hallo u guten Tag liebe Wordpress-Community,
was ist wenn man auf einem Server ist, der sehr vorsichtig gemanaged wird - Sind denn die automaitischen Updates sehr sicher: Sind die hierfür noetigen Vorbedingungen für den Server wirklich sicher!?
Habe einen Artikel gefunden der das u.a.. auch kritisch beleuchtet:
Automatic WordPress Updates Using FTP/FTPS or SSH
https://www.serverstack.com/blog/2013/02/1…ftpftps-or-ssh/
When working with WordPress in a more secure environment where websites are not entirely world-writable, you will notice upgrades request FTP or FTPS credentials as the server itself does not typically have write access in properly-configured environments. Entering these credentials for every upgrade can become quite tedious, and WordPress has implemented some constants you can define within wp-config.php to make upgrades automatic.
It should be noted here that you can also make upgrades automatic by setting the file ownership of all files within the WordPress directory to the same user/group under which the webserver is running. THIS IS HORRIBLE SECURITY PRACTICE!
While storing your FTP credentials for a specific user can also be considered insecure in certain instances, it can be a very safe method to automate WordPress updates under the proper conditions. Some general considerations which can make stored credentials MUCH more secure include:
hier mehr: https://www.serverstack.com/blog/2013/02/1…ftpftps-or-ssh/
Die Frage ist: sind denn die Bediungungen die wir für den automatischen Prozess brauchen wirlich sicher!? Oder anders gefragt; was koennen wir tun, damit diese Basisvoraussetzungen die der Server braucht - für die automatisierten Wordpressupdates - wirklich sicher sind.!?
Freu mich von Euch zu hoeren.
:shock: