved that level of ubiquity.
I think we're a few years past the arguments you make against PHP. If you want to be trendy, you should rail against the people running Internals (namespace separator).
It was not created by programmers. It was created by web designers (hence its great visual design).
Wordpress was probably the only company that has migrated from Ruby to PHP (when they purchased Gravatar).
http://www.oreillynet.com/ruby/blog/2007/09/7_reasons_i_swit...
This is just childish. Different tools and languages have different uses. End of story. Ruby isn't better than PHP, PHP isn't better than Ruby - That's like saying a screwdriver is better than a saw - It depends what you're trying to accomplish with the tool.
Also, If I understand the architecture of Movable Type correctly, it renders much of the site into static pages. I would expect that this tends to reduce the number of points where vulnerabilities would be possible, at least as far as points where it might be exploited via causing it to execute with malicious parameters via an HTTP request. i.e. In Wordpress, every page you load is the result of the execution of some PHP scripts, while in a blog that is rendered to a bunch of static files, it's conceivable that the only thing that unauthenticated users can mess with is the comment system.
http://www.google.com/trends?q=joomla%2C+wordpress%2C+drupal...
"No sympathy for the devil, keep that in mind. Buy the ticket, take the ride."