7.0.2 got released on Friday. Exploits are already happening. People reporting hacks
CausticFlames@sopuli.xyzEnglish
2 daysFriendly reminder to anyone who cares enough that you can still use WordPress to make your site with all your fancy plugins and layouts, and then export that to a static site for hosting. No need to actually host Wordpress itself that way you avoid nearly all of this BS.
CausticFlames@sopuli.xyzEnglish
2 daysSimply Static is currently the most actively maintained solution, as a plugin for wp:
https://docs.simplystatic.com/category/6-user-guidesThere is also WP2Static, which is a very long standing project: https://github.com/elementor/wp2static
yuman@programming.devEnglish
1 daythis thing here. I’ve dramatically reduced support work at two shops I’ve set this up for. incidents went from from coupla times a month to once a year. not to mention - you don’t need no VPS no more, don’t need no database, nothing, the simplest web hosting will do and it’s very cache friendly.
- 9point6@lemmy.worldEnglish2 days
https://www.wordfence.com/threat-intel/vulnerabilities
The CVE list always cracks me up, there’s like tens daily
- SreudianFlip@sh.itjust.worksEnglish2 days
Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?
- Marthirial@lemmy.worldEnglish2 days
I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.
Mediocre craftspeople blame their tools.
- kungen@feddit.nuEnglish2 days
I’ve driven a poorly designed car without many safety features for years, and I’ve never flown through the windshield, ever.
loo@lemmy.worldEnglish
2 daysGlad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending






