[ad_1]
0. 99,9% of security issues are due to bots exploiting vulnerable plugins.
Solution:
1. If the developer marks the release as a security update the update would be automatically applied.
2. Some hosts already apply automatic wordpress core updates when it’s a security release, this should be done for plugins.
What am I not seeing? Why isn’t this implemented? We have wordpress plugin auto updates but no one responsible uses those on all plugins.
[ad_2]
Plugins can be automatically updated and for some managed hosting, is by default.
Security fixes, like any update, are liable to break a site.
The problem is that the WordPress Plugin versioning system doesn’t differentiate between security and functional updates. It’s annoying.