Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.
Lots of counter examples and definitely no clear relationship. IMO its up to the person making the claim to provide evidence.
The most popular widely deployed software will be the most valuable to attack. That most fail is a function of other properties of the software.
Just today I spent three hours to manually fix a page where a customers site was defaced after they installed and then uninstalled a translation plugin. I had to write a script that manually check every single instance of translatable text there is on the website.
Wordpress is pretty much the exact opposite of that.
It's the WordPress plugin ecosystem that's more often the security nightmare though.
Complexity does not lead directly to exploits, letting errors be ignored does. At what level an error can be ignored - that's quality control. And one can tell poor quality software by how exploitable it is.
Indirectly then? More complexity means more interacting parts, more complex interaction might hide flaws in ways it's hard to predict without looking at the big picture, which might be too big for a single person to picture (he).
I don't advocate for oversimplified systems, the same way I don't advocate for overcomplicated systems. I advocate for finding an equilibrium.
WordPress is a software design from the early 2000's - and not a particularly good example. Even back then there were more secure designs.
Take QMail for example. A simple design, it had security baked in from the start, and remains one of the most secure software packages in history. This exploit would have been prevented if WordPress had followed QMail's security designs. Enforced data flow, avoidance of parsing, eliminating untrusted code, and eliminating bugs by choosing code paths with fewer variables, would've all prevented this bug.
DJB wrote a paper on QMail[1] to try to explain what worked and what was unnecessary. Anyone implementing new software (and wants it to be secure) should consider these [and other] design points. Popular software doesn't have to be bad software. [1] https://cr.yp.to/qmail/qmailsec-20071101.pdf
People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.
Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.
Prime example: whitehouse.gov.
If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.
But people on HN like to lump the good in with the bad because everything is binary.
Probably true, but for whatever reason Wordpress seems to attract an awful lot of people that do not know what they are doing
And that is insecure Wordpress: people lego-mounting sites without touching code, only with plugins.
Works as intended, that's why WP has been so popular
Cons: it has a low entry barrier
People who _don't_ know what they are doing are using WP for every project, that they touch, because it is all they know. Given WPs database design, the assumptions baked into that, and the complications resulting from that, make anything other than a posts and pages website a PITA.
This in turn requires one to install shitty plugins, or spend time developing a minimalistic solution to each new challenge. With every plugin the attack surface grows, and the vast majority of larger WP sites is this cobbled together mess of WP plugins, having some WP expert trying to make them all work together without stepping on each other's toes, while hopelessly falling behind on updates, because updates could, and _will_ break things.
People only knowing PHP and WP, try to use WP as a sledgehammer, not realizing that hammer actually being made out of glass. Very few plugins are actually minimalistic, no-bloat, safe, well-developed. Lots of those plugins are 80% marketing fluff and wanting to make a business out of worse than mediocre code bases. That's also due to many people in that community being exactly those, who don't know anything but WP.
Even normal core WP updates can break the legality of ones site. I have had that at some point, where after some WP update it started loading emojis from a friggin third party, to replace the unicode symbol I had used. I was furious, because this needs to be part of the data protection policies/statements. One does not simply load a third party shit, replacing what the dev actually put there, which was just a unicode symbol. That's an idiotic thing to do. If I wanted third-party emojis, I would have included them myself.
Finally, some big pages run on WP says not much, given the catastrophic state of many websites. whitehouse.gov is laughably badly made. Another complete failure. The first thing I see that it loads Google tags manager. A government site loading shit.
fonts.googleapis.com
googletagmanager.com
gstatic.com
parsely.com
All this crap. And this is only what is loaded right out of the box. I haven't even allowed their shitty scripts to run yet.And the navigation font is tiiiny. What a horrendous design.
When I click on some navigation link, it wants to go to:
https://www.whitehouse.gov/wp-content/uploads/2026/01/Wide_Site_Primary_02.mp4
lol. From nav directly to some mp4 video?? Not a URL of a page, which then would display the video, but a URL directly to a video? Good that my noscript blocked media on that domain!If it is a prime example, then it is a prime example of a very shitty made website, by people, who don't know what they should be doing.
So all this shows is one can make a shitty site using WP. Great. I am sure one can also make a not shitty site using WP. Like you say, _"If you know what you are doing ..."_. Just that most WP people don't. They don't know how to not make a mess, or choose the short-term easy way out, and install tons of shitty plugins. Many of them just have to put things up once initially and are paid, or hold the hand open for some maintenance fee they extract, required only due to how badly made these WP sites are.
Drupal (also popular in governments and such), by contrast, will check that it can’t write to anything but its designated file uploads directory, and complain if it can, and has careful guidance around avoiding letting uploads be accidentally executable too. The blast radius of the typical vulnerability, and the possibility of persistent takeover, is drastically reduced.
It’s possible to use C correctly, but in practice using it invites security problems, because it’s frightfully easy to make subtle but disastrous mistakes, even for experts, so there are reasons why people are moving to safe languages.
WordPress is that kind of bad. It has always been bad, though it’s somewhat less bad than it used to be. Some of its badness is a part of how it got popular.
You do not need to. Its to help people who cannot manage an ssh login update. You can use the cli to update if you can. I am pretty sure big sites will not be doing their updates from the big site.
The problem with plugins is lack of a proper framework. Its very easy to do things like pass user inputs into a query by strong concatenation because you have to make in extra effort to not do so.
That said, its no guarantee. I have seen people do things like call exec on user inputs in Django.
> has careful guidance around avoiding letting uploads be accidentally executable too.
That should be the default, not something you need to take extra care over.
I can mitigate the damage a little bit with some chattr +i, but overall, every plugin is another gigantic attack surface.
I agree. That’s one of the problems of PHP’s file-based execution model, and how the likes of Apache and nginx work. Drupal is no paragon of security, but it’s far closer than WordPress. For all its faults, even Node.js avoids this class of problem.
You know that the scripts doing it are optimized for success rate, so the types of requests they send give you an impression of what's actually out there.
It's clear to me that once we finally achieve rogue AGI, it is going to propagate through unpatched WordPress WooCommerce instances.
And its closely related cousin, Joomla.
Sometimes the same IP address hits two or three URLs before going dead.
Sure is quiet around here at night.