Live data from Hacker News

The Next WordPress

wsvincent.com

21–30 of 43 posts

Re: The Next WordPress

#21
> WordPress itself is an inherently insecure platform.

Linking to regular security updates for a system is proof that that system takes security seriously, not that it is insecure. I'd worry about an open source project that didn't have regular security updates.

Also, "inherent" is silly to use in this context.

Re: The Next WordPress

#23
I was recently considering creating an IDE specifically for WordPress with built-in completion, tips and mapping for people who are skilled at programming but new to WP development. Would anyone use it?

Re: The Next WordPress

#25
I would love to maintain our websites with a static site generator and manage updates via pull requests to our version control system.

I don't have a single user who would understand that sentence. That's why we use WordPress.

Re: The Next WordPress

#26

First of all, Wordpress is known to fix security issues quickly and platforms with many developers have more eyes on the code so it's only natural that they have a LOT of reported vulnerabilities. This does not mean that it's "inherently" insecure. A static site can't enable... - User management (Members) - On-site-comments (That Search engines can find) - Voting (Polls & Ratings are very popular on Wordpress!) - Car…

> This does not mean that it's "inherently" insecure.

It's a pretty strong indicator though.

Re: The Next WordPress

#27

I would love to maintain our websites with a static site generator and manage updates via pull requests to our version control system. I don't have a single user who would understand that sentence. That's why we use WordPress.

Maybe with a pre-configured, cross-platform App - It might be "easier", but then you'd have to have it auto-update as well.

While with any dynamic CMS, it's just - go to this site and login.

Re: The Next WordPress

#28
post #13
post #4

I think the author assumes that all wordpress sites are simple blogs. Woocommerce alone powers 30% of e-commerce sites.

What makes you think that? The word "blog" is nowhere in the article. It's clear to me they're talking about WP the platform.

wonder how one does a static e-commerce site.

Re: The Next WordPress

#29
post #26

First of all, Wordpress is known to fix security issues quickly and platforms with many developers have more eyes on the code so it's only natural that they have a LOT of reported vulnerabilities. This does not mean that it's "inherently" insecure. A static site can't enable... - User management (Members) - On-site-comments (That Search engines can find) - Voting (Polls & Ratings are very popular on Wordpress!) - Car…

> This does not mean that it's "inherently" insecure. It's a pretty strong indicator though.

No, the more developers the better is usually the case.

Any app that is large and complex at it's core with a very wide API that is continuously expanded on and occasionally refactored will get new bugs and vulnerabilities along the way.

Couple that with many developers that are exchanged now and then and you have a nice unavoidable mess to handle whether you want to or not.

Also, a majority of the vulnerabilities are in abandoned and badly coded plugins:

https://www.wpwhitesecurity.com/wordpress-security/statistic... (2014)

Re: The Next WordPress

#30
It's more precise to say "problem" when you mean something bad, and not "issue," which is neutral. I am pretty sure that "issue" is a bureaucratic euphemism.

It seems the higher up you go, the worse language gets:

  Technician: "The server is on fire!"
  Manager: "Uh . . . the server has a 'problem.'"
  Senior Director: "Ahem, the service has an 'issue.'"
  Owner: "You mean my server is on fire?"
Actually, maybe it's middle management.
Post reply on HN