If you store WP code on Github consider your wp-config.php

Something to think about if you store WordPress code on GitHub

If you store WordPress code on Github inside of a public repository all your code is public. Most people know and accept this, but people either don't realise that their database credentials get stored inside the php file wp-config.php or they do and forget to exclude it from their repository.

This means that if you do a simple Google search for site:github.com master/wp_config.php password blob DB_PASSWORD you will find a whole rake of folk with their passwords on display.

Obviously it is impossible to tell if they are just sample details or real details, but it is still crumby practice and if you do it you really need to stop now.

I will be contacting people I find to let them know, but please pass this message on to any WordPress/GitHub users you know.

Recent posts View all

Productivity

5 ways to speed up your software development

I love feeling like I am speeding through development tasks, here are five things that can help speed up your software development

Accessibility SEO

The main reasons why we shouldn't use click here as link text

There are many reasons why we shouldn't use click here or similar as link text, let's go through them