Daily Tip: WP-phpmyadmin Plugin Poses a Huge Security Risk
June 28, 2011
Big surprise, right? Why in the world anybody would be using a plugin called WP-phpmyadmin is beyond me, but reports are our that many sites are being hacked through it. Formerly housed at wordpress.org/extend/plugins/wp-phpmyadmin/, this plugin has already been pulled from the WordPress repository. If for some reason you’re using this plugin, delete it now.
Today our tip is this; do not install plugins that expose server information. If you absolutely have to use a plugin like this for a quick one time task, (really I can’t imagine why this would be necessary), make sure to delete it once you’re finished.
Because this plugin/widget is provided free of charge, I simply ask you to link back to Pressography.com in a post on your blog, or from one of your sites. It doesn't need to be anything fancy - just a note saying that you're using it, and whether or not you like it. However, there is no requirement that you do this, you're free to use the plugin regardless.



Comments
Got something to say?