Translate to EnglishÜbersetzen Sie zum Deutsch/GermanПереведите к русскому/RussianΜεταφράστε στα ελληνικά/GreekVertaal aan het Nederlands/Dutchترجمة الى العربية/Arabic中文翻译/Chinese Traditional中文翻译/Chinese Simplified한국어에게 번역하십시오/Korean日本語に翻訳しなさい /JapaneseTraduza ao Português/PortugueseTraduca ad Italiano/ItalianTraduisez au Français/FrenchTraduzca al Español/SpanishOversetter til Norsk/Norwegian



Wordpress 2.5.1 Should You Upgrade?
Alvin Phang  
del.icio.us it! | reddit it! | stumble it!

Hi Guys if you have been reading my blog lately, you would have know as I was recently hacked by a group of hackers. It was not a fun thing to be hacked and until now I am not too sure how I got hacked but the interesting part was I was hacked just after I upgraded my Wordpress to 2.5.1 ( which suppose to be more “secure” ). I believe it is more secure and I was hacked due to some loop hole in the server.

Here Are Some Of The New Features Of Wordpress 2.5.1

  • Performance improvements for the Dashboard, Write Post, and Edit Comments pages.
  • Better performance for those who have many categories
  • Media Uploader fixes
  • An upgrade to TinyMCE 3.0.7
  • Widget Administration fixes
  • Various usability improvements
  • Layout fixes for IE

On top of that it fixed over 70 bug fixes in Wordpress to improve it’s “security”. I am now still currently still using 2.2.0 as I got some nightmare after upgrading to 2.5.1, however I do have to warn you if you are thinking of upgrading your Wordpress, there will be plug ins that will not work with the new Wordpress :)

Would I Still Upgrade To Wordpress 2.5.1? Well maybe later on when a new release is to be released I may consider upgrading again :)

If you're new here and like what you read, please subscribe to my blog feed or sign up for free email updates. Thanks for visiting!

RSS feed | Trackback URI

15 Comments »

Comment by Linky Love Subscribed to comments via email
2008-05-12 09:15:45
MyAvatars 0.2

Never fix anything that works :-)

Having said so I am the first to say I hate fancy upgrades, especially when you -the end user- will be the one having to find out that security is a problem on the new upgrade.

My 2.3WP got hacked so my webhost got me up and running again fast and adviced me to upgrade to 2.5.

And like Alvin says: some plugins are no more working on some of my WP2.5 blogs, yet on some other 2.5 blogs, they do… Works on some, doesn’t work on the other…

There is more than just your wordpress version to protect yourself from hacks, so you need to work with your webhost in finding the best safety for your blog.

I mean: if you have your WP well protected but your webhost has a loophole, then all your efforts are useless.
Or if your webhost is well protected but you are running plugins that lack security, you open the gates for problems.

So you need to find a good combination of WP protection and of webhost.

Comment by Su Sheng Loong
2008-05-12 09:55:07
MyAvatars 0.2

In that case, is is better to host our blogs on dedicated server instead of shared web host? Currently I am using a Linux shared web host as dedicated server is pretty expensive. But I am quite concerned about the security of my blog.

Comment by Alvin Phang Subscribed to comments via email
2008-05-12 14:30:06
MyAvatars 0.2

Regardless what type of server you use… it has nothing to do with security as most times different accounts have different IPs..

Most often will have to do with what programs u have install on your server will affect your security

(Comments wont nest below this level)
 
 
 
Comment by Joe
2008-05-12 09:52:47
MyAvatars 0.2

Hey Alvin,

Your theme is incredibly good, this really is the ultimate theme for text-link-ads and a hands-down structure to monetize from own products and affiliate marketing.

If you can invest two minutes with me (and us) regarding autosocialposter.com , I would highly appreciate it. Reason I am asking is because I may have a confusion between the bookmark tools and one of the additional scripts you provide.

Would you recommend autosocialposter.com after acquiring your $47 massive value package?

I mean, great stuff…but would you recommend it?

Joe

 
Comment by stephen Subscribed to comments via email
2008-05-12 13:00:29
MyAvatars 0.2

Which plugins are not working on WP 2.5.1?

Thanks!

Comment by Alvin Phang Subscribed to comments via email
2008-05-12 14:30:41
MyAvatars 0.2

There is simply too many of them.. I cant tell you for sure :)

 
 
Comment by Linky Love Subscribed to comments via email
2008-05-12 16:13:37
MyAvatars 0.2

@Su Sheng Loong

Affordable dedicated servers do exist, but of course that all depends on your earnings :-)

If a hacker hacks pretty deep in a shared web host, all the people sharing that host will be affected. It’s a pain when:
- it happens all the time
- the shared webhost is slow in getting all sites back online.

And it seems that the make money bloggers like us are quite targetted…

You should make sure you do what you can on your side to limit hackers getting in like:
- not making enemies online :twisted:
- use plugins “the big money bloggers” are using, hoping that those are safe. (maybe there are better ways to find out which plugins are safe…)
- reduce interactivity (which unfortunately reduces your ability to know what your visitors really want)

 
Comment by rey
2008-05-13 00:00:54
MyAvatars 0.2

I recently upgraded to 2.5.1 myself. Are you absolutely sure it was due to a vulnerability in the latest version that made you more susceptible to attack?

I’m just concerned that I may have made my blog less secure by upgrading. But I shouldn’t be too concerned since I don’t really have enough traffic to justify being hacked in the first place anyway. :)

Comment by Alvin Phang Subscribed to comments via email
2008-05-13 00:51:06
MyAvatars 0.2

I believe it’s more secure.. just that I was unlucky to be hacked in.. I think it has more to do with the plug ins I used :)

 
 
Comment by zaifulzin Subscribed to comments via email
2008-05-13 02:03:38
MyAvatars 0.2

LOL…just update a couple of minute, hope nothing bad thing happened. How about your blog loading time, is it normal? After upgrading to 2.5, i found that my blog loading more slower then before eventhough ive deactivate all plugin.

 
Comment by Dave Starr Subscribed to comments via email
2008-05-13 07:31:34
MyAvatars 0.2

FWIW I have only upgraded two of my blogs to 2.5.1 … it is a sad comentary on how “upgrades” can make aproduct worse … wish they had left it alone. As Alvin said, the list of things, especially plugins that give proiblems with 2.5.1 are too numerous to mention. I will not chnage any more blogs over unless WordPress has someone who actually blogs use the enw program. I am really surprised at how many bloggers who seem to know what they are doing just made the move abd bever said a word.

Hat’s off tyo Alvin and the very few others who actually tell the truth about 2.5. Does it actually make you more secure? Beats me, the list of “fixes” has never been discussed authoritatively … and every “fix” may induce another problem, so for now I am staying 2.3 … and looking seriously at Drupal and a few other alternatives.

 
Comment by Rick Roberts Subscribed to comments via email
2008-05-14 10:19:52
MyAvatars 0.2

I’ve got one blog that still runs 2.3.1 and I dread ever upgrading it. I have so many tweaks in the theme it will be a nightmare to get it all working again.

 
Comment by Hussein
2008-05-16 16:06:16
MyAvatars 0.2

My blog is running on wordpress 2.5.1 and all of my plugins are working fine.. :D

 
Comment by Raj Subscribed to comments via email
2008-05-16 17:48:44
MyAvatars 0.2

Thanks Guys

I was about to upgrade but after reading the comments and posts here, I will wait.

Thanks once again for all the posts and comments its a real help for us new comers to blogging

Raj

 
Comment by Jimmy Lim Subscribed to comments via email
2008-07-21 01:38:05
MyAvatars 0.2

Those who got use WordPress 2.5 and above, do you have any problems with the Visual Editor?

As described in this forum, http://wordpress.org/support/topic/164990?replies=40.

I unable to resolve this visual editor problem and get irritated by it, I wonder if it happens to WordPress 2.2.0?

 
Name (required)
E-mail (required - never shown publicly)
URI
Subscribe to comments via email
Your Comment (smaller size | larger size)
You may use <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> in your comment.

Subscribe without commenting