Security in Wordpress
I've been working with Wordpress, I work with Drupal, and I wanted to summarize a bit how to deal with Security in Wordpress.
In a nutshell:
- You can trust Wordpress core and need to keep up with updates (do upgrades as frequently as you can)
- You can not trust all plugins, you need check how secure, mature and professional they are
There is no real comparisson, but this is a big difference Wordpress has with Drupal. Drupal's community takes care of the security of core and its modules.
Let's wrap up sharing an interesting (much longer) article on the subject from Smashing Magazine http://www.smashingmagazine.com/2012/10/09/four-malware-infections-wordpress/