Wordpress security issues - inviting the hackers in and brewing them a tea

If like me you think Wordpress is a great cms you’ve probably installed several templates and plugins. But do you know what exactly it is you are installing?

Chances are unless you are a PHP programmer you won’t have given this a second thought.

So what is it you are installing?
Wordpress  plugins and some templates contain code that performs a particular task.  Some of my favourite plugins are listed here

So what’s the security issue?
Those plugins and templates could be malicious!

Most of us take precautions when downloading programs and files on to our desktops, but happily install plungins and templates on servers without giving it a second thought.  So now you have your nice new shiny template installed, but what else is it doing? Possibilities are endless, you could be opening your server up for sending out spam,  or leaving your company server open to attack.

In the last few week alone I’ve seen..

  • templates email that send out emails when installed
  • plugins inserting hidden links in all your posts
  • mystery encoded php in templates
  • plugins that install extra php files from remote servers

So what can you do?
Until there is a online system where plugins and templates are checked for security holes, and we’re able to download them from a verified source, all we can do is be very careful.. Before installing look through those template and plugin files, and check for suspicious code.

Share this article:
  • del.icio.us
  • Digg
  • Furl
  • NewsVine
  • Reddit
  • Slashdot
  • StumbleUpon
  • Technorati

Recent Posts

  • The Vouch’ers

    May 21st, 2009 No this isn't  another plug for one of DougS voucher code sites, but the band The Vouch. Three of the five band
  • Tracking search trends, rising keywords and phrases.

    May 16th, 2009 If you need to keep an eye on what's hot, and spot breaking stories there aren't many great tools around. In the end i
  • Wordpress plugin update

    May 16th, 2009   Finally! Upgraded to WordPress 2.7.1, what’s the bet the next release comes out in a day or 2. So while upgradin
  • Long time no post

    May 4th, 2009 Time for my annual update :) Never made it to OZ, was supposed to go there for a month or 2 on business but better t
  • Upgrade WordPress or kiss good bye to your rankings

    October 27th, 2008 Running an old version of WordPress? Then you Google rankings are at risk! Old versions of WordPress have plenty of