Dev Branch

EP27 – WordPressing with Abandon(ware)

May 5, 2023

In this episode of WPwatercooler’s Dev Branch, we’ll be joined by Robert Rowley, a Security Expert, to discuss a critical aspect of building sites with WordPress — plugins. Specifically, we’ll delve into the topic of abandoned plugins and the risks that they can pose to website security.

We discuss the issue of abandoned WordPress plugins being used to exploit sites by hackers. We talk about a recent story where hackers were using an abandoned plugin to insert PHP into sites and how it was difficult to find and remove the code. We also discuss the problem of old plugins still being listed in the WordPress repository and how it’s hard to contact the developers of these plugins. We suggest solutions like monitoring spikes in downloads and making it easier for someone to take over an abandoned plugin. We also mention a plugin being tested to test plugin dependencies and adding security contact information to a plugin.

Join us for this important conversation about orphaned WordPress plugins learn and how to keep your website safe from potential security threats.

Links

Panel

Episode Transcription

Speakers:

Show More

Likes, Bookmarks, and Reposts

12 responses to “EP27 – WordPressing with Abandon(ware)”

  1. Jason Tucker Avatar

    @wpwatercooler looking forward to this one!

  2. Jason Tucker Avatar
  3. Ahmed Avatar

    … liked this!

  4. Jason Tucker Avatar

    … reposted this!

  5. Ahmed Avatar

    … reposted this!

  6. SteveRudolfi Avatar

    … reposted this!

  7. Donncha Ó Caoimh Avatar
  8. Jos Velasco Avatar

    … liked this!

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.