• [^] # Re: Oulà

    Posté par (site web personnel, Mastodon) . En réponse au message Bonnes pratiques pour un site web ?. Évalué à 4.

    Je ne pensais pas que WP avait si mauvaise...press.

    C'est objectivement une passoire ce truc. Je vais cependant essayer de détailler un peu avec les premiers liens sur lesquels je tombe appuyant ma pensée.


    CMS critic, comparant Wordpress/Drupal/Joomla en 2017 concluait

    According to CVE data, if you compare market share to incident rate, Drupal comes out with the least number of incidents to market-share ratio and since 2005, Joomla has had the most amount of found vulnerabilities, with 327.
    [...]
    Overall, Drupal offers the system with the most focus on security and the dedicated team of volunteers have done well to keep vulnerabilities statistics low in recent times. Whereas, Joomla offers the least amount of security based on statistics and the least amount of people working for their in-house security team. With the popularity that comes with WordPress it’s almost impossible to create a wholly secure environment, but with careful planning and cautious use of plug-ins it’s possible to increase security to a suitable level.

    Concernant justement les extensions, qui sont quasiment nécessaire (je doute que tu arrives à avoir quelque chose sans devoir en installer)

    The major security vulnerability with WordPress, and most CMS, is the entry points created using third party plug-ins and extensions, which make up 56% of known vulnerabilities in WP. Overall, the security is at the level it needs to be to protect such a vast number of sites, and security suggestions are updated frequently by the maintenance team to guide users on the best security practices.

    D'après Get Astra en fin décembre 2020, le classement n'a pas vraiment changé mais on attire l'attention sur les XSS

    46% of the vulnerabilities found in Drupal were cross site scripting – XSS. XSS is a code injection attack wherein an attacker injects malicious scripts into websites to gain unauthorized access. Cross site scripting has also been a major vulnerability in WordPress with roughly 39% vulnerabilities caused due to XSS. Joomla’s 15% vulnerabilities were XSS too.

    Attention qu'une lecture rapide (juste les pourcentages) peut laisser croire que WP est mieux que les autres, mais il faut ramener aux parts de marché (et on se rend compte que WP est la principal source des sites non sécures...)

    nom cms % marché
    WordPress 59.7
    Joomla 06.7
    Drupal 04.7
    Magento 02.3

    Mieux, malgré les améliorations de version en version, 70% des sites WP sont vulnérables à une attaque

    type CVE % 2014-2019
    XSS 35.5
    code execution 14.3
    bypass something 11.8
    gain information 11.8
    SQLi 08.4

    Mais comme tu as posé la question, Get Astra a listé toute les bonnes pratiques à adopter avec WordPress auxquelles je rajouterai de ne pas installer de plugin...

    "It is seldom that liberty of any kind is lost all at once." ― David Hume