WordPress plugin hole puts '2M websites' at risk

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • wp2static

    WordPress static site generator for security, performance and cost benefits

  • > It is not actually that hard to run Wordpress securely. Stick to supported plugins and themes, and install security patches quickly when they are released.

    Depending on your site's functionality, it may also be possible to run a static WP site:

    * https://wordpress.org/plugins/simply-static/

    * https://wp2static.com

    You do all your regular updates via the CMS, but, instead of putting the dynamic site on the public Internet, you generate static files and point your public web server's HTML rootdir at those.

  • wp_d_rymcg

    wp deployment for d.rymcg.tech

  • If you are stuck on wordpress, consider using a static export plugin like wp2static [1]. I have been playing around[2] with a setup where the normal WP UI is protected behind HTTP Basic Authentication, and wp2static exports the public snapshot

    [1] https://github.com/WP2Static/wp2static

    [2] https://github.com/jessopb/wp_d_rymcg

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • snuffleupagus

    Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

  • I wonder if Snuffleupagus can block this exploit.

    https://snuffleupagus.readthedocs.io/

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts