  1. Felipe LavĂ­n


    Here's an idea: let's have a secure and fast CMS, that's not filled with hundreds of features we'll neve use...

    Get a security audit of the code and review how are things done right now and improve them before adding more stuff.

    Posted: 10 years ago #
  2. Jeff Chandler

    I've been a fan of the security audit idea since 2007 but it has yet to occur. Perhaps it's because of cost but I think it's because the notion of hundreds of people looking through the code all the time is equal to an ongoing security audit.

    Still, I think it would be refreshing just to see a professional security firm go through WordPress line by line and then see the published report. I bet the results would surprise a lot of people.

    Posted: 8 years ago #
  3. Jen
    Key Master

    Mark Jaquith, lead developer, is a paid professional who does WordPress security audits for clients. If someone from a security firm wants to volunteer like Mark does, and write a report, fine. However, I would not want Mark to take time away from coding to write a report on something that would be outdated almost immediately.

    Posted: 8 years ago #

