String concatenation SQL injection in the year 2026.
String concatenation SQL injection in the year 2026.
>Rather than executing an SQL query directly, we’ll use the dbDelta function
>Note that the dbDelta function is rather picky, however. For instance:
>You must put each field on its own line in your SQL statement.
>You must have two spaces between the words PRIMARY KEY and the definition of your primary key.
>You must use the key word KEY rather than its synonym INDEX and you must include at least one KEY.
>KEY must be followed by a SINGLE SPACE then the key name then a space then open parenthesis with the field name then a closed parenthesis.
>You must not use any apostrophes or backticks around field names.
>Field types must be all lowercase.
>SQL keywords, like CREATE TABLE and UPDATE, must be uppercase.
>You must specify the length of all fields that accept a length parameter. int(11), for example.
>> s/you must/thou shalt/g
Please don't. There is absolutely no reason not to use the extremely simple and powerful combination of:
* a headless CMS / static website generated, of which there are a bunch so pick the one you like the most. My go-to is Hugo but it is somewhat complex
* a static hosting service with a generous free tier like CloudFlare Pages/Workers, Netlify, Firebase Hosting, etc.
Your blog costs nothing, has zero attack surface and zero maintenance.
https://github.com/hparadiz/technexus
https://github.com/divergence/framework
My framework is faster than Eloquent at this point.
I cringe everytime.
WordPress is actively degrading the security and quality of the web I general. Has been for many many years.
PHP might seem worse than other languages due to a combination of factors:
- It's the most used one by far, even though few of us like to admit it.
- Old tutorials still come up during web searches, so "SELECT * FROM `table` WHERE id = $id" will still be written today.
ASP had a bit of a barrier to entry because it required all the MS. Whereas PHP was everywhere.
But what do you do in that situation? If they change the structure too much, then either they make it impossible to upgrade an existing site, or potentially break a whole bunch of things said sites depend on (mostly themes and plugins). And that ease of upgrading is likely what stops a lot of people just migrating away to other solutions.
And since the WordPress foundation controls the extension marketplace, they can reliably determine which parts of the API surface are in use, or even invest a chunk of money every month to send AI-written patches to plugin maintainers to ease the transition.
There would be so many ways to improve the situation (to the benefit of WordPress maintainers, customers, and ecosystem vendors alike, mind you!), but alas, they are stuck to their ways and will not.
What WordPress foundation?
https://news.ycombinator.com/item?id=42689906
The foundation was, at some point in time when the drama was at its peak, mostly a feel-good non-profit initiative.
It’s clear that the core WordPress developers have a very different idea of project stewardship than the Gutenberg devs do.
Anyway, I probably shouldn't comment as maybe WP has progressed but it doesn't sound like it.
Alternatively, folks that aren't particularly technical hacking together a solution that works 'well enough' for what they need, and agencies that only have the interest/capacity to use one platform deciding that each and every customer needs to use that platform.
If you're a skilled programmer WordPress is probably not a good solution for your issues, but if you're more of a designer or hobbyist that wants a somewhat hacky extendable blog system it's pretty easy to use.
But yes, I agree, WP is very useful for those times when you need to run a quick `sudo rm -rf /` command but can't get to a terminal.
If code is poetry, Wordpress is a new genre of it, probably?
[0] https://wptavern.com/wordpress-org-login-introduces-mandator...
You don't need many libraries in a typical project, because PHP is batteries-included and if you use a framework it does all the rest for you, that is true. But there are still hundreds of thousands of packages with billions of installs:
PHP can run the same code fully dynamically typed or with very strict type annotations, depending on your requirements. It has runtime reflection APIs that are so cheap that you don't really have to think about using them. You can do OOP or FP with PHP, or even procedural HTML-interleaved-with-PHP if that's your thing. It has late static binding, so you can defer to child classes from their parent class. There are generators and fibres as first-class language constructs now. Property hooks are an extremely clear pattern, way better than in many other languages.
Generally, there have been tons of new syntax extensions over the years, and they all slot in gracefully. With PHP 8.6, we're going to get partial application for functions, which will make PHP 8.5's match expressions one of the most ergonomic implementations I have seen yet!
It would definitely be a breaking change and unmigratable.
User data should of course be passed via prepared statements.
> WordPress database access abstraction class.
class wpdb {}
So this is some sort of ORM provided. $results = $wpdb->get_results( "SELECT * FROM {$wpdb->prefix}options WHERE option_id = 1", OBJECT );
> Some of the methods in this class take an SQL statement as input. All untrusted values in an SQL statement must be escaped to prevent SQL injection attacks. Some methods will escape SQL for you; others will not. Check the documentation to be sure before you use any method in this class. For more on SQL escaping in WordPress, see the section entitled Protect Queries Against SQL Injection Attacks below.It does not however prevent $wpdb users from NOT binding query parameters, which leads to this vulnerability.
Also, regarding placeholders, historically many DB and frameworks do not support passing lists for a value in a placeholder (like "WHERE id IN(?)") so users of such software fall back to string concatenation.
> data: {'requests': [{'method': 'POST', 'path': 'http://:'}, {'body': {'requests': [{'method': 'GET', 'path': 'http://:'}, {'method': 'GET', 'path': '/wp/v2/widgets?author_exclude=1%29+AND+1%3D0+UNION+ALL+SELECT+0%2C1%2C0x323...
hmm yes, definitely. You are the principal.