WordPress - Any hacking issues ?

Discussion in 'WordPress' started by Suri.CMS, Dec 10, 2008.

  1. #1
    Hi All,
    I am planning to use WORDPRESS for a very huge website.(Lets say - 1,00,000 pages)

    I would like to know if WordPress is more prone to hacking issues.

    If you are using WordPress, can you please update me with the security issues you faced off-the-late.

    Also if you are a BIG site (using WordPress & having thousands of posts) owner, please advise on whether I should go ahead using WordPress for a huge site ? Will there be any performance problems or related problems ?
     
    Suri.CMS, Dec 10, 2008 IP
  2. cormac

    cormac Peon

    Messages:
    3,662
    Likes Received:
    222
    Best Answers:
    0
    Trophy Points:
    0
    #2
    WordPress offers lots of updates as soon as they spot a vulnerability and fix it. As long as you adhere to typical security configurations and update WP when they are released you should be ok.

    WP can be used for any size of site though if you don't have things configured right you could experience lag. For a site your size I'd assume you are planning to use a dedicated server?
     
    cormac, Dec 10, 2008 IP
  3. Suri.CMS

    Suri.CMS Peon

    Messages:
    432
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Yes ! Starting with VPS and then to a dedicated server.
     
    Suri.CMS, Dec 10, 2008 IP
  4. cormac

    cormac Peon

    Messages:
    3,662
    Likes Received:
    222
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Thats good. Would be a crazy idea to run such a big site on a shared account.
     
    cormac, Dec 10, 2008 IP
  5. lvtim

    lvtim Well-Known Member

    Messages:
    291
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #5
    I've had no problem with WordPress hacking, but I've seen a few sites that got hacked simply because they were not upgraded to the latest version. WordPress is a pretty solid platform as long as you keep up with the updates. CNN and Wall Street Journal are just two of the big shots running their sites on WP.
     
    lvtim, Dec 10, 2008 IP
  6. deepblue

    deepblue Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #6
    Yes you need to keep a track on software upgradation. Since WP is very popular it gets much more attention of hackers than required.

    WSJ and CNN blogs are on WP not the whole site.
     
    deepblue, Dec 11, 2008 IP
  7. lvtim

    lvtim Well-Known Member

    Messages:
    291
    Likes Received:
    8
    Best Answers:
    0
    Trophy Points:
    130
    #7
    The fact that these two are *not* using other blogging platforms should tell us something about WP's technical worthiness when set up properly. No CMS is totally secure, unless God himself created one.

    WP is close to godliness.

    Let me add this -- so far my experience in cleaning up a hacked WordPress site has been relatively easy as long as you have your database backed up regularly. Most of the time they were not done to deface the site, but rather creating illegal backlinks to the hacker's site. I've seen worse things happen to Joomla and Mambo where script injections are concerned, those things were totally transformed.
     
    lvtim, Dec 11, 2008 IP
  8. campolar

    campolar Peon

    Messages:
    2,683
    Likes Received:
    244
    Best Answers:
    0
    Trophy Points:
    0
    #8
    campolar, Dec 11, 2008 IP
  9. einsteinsboi

    einsteinsboi Well-Known Member

    Messages:
    1,122
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    140
    #9
    You have to really really be diligent with the upgrades whenever they come out, which is so bloody often that I am now slowly migrating all my sites to Drupal. I have had websites that I upgraded to the latest WP version and still got hacked, and only the WP sites on the server got hacked! For such a big site as you're planning I would be tempted to go with something besides WP, but at the end it's all a matter of your personal preference.
     
    einsteinsboi, Dec 11, 2008 IP
  10. Suri.CMS

    Suri.CMS Peon

    Messages:
    432
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #10
    But from where are you getting templates (themes) for Drupal ?
    I did not find even one outstanding template so far for Drupal.
     
    Suri.CMS, Dec 11, 2008 IP
  11. einsteinsboi

    einsteinsboi Well-Known Member

    Messages:
    1,122
    Likes Received:
    76
    Best Answers:
    0
    Trophy Points:
    140
    #11
    Well, this seems to be the biggest gripe against Drupal, that it doesn't have many themes. I tend to disagree. My top places for themes are the drupal website http://drupal.org, http://www.roopletheme.com/, and http://themegarden.org.

    If I don't find a theme I like, I have two approaches: Either I take one of the themes from these websites and modify them to my needs by playing with the css, or I create my own themes, either porting them into Drupal or creating them from scratch. Starting from the Zen theme it is easy to create your own theme.

    Ofcourse you can pay someone to create the theme for you also.

    I think Drupal is well worth the effort, for the power, functionality and stability I get I don't mind going the extra mile for the theme
     
    einsteinsboi, Dec 11, 2008 IP
  12. Suri.CMS

    Suri.CMS Peon

    Messages:
    432
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #12
    Even I was more interested in Drupal only.

    But then, I heard an issue.

    Drupal can support high number of guest visitors. However, if more members login, then there is no performance optimization and so it may run the server down due to heavy load.

    I don't know it's true or not. But I got this feedback from a Drupal user.

    I was trying to create a user community. So I had to think twice, because I may have 1000 members logging in at same time.

    Also I was interested to use vBulletin as forum instead of Drupal's below-par forum. I thought integration of Drupal & vBulletin is a tricky one (I know there are some solutions like vBdrupal, but I don't like them).
     
    Suri.CMS, Dec 11, 2008 IP
  13. deepblue

    deepblue Peon

    Messages:
    47
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #13
    what exactly you mean by integrating drupal with vulletin?

    why dont you think of WPMU and BBpress?
     
    deepblue, Dec 11, 2008 IP
  14. Principe

    Principe Peon

    Messages:
    11
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #14
    I'm using WordPress for a long time but I never had a hacking issue yet.
    WordPress has just problem with CPU Usage. If you have more than 100.000 pages,
    I don't suggest you VPS, go and start with a Dedicated Server.
     
    Principe, Dec 13, 2008 IP
  15. Suri.CMS

    Suri.CMS Peon

    Messages:
    432
    Likes Received:
    5
    Best Answers:
    0
    Trophy Points:
    0
    #15
    Members should not be registering twice. This is the main one.

    When I checked out WPMU last time, I heard it was too buggy to use. I am not sure if the situation has changed now.
     
    Suri.CMS, Dec 14, 2008 IP
  16. Jalpari

    Jalpari Notable Member

    Messages:
    5,640
    Likes Received:
    137
    Best Answers:
    0
    Trophy Points:
    260
    #16
    iN the begining i was facing spam comments but now it has be solved by using plugin akismet. Hve strong password so no one can hack ur blog. and change on frequent base
     
    Jalpari, Dec 14, 2008 IP
  17. ReneK

    ReneK Active Member

    Messages:
    24
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    88
    #17
    use a different username and delete the admin one... and use a different prefix for your db can also help.. you can also use the WordPress Exploit Scanner plugin
     
    ReneK, Dec 16, 2008 IP
  18. wizgo

    wizgo Greenhorn

    Messages:
    26
    Likes Received:
    1
    Best Answers:
    0
    Trophy Points:
    15
    #18
    I have heard of site getting hack, but I have never had a problem. I love Wordpress
     
    wizgo, Dec 17, 2008 IP