Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

21–30 of 210 posts

Re: Secure Custom Fields by WordPress.org

#23
> This update is as minimal as possible to fix the security issue.

> This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins.

So.. is this fixing a security issue.. or is this because of WP Engine?

> and are forking Advanced Custom Fields (ACF) into a new plugin

And stealing their place in the plugin store. A fork generally implies that you are going to set off on your own, and not inhabit the dead flesh of the project you just killed.

Matt Mullenweg is the biggest child I have ever seen in operation.

Re: Secure Custom Fields by WordPress.org

#24

If anyone from Automattic is reading this and would like to confidentially leak any internal information about this behaviour from Matt, please email admin@bullenweg.com and I will publish it on bullenweg.com.

This is excellent!

Is there a repo of this website?

It would be good to have for preservation purposes.

Re: Secure Custom Fields by WordPress.org

#25
Pathetic. Matt banned one of the most popular WordPress plugins. Then, he forked the code and hosted it on WP.org, which is against the Terms of Service. He also hosted it in the plugin directory on the same path as ACF, stealing its SEO traffic. Wow!

Matt's state of mind is clearly not good. If I were an investor in WordPress, I would start thinking about cutting my losses. WordPress will not recover from this self-inflicted destruction

*Update* Oh, it's worse than that. He just renamed the ACF to SCF and claimed all the installations and reviews from ACF. I still can't believe this happened. This can't be legal!

Re: Secure Custom Fields by WordPress.org

#26

> This update is as minimal as possible to fix the security issue. > This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins. So.. is this fixing a security issue.. or is this because of WP Engine? > and are forking Advanced Custom Fields (ACF) into a new plugin And stealing their place in the plugin store. A fork generally implies that you a…

> So.. is this fixing a security issue.. or is this because of WP Engine?

It's fixing a security issue WP Engine cannot fix because they are banned from wordpress.org.

Re: Secure Custom Fields by WordPress.org

#27

Blog post on wordpress.org concerning this: https://wordpress.org/news/2024/10/secure-custom-fields/

> This update is as minimal as possible to fix the security issue. What is the actual issue? CVE number?

Details haven't been made public yet: https://www.cve.org/CVERecord?id=CVE-2024-9529

Though, Automattic posted publicly that there was a vulnerability shortly after filing the CVE, while simultaneously blocking WPEngine from being able to push a fix to it because they'd cut off access to wp.org

Re: Secure Custom Fields by WordPress.org

#28
I can't even follow what's going on here, and I used to be an expert in software licensing drama. All I see is a bunch of unilateral actions driven by Matt Mullenweg that breaks so many implicit promises of how a free software steward should behave.

Wordpress sites quite often seen to be a hodge-podge of plugins, each with their own UI and conventions, and (as a host) I'm never an expert in anye one of them. Has one of the site designers used a plugin that has offended Matt? Or that might offend him in the near future? How do I even audit for that?

I don't need much of a push to move my position on this. Before: "eh, use Wordpress if it's cheaper" Now: "please don't, that decision will probably cost me".

Re: Secure Custom Fields by WordPress.org

#29

> This update is as minimal as possible to fix the security issue. > This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins. So.. is this fixing a security issue.. or is this because of WP Engine? > and are forking Advanced Custom Fields (ACF) into a new plugin And stealing their place in the plugin store. A fork generally implies that you a…

> So.. is this fixing a security issue.. or is this because of WP Engine? It's fixing a security issue WP Engine cannot fix because they are banned from wordpress.org.

*Has fixed, but can't post the fixed version to wordpress.org, to be clear

Re: Secure Custom Fields by WordPress.org

#30

OK so: 1) WordPress clearly lacks functionality like ACF that belongs in core 2) Many developers clearly like ACF 3) Many do not (it's messy in the DB, if you ask me) 4) Core functionality that was if not API-compatible, at least API-familiar with ACF would be welcomed by many 5) Creating a new plugin that did this, that was transitioned into core (like other functionality has been), would be a good plan 6) Commandee…

The fucked thing is that per the article, they're not even dedicating any resources to maintain it going forward, they've just made this one fix and are throwing it to other people to maintain if they want:

> Going forward, Secure Custom Fields is now a non-commercial plugin, and if any developers want to get involved in maintaining and improving it, please get in touch.

Post reply on HN