In the same week that we learned from W3Techs that the popular open source content management system (CMS) WordPress now powers a full 25 percent of all sites on the web, we learn that six popular WordPress plugins contain serious security vulnerabilities. The later news comes to us by way of security firm Wordfence, which specializes in WordPress security and develops the Wordfence security plugin for the platform.
This news isn’t surprising, nor is it cause for alarm. Because WordPress is by far the most popular content management platform on the web, it’s an obvious target for hackers, and third party plugins are the most obvious way inside. However, the folks at Automattic, which develops the platform, have proven themselves to be diligent at finding vulnerabilities and keeping them patched.
Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux



Although some have been trying to sound the alarm, many of us have been lulled into complacency brought by a belief that Microsoft is no longer a real threat and that we are now free to concentrate all of our energies on growing Linux and FOSS, which is basically all we’ve wanted to do.
A popular web based application for administering MySQL databases, phpMyAdmin is the preferred tool of many webmasters for working with MySQL when used to power websites and is installed by default with most web hosting packages. The app can be used to perform a variety of tasks, including creating, modifying or deleting databases, tables, fields or rows; executing SQL statements; and managing users and permissions.
Newer converts to open source probably don’t know much about the site, but it wasn’t long ago when Linux users were very aware of SourceForge and how to use the service, at least well enough to download software — perhaps more aware than they wanted to be. It was the go-to site when looking for a program not available in a particular distro’s repository. Not anymore. Not for a while. These days, the more important projects have either migrated to GitHub or are hosting their own.

Nope. I’m an advocate of free “as in speech” software — which includes the freedom to choose. If there’s a FOSS solution for something I need or want to do, I’ll take that every time, and encourage my friends to do so as well. However, if there’s something I need or want to do with no FOSS solution available, I might use a proprietary solution, depending on the depth of my need or want and on how draconian the terms of the proprietary EULA.
