Live data from Hacker News

Secure Custom Fields by WordPress.org

wordpress.org

101–110 of 210 posts

Re: Secure Custom Fields by WordPress.org

#101

Wordpress banned forks from the plugin directory a while ago, so they're doing what they ban everyone else from doing. https://make.wordpress.org/plugins/2021/02/16/reminder-forke...

ACF isn’t a premium plugin (linked post only concerns those). The linked post also might not reflect the current policies. This update was a security update and was done due to the unique circumstances around the original publisher.

Exactly. ACF is free and open source. ACF Pro is not. Secure Custom Fields is based on the free version (ACF, without "Pro").

Re: Secure Custom Fields by WordPress.org

#102

The URL though says "advanced-custom-fields"; Matt...I can't find the words to comment; I just shake my head -_-

If you look at the reviews, they took over the advanced-custom-fields plugin and modified the owner to be Wordpress.org and renamed it to Secure Custom Fields. What a terrible look They also modified it by ripping out the pro features, so if people update their ACF Plugin and they had pro features enabled, it'll just break their install https://plugins.trac.wordpress.org/changeset/3167679/advance...

AFAIK the free version never included “pro features” in the first place

Re: Secure Custom Fields by WordPress.org

#103

Blog post on wordpress.org concerning this: https://wordpress.org/news/2024/10/secure-custom-fields/

> There is separate, but not directly related news that Jason Bahl has left WP Engine to work for Automattic and will be making WPGraphQL a canonical community plugin. We expect others will follow as well. Anything to prop up their position and throw the company they are attacking under the bus. What a jerk.

Which, by the way, previously ended with "We expect others will defect as well." before the post was edited

Re: Secure Custom Fields by WordPress.org

#104

Earlier quoted context omitted.

What a choice, and what poor timing. Companies that make breaking changes on holiday weekends aren’t going to earn much goodwill from developers.

Nothing has broken. Perhaps WP Engine should have consider that before suing us.

[flagged]

Re: Secure Custom Fields by WordPress.org

#105
post #74

Earlier quoted context omitted.

Can anyone else prove this security vulnerability actually existed?

It doesn't matter. Matt didn't have the right to hijack ACF.

I'm not on Matt's side, but anyone has the right to fork a GPL project and call it something else.

Re: Secure Custom Fields by WordPress.org

#106

> This update is as minimal as possible to fix the security issue. > This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins. So.. is this fixing a security issue.. or is this because of WP Engine? > and are forking Advanced Custom Fields (ACF) into a new plugin And stealing their place in the plugin store. A fork generally implies that you a…

> So.. is this fixing a security issue.. or is this because of WP Engine?

AFAIK, here's the timeline.

1. Automattic announced that there was a security issue in ACF.

2. WP Engine fixes it immediately.

3. Automattic bans the WP Engine developers from Wordpress.org, so they can't deploy the fix. This places millions of users at risk, but that's how they roll.

4. Automattic forks ACF, removes the commercial upgrade, and renames it.

Re: Secure Custom Fields by WordPress.org

#107
post #74

Earlier quoted context omitted.

It doesn't matter. Matt didn't have the right to hijack ACF.

I'm not on Matt's side, but anyone has the right to fork a GPL project and call it something else.

That isn't what happened here.

Re: Secure Custom Fields by WordPress.org

#108

If anyone is interested in the extended controversy surrounding Wordpress, there is a site that has been tracking everything.[0] [0] https://bullenweg.com

Wow, I hadn't heard about the nosebleed incident. Absurd, even if he ain't snorting coke, it's deeply weird to continue an interview while profusely bleeding as if nothing is happening.

I have no stake in any of this but some people have nosebleeds without anything nefarious or bad going on. This guy doesn’t need any help looking bad, suggesting that his nosebleed is important is stupid.

Re: Secure Custom Fields by WordPress.org

#109

Earlier quoted context omitted.

This is excellent! Is there a repo of this website? It would be good to have for preservation purposes.

It actually is an excellent website, and the repo is here: https://github.com/bullenweg/bullenweg.github.io

Matt you propably don't remember me but we met briefly on WordCamp Vienna 8 years ago. I was hugely inspired by you for many years and still was until few weeks ago.

It's not too late to stop this madness.

Re: Secure Custom Fields by WordPress.org

#110
post #94

Earlier quoted context omitted.

It is complete bullshit, but calling ACF high quality is also pretty out there. It's one of those giants in WP that is stuck in the past, arguably much like a lot of core.

To be fair we haven’t worked with WP in 4 years; our experience with ACF was always positive.

4 years ago it was still great. I had one contact with WPE support since they bought the plugin last year or so and it was the most frustrating support interaction I ever had. It felt like I was writing with an AI that was prompted to drive me crazy so that I would leave them alone.
Post reply on HN