A Web.com Partner

WordPress Security Incident

Whilst alarming to the end-user, so far no user log-in information seems to have been accessed. Keeping in mind this is for WordPress.com users as opposed to those running independently-hosted installations.

In a relievingly transparent post (some may argue, unusual for an internet company), Matt from WordPress posts:

“Automattic had a low-level (root) break-in to several of our servers, and potentially anything on those servers could have been revealed.

We have been diligently reviewing logs and records about the break-in to determine the extent of the information exposed, and re-securing avenues used to gain access. We presume our source code was exposed and copied. While much of our code is Open Source, there are sensitive bits of our and our partners’ code. Beyond that, however, it appears information disclosed was limited.”

Additional information about the WordPress security incident

For additional information, you can check out Matt’s full post/comment thread after the break.

http://en.blog.wordpress.com/2011/04/13/security/

x