> You’re supposed to give your site write access to its code
You do not need to. Its to help people who cannot manage an ssh login update. You can use the cli to update if you can. I am pretty sure big sites will not be doing their updates from the big site.
The problem with plugins is lack of a proper framework. Its very easy to do things like pass user inputs into a query by strong concatenation because you have to make in extra effort to not do so.
That said, its no guarantee. I have seen people do things like call exec on user inputs in Django.
> has careful guidance around avoiding letting uploads be accidentally executable too.
That should be the default, not something you need to take extra care over.
> That should be the default, not something you need to take extra care over.
I agree. That’s one of the problems of PHP’s file-based execution model, and how the likes of Apache and nginx work. Drupal is no paragon of security, but it’s far closer than WordPress. For all its faults, even Node.js avoids this class of problem.
You do not need to. Its to help people who cannot manage an ssh login update. You can use the cli to update if you can. I am pretty sure big sites will not be doing their updates from the big site.
The problem with plugins is lack of a proper framework. Its very easy to do things like pass user inputs into a query by strong concatenation because you have to make in extra effort to not do so.
That said, its no guarantee. I have seen people do things like call exec on user inputs in Django.
> has careful guidance around avoiding letting uploads be accidentally executable too.
That should be the default, not something you need to take extra care over.