Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

11–20 of 210 posts

Re: Secure Custom Fields by WordPress.org

#11

The URL though says "advanced-custom-fields"; Matt...I can't find the words to comment; I just shake my head -_-

If you look at the reviews, they took over the advanced-custom-fields plugin and modified the owner to be Wordpress.org and renamed it to Secure Custom Fields. What a terrible look They also modified it by ripping out the pro features, so if people update their ACF Plugin and they had pro features enabled, it'll just break their install https://plugins.trac.wordpress.org/changeset/3167679/advance...

What a choice, and what poor timing.

Companies that make breaking changes on holiday weekends aren’t going to earn much goodwill from developers.

Re: Secure Custom Fields by WordPress.org

#12

Blog post on wordpress.org concerning this: https://wordpress.org/news/2024/10/secure-custom-fields/

> There is separate, but not directly related news that Jason Bahl has left WP Engine to work for Automattic and will be making WPGraphQL a canonical community plugin. We expect others will follow as well.

Anything to prop up their position and throw the company they are attacking under the bus. What a jerk.

Re: Secure Custom Fields by WordPress.org

#14
OK so:

1) WordPress clearly lacks functionality like ACF that belongs in core

2) Many developers clearly like ACF

3) Many do not (it's messy in the DB, if you ask me)

4) Core functionality that was if not API-compatible, at least API-familiar with ACF would be welcomed by many

5) Creating a new plugin that did this, that was transitioned into core (like other functionality has been), would be a good plan

6) Commandeering the slug for a decade-old commercial plugin like this, to replace it with a fork, is so obviously fucking bad form that it's still hard to believe it is happening even given all the other whatthefuckery that has been happening.

ETA: 7) "Secure Custom Fields"? Really? The difference is what?

What the fuck, Matt?

ETA: personally I understand many of the frustrations with WP Engine's positioning. I have experienced exactly the trademark confusion issues that the lawsuit has been about, where clients have assumed WP Engine is WordPress itself. I don't use them after some iffy customer service and technical issues early on. But this is absurd behaviour.

Re: Secure Custom Fields by WordPress.org

#15

Blog post on wordpress.org concerning this: https://wordpress.org/news/2024/10/secure-custom-fields/

  This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins.
Yeah, that is not how trust works.

Re: Secure Custom Fields by WordPress.org

#19

Blog post on wordpress.org concerning this: https://wordpress.org/news/2024/10/secure-custom-fields/

> This update is as minimal as possible to fix the security issue. What is the actual issue? CVE number?

I think they mean that it's developed by WP Engine and that's the security issue.

Re: Secure Custom Fields by WordPress.org

#20
So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer's plug-in using the developer's own code, ostensibly as retribution for a security issue that the developer had already fixed. https://www.advancedcustomfields.com/blog/acf-6-3-8-security...

What am I missing?

Post reply on HN