Business owner here, not a technologist. The setup I want is for our SSO to accommodate a Wordpress learning site hosted at WP Engine with a custom PHP app hosted elsewhere (Vultr).
I was able to get this setup configured and functional, but a technology advisor is telling me that such a dual-server arrangement opens up “massive security vulnerabilities.”
Can I get some insights / thoughts on this from those more knowledgeable than I about these matters?
Many thanks in advance for any help!
Russell