Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Otter@lemmy.ca to Technology@lemmy.world – 308 points –
Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
arstechnica.com
51

You are viewing a single comment

Funnily enough, I was hearing this from developers in the early 2010s when I was just starting my career (IT adjacent, but not a developer).

Seriously, people have been saying this stuff about WordPress as long as it’s been around, and I’m always surprised that it still exists. This was definitely one of those technologies that sounded bad enough that it could never last. Joke is on me.

Of course I thought the same with JavaScript but was forced to learn it last year

Of course I thought the same with JavaScript but was forced to learn it last year

Use TypeScript. It's still built on a giant steaming pile of shit but at least if you're careful most of your own code can be reasonably correct.

It’s not my choice. I’m only here to help others fix their code, not to actually do the coding. I have to someone know best practices and how to fix common bugs

That's a shame. If you can convince them to use TypeScript that would be for the best, otherwise good luck, you're going to need it. I can't say you couldn't pay me to write JavaScript, but I can say what I would demand to do it is way more than anyone would be willing to pay.