Over 90 WordPress themes, plugins backdoored in supply chain attack

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • SonarLint - Clean code begins in your IDE with SonarLint
  • ONLYOFFICE ONLYOFFICE Docs — document collaboration in your environment
  • InfluxDB - Access the most powerful time series database as a service
  • Ghost

    Turn your audience into a business. Publishing, memberships, subscriptions and newsletters.

    The CMS space is incredibly crowded. The vast majority of WordPress websites would be cheaper, faster, and more secure if they were just moved to SquareSpace, which has the WordPress features that 99% of sites would need.

    For more custom projects, I prefer the headless variety[1] because it makes sense to separate the data and presentation layers. That means you have the full ecosystem and flexibility of HTML/CSS/JS.

    Ghost[2] was the first serious competitor I saw years ago. Gatsby is among the most popular these days[3].

    But honestly, information sites should just use SquareSpace or something like it. There's no reason to maintain static site infrastructure at this point.

    1. https://jamstack.org/

    2. https://ghost.org/

    3. https://www.gatsbyjs.com/

  • utterances

    :crystal_ball: A lightweight comments widget built on GitHub issues

  • SonarLint

    Clean code begins in your IDE with SonarLint. Up your coding game and discover issues early. SonarLint is a free plugin that helps you find & fix bugs and security issues from the moment you start writing code. Install from your favorite IDE marketplace today.

  • Publii

    The most intuitive Static Site CMS designed for SEO-optimized and privacy-focused websites.

  • ProcessWire

    Our repository has moved to https://github.com/processwire – please head there for the latest version. (by ryancramerdesign)

  • wp2static

    WordPress static site generator for security, performance and cost benefits

  • Wagtail

    A Django content management system focused on flexibility and user experience

  • Gatsby

    The fastest frontend for the headless web. Build modern websites with React.

    The CMS space is incredibly crowded. The vast majority of WordPress websites would be cheaper, faster, and more secure if they were just moved to SquareSpace, which has the WordPress features that 99% of sites would need.

    For more custom projects, I prefer the headless variety[1] because it makes sense to separate the data and presentation layers. That means you have the full ecosystem and flexibility of HTML/CSS/JS.

    Ghost[2] was the first serious competitor I saw years ago. Gatsby is among the most popular these days[3].

    But honestly, information sites should just use SquareSpace or something like it. There's no reason to maintain static site infrastructure at this point.

    1. https://jamstack.org/

    2. https://ghost.org/

    3. https://www.gatsbyjs.com/

  • ONLYOFFICE

    ONLYOFFICE Docs — document collaboration in your environment. Powerful document editing and collaboration in your app or environment. Ultimate security, API and 30+ ready connectors, SaaS or on-premises

  • jamstack.org

    The official Jamstack site

    The CMS space is incredibly crowded. The vast majority of WordPress websites would be cheaper, faster, and more secure if they were just moved to SquareSpace, which has the WordPress features that 99% of sites would need.

    For more custom projects, I prefer the headless variety[1] because it makes sense to separate the data and presentation layers. That means you have the full ecosystem and flexibility of HTML/CSS/JS.

    Ghost[2] was the first serious competitor I saw years ago. Gatsby is among the most popular these days[3].

    But honestly, information sites should just use SquareSpace or something like it. There's no reason to maintain static site infrastructure at this point.

    1. https://jamstack.org/

    2. https://ghost.org/

    3. https://www.gatsbyjs.com/

  • bedrock

    WordPress boilerplate with Composer, easier configuration, and an improved folder structure

    If you professionally build a WordPress site, please consider turning off the native plugin and theme management, and replace it with composer and files non-writable to PHP.

    https://roots.io/bedrock/ is a neat boilerplate for how this can be done.

  • Grav

    Modern, Crazy Fast, Ridiculously Easy and Amazingly Powerful Flat-File CMS powered by PHP, Markdown, Twig, and Symfony

    If you're not completely against markdown, I particularly like Grav (https://getgrav.org) combined with the optional Admin plugin. Very quick and easy installation; I don't need to keep detailed notes on getting the exact packages loaded to make it work.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts