
<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How can a WordPress plugin be unsafe</title>
	<atom:link href="http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/</link>
	<description>Just writing what hits my mind!</description>
	<lastBuildDate>Thu, 13 Jan 2011 22:34:15 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>By: stratos.me &#187; Blog Archive &#187; Get rid of the Sociable plugins. Do it yourself!</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1260</link>
		<dc:creator>stratos.me &#187; Blog Archive &#187; Get rid of the Sociable plugins. Do it yourself!</dc:creator>
		<pubDate>Mon, 08 Dec 2008 19:26:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1260</guid>
		<description>[...] people to minimize their plugin needs. They are resource hungry and may cause problems due to security issues on your blog. There are those that agree to that but say that on the other hand there are those [...]</description>
		<content:encoded><![CDATA[<p>[...] people to minimize their plugin needs. They are resource hungry and may cause problems due to security issues on your blog. There are those that agree to that but say that on the other hand there are those [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stratosg</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1256</link>
		<dc:creator>stratosg</dc:creator>
		<pubDate>Sun, 07 Dec 2008 12:12:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1256</guid>
		<description>@Velvet Blues: Yah in general if you use the framework instead of going snooping around you will probably never have a problem. In any case one should be very careful when choosing to install a plugin.

@Raju Not a problem man. That&#039;s what we are here for. Discussing a subject ;) I would like to add that i have Microkid&#039;s related posts and it seems to suit fine :)</description>
		<content:encoded><![CDATA[<p>@Velvet Blues: Yah in general if you use the framework instead of going snooping around you will probably never have a problem. In any case one should be very careful when choosing to install a plugin.</p>
<p>@Raju Not a problem man. That&#8217;s what we are here for. Discussing a subject <img src='http://www.stratos.me/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  I would like to add that i have Microkid&#8217;s related posts and it seems to suit fine <img src='http://www.stratos.me/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raju</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1253</link>
		<dc:creator>Raju</dc:creator>
		<pubDate>Sun, 07 Dec 2008 07:29:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1253</guid>
		<description>@Kim,
were u using Yet Another Related Posts plugin? Cos I ran into problems using it. I switched over to Azittos Related Posts plugin which works like a charm!

@Stratos,
Sorry for diverting the topic  :oops:</description>
		<content:encoded><![CDATA[<p>@Kim,<br />
were u using Yet Another Related Posts plugin? Cos I ran into problems using it. I switched over to Azittos Related Posts plugin which works like a charm!</p>
<p>@Stratos,<br />
Sorry for diverting the topic  <img src='http://www.stratos.me/wp-includes/images/smilies/icon_redface.gif' alt=':oops:' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Velvet Blues</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1251</link>
		<dc:creator>Velvet Blues</dc:creator>
		<pubDate>Sun, 07 Dec 2008 03:26:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1251</guid>
		<description>Yeh, the WordPress plugin API, when used correctly, does a good job of preventing attacks. However, I have heard of some plugins, namely those that use AJAX, being problematic. (One of the poll plugins in particular was noted.)

I could imagine that a form submission plugin could be problematic as well, not necessarily for attacking a database, but for doing other equally fun things like deleting files (or creating new files).</description>
		<content:encoded><![CDATA[<p>Yeh, the WordPress plugin API, when used correctly, does a good job of preventing attacks. However, I have heard of some plugins, namely those that use AJAX, being problematic. (One of the poll plugins in particular was noted.)</p>
<p>I could imagine that a form submission plugin could be problematic as well, not necessarily for attacking a database, but for doing other equally fun things like deleting files (or creating new files).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: stratosg</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1235</link>
		<dc:creator>stratosg</dc:creator>
		<pubDate>Wed, 03 Dec 2008 07:40:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1235</guid>
		<description>@Kim Thanks! I haven&#039;t found such a plugin either but there still is a threat that a coder could make a mess big time. As for the related articles i didn&#039;t notice any bottleneck there but then i don&#039;t have that much traffic :D

@Sire Thanks. To be honest no i don&#039;t have any pricing but i think it will depend on the problem at hand. But, pricing should not make my friends hesitate to contact me. If there is a problem we will resolve it and settle it afterwords ;)

@Raju Yah coders are very careful but as i said there is the potential. As for the plugin you said that is actually nasty. If i wanted something like that i would simply ask and i am sure that all the plugin users would do it out of their heart.

Thanks for dropping in guys! I really appreciate your feedback and comments!</description>
		<content:encoded><![CDATA[<p>@Kim Thanks! I haven&#8217;t found such a plugin either but there still is a threat that a coder could make a mess big time. As for the related articles i didn&#8217;t notice any bottleneck there but then i don&#8217;t have that much traffic <img src='http://www.stratos.me/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>@Sire Thanks. To be honest no i don&#8217;t have any pricing but i think it will depend on the problem at hand. But, pricing should not make my friends hesitate to contact me. If there is a problem we will resolve it and settle it afterwords <img src='http://www.stratos.me/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>@Raju Yah coders are very careful but as i said there is the potential. As for the plugin you said that is actually nasty. If i wanted something like that i would simply ask and i am sure that all the plugin users would do it out of their heart.</p>
<p>Thanks for dropping in guys! I really appreciate your feedback and comments!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Raju</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1234</link>
		<dc:creator>Raju</dc:creator>
		<pubDate>Wed, 03 Dec 2008 07:17:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1234</guid>
		<description>I agree with Kim here. There are many plugins which are badly coded. badly coded in a way that it slows down the website and overuse resources. But I haven&#039;t found out any plugin which can cause a potential threat to the website security as such. may be they are harmless ones which goes unnoticed. 
First time I realized the potential threats from a plugin was when I installed a plugin it automatically added its author&#039;s site to my blogroll and footer section and didn&#039;t take them out even after uninstalling  :roll:</description>
		<content:encoded><![CDATA[<p>I agree with Kim here. There are many plugins which are badly coded. badly coded in a way that it slows down the website and overuse resources. But I haven&#8217;t found out any plugin which can cause a potential threat to the website security as such. may be they are harmless ones which goes unnoticed.<br />
First time I realized the potential threats from a plugin was when I installed a plugin it automatically added its author&#8217;s site to my blogroll and footer section and didn&#8217;t take them out even after uninstalling  <img src='http://www.stratos.me/wp-includes/images/smilies/icon_rolleyes.gif' alt=':roll:' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kim Woodbridge &#124; (Anti) Social Development</title>
		<link>http://www.stratos.me/2008/12/how-can-a-wordpress-plugin-be-unsafe/comment-page-1/#comment-1232</link>
		<dc:creator>Kim Woodbridge &#124; (Anti) Social Development</dc:creator>
		<pubDate>Wed, 03 Dec 2008 02:40:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.stratos.me/?p=689#comment-1232</guid>
		<description>I have not hard any plugins cause a security risk but have had them cause a decrease in performance.  I had to remove the Related Posts plugin from my elephant site because it was causing too much CPU usage and my host took down my site until I resolved the problem.  Only from the server logs was I able to tell which plugin was causing the problem.

Great article!</description>
		<content:encoded><![CDATA[<p>I have not hard any plugins cause a security risk but have had them cause a decrease in performance.  I had to remove the Related Posts plugin from my elephant site because it was causing too much CPU usage and my host took down my site until I resolved the problem.  Only from the server logs was I able to tell which plugin was causing the problem.</p>
<p>Great article!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

