<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Wordpress plugin security</title>
	<atom:link href="http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/</link>
	<description>A tool for designers dealing with programmers dealing with designers...</description>
	<pubDate>Thu, 11 Mar 2010 17:57:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Blogshop</title>
		<link>http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/#comment-1362</link>
		<dc:creator>Blogshop</dc:creator>
		<pubDate>Sun, 16 Nov 2008 10:33:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=255#comment-1362</guid>
		<description>Whoops, didnt realize you meant the read me files FAQ&#38; never mind. Thanks, keep up the great work.</description>
		<content:encoded><![CDATA[<p>Whoops, didnt realize you meant the read me files FAQ&amp; never mind. Thanks, keep up the great work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Log0</title>
		<link>http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/#comment-1347</link>
		<dc:creator>Log0</dc:creator>
		<pubDate>Sat, 01 Nov 2008 08:22:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=255#comment-1347</guid>
		<description>Worse, the user submitted plugin is stored publicly accessible, and is never checked. It's just about the user's trust to your plugin... and if they believe you can't be possibly harmful... 

you get it.</description>
		<content:encoded><![CDATA[<p>Worse, the user submitted plugin is stored publicly accessible, and is never checked. It&#8217;s just about the user&#8217;s trust to your plugin&#8230; and if they believe you can&#8217;t be possibly harmful&#8230; </p>
<p>you get it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gareth Heyes</title>
		<link>http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/#comment-1340</link>
		<dc:creator>Gareth Heyes</dc:creator>
		<pubDate>Fri, 24 Oct 2008 07:56:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=255#comment-1340</guid>
		<description>Well I'm referring to the official Wordpress plugin page as I see that as their responsibility but really all plugin sites should provide some sort of security review or at least some automatation security testing.</description>
		<content:encoded><![CDATA[<p>Well I&#8217;m referring to the official Wordpress plugin page as I see that as their responsibility but really all plugin sites should provide some sort of security review or at least some automatation security testing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacob Santos</title>
		<link>http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/#comment-1339</link>
		<dc:creator>Jacob Santos</dc:creator>
		<pubDate>Thu, 23 Oct 2008 22:50:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=255#comment-1339</guid>
		<description>Do you mean the Plugins Extend on the wordpress.org site or just out in the open on any site? There are some plugin release review, but how extensive they are is unknown.</description>
		<content:encoded><![CDATA[<p>Do you mean the Plugins Extend on the wordpress.org site or just out in the open on any site? There are some plugin release review, but how extensive they are is unknown.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Willbanks</title>
		<link>http://www.thespanner.co.uk/2008/10/22/wordpress-plugin-security/#comment-1338</link>
		<dc:creator>Mike Willbanks</dc:creator>
		<pubDate>Wed, 22 Oct 2008 20:44:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.thespanner.co.uk/?p=255#comment-1338</guid>
		<description>I agree fully.  Wordpress is one of those software packages that is almost too easy to not use it but yet the way they allow the plugins to be released is quite pitiful and their architecture is simply disgusting.

There are easy solutions around this, something even as simple as having an official review process (could cost money even) to stamp it as an approved plugin.

Secondly have a simple vulnerability scanner to look for common pitfalls as you speak.

Lastly, there should really be something attached to it.  You get these people that think they can write PHP that just installed wordpress and write a plugin they are not focused on security or even know what it is.  All they think is, hmm, how do I get this to work - aka happy path testing.</description>
		<content:encoded><![CDATA[<p>I agree fully.  Wordpress is one of those software packages that is almost too easy to not use it but yet the way they allow the plugins to be released is quite pitiful and their architecture is simply disgusting.</p>
<p>There are easy solutions around this, something even as simple as having an official review process (could cost money even) to stamp it as an approved plugin.</p>
<p>Secondly have a simple vulnerability scanner to look for common pitfalls as you speak.</p>
<p>Lastly, there should really be something attached to it.  You get these people that think they can write PHP that just installed wordpress and write a plugin they are not focused on security or even know what it is.  All they think is, hmm, how do I get this to work - aka happy path testing.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
