Why WordPress don’t implement a basic limit login attempt solution?
-
Hello buddies. I hope nobody get offended, but I have a rant today and I have to leave it out here…
I specialize in providing hosting for WP sites as also in cleaning compromised sites (defacements/phishing/attacks/vulns), and after every job done, I wonder why in the world the WP team haven’t hardened a bit more the security of these overall websites, natively.
I know you continuously release security fixes here and there, and I know that you already put a lot of awesome efforts/time/work/money, but my example point to the basics, with this example: WHY WordPress can’t limit the amount of login attempts? or why XML-RPC couldn’t be inactive by default on new installs? I don’t ask for harder security measures, there are security plugins for that. But there’s still a incredibly big number of website owners with total unawarenes of that. Most hosting services don’t filter the queries, and users mostly install WP via one-click installers that deploy a template. That makes those sites inherently INSECURE.
As a sysadmin, I’m tired of seeing these kind of logs in newbies’ or webdesigners’ accounts:
https://drive.google.com/file/d/0B4ZIdz9VEIQGZ2tmVUpQN2lnX1E/
(and this is just a fragment of a 280 MB log file)
And as vast majority of hosting servers are not actively monitoring these logs until it’s really late, these scans become unnoticeable. But as long as the number of WP sites grows per server, I also see a growing number of hosting companies failing to provide a reliable or stable service.The current state of WordPress, is that is being natively insecure for newbies/webdesigners, and the massification of WP makes it the bot-choice to scan for. You are happy that nearly 30% of Internet is running WordPress. I’m too, really, it’s just great, as it guarantees I will have unlimited sources of jobs. But I’m also sad because that 30% of internet could become rickety in some point.
I collaborate in several groups and forums and I see a lot of new users completely unaware of the security basics (they ever “don’t believe on bots” as if they were urban myths), and another lot of power users who think they know how to secure WordPress, but are doing pretty useless efforts and get their sites compromised, too. There’s a very small number of people with real awareness taking good security measures. And I should speak for all of them, I only can say: PLEASE HELP! Help the newbies to have a secure WP from the very first minute it’s installed, and by doing that you will help the experts too, as we cannot be omnipresent to fight the daily threats.
IMHO, you need to consider these facts and discuss solutions with a higher priority and take more actions to secure WordPress since the very first minute it’s just installed. Then, and only then, Internet will be a place a bit more secure.
Do you have any topics where it is discussed or starting to be analyzed? I’ll be more than pleased to collaborate and help in securing WP.
- The topic ‘Why WordPress don’t implement a basic limit login attempt solution?’ is closed to new replies.