Earlier quoted context omitted.
> This does not mean that it's "inherently" insecure. It's a pretty strong indicator though.
Not really. Sometimes you hear about the WordPress security vulnerabilities that are patched, but still exploited, and this is mostly a problem with people not keeping an eye on security updates. Combine that with the popularity that WordPress has drawing in people who know enough to program themes and plugins, but not enough to program said themes and plugins securely (avoiding simple SQLi and XSS) and you get the p…
Re: The Next WordPress
#41Also the blame falls on actual users not keeping plugins up to date or using one's from dodgy sources.