Live data from Hacker News

WordPress.org's latest move involves taking control of a WP Engine plugin

theverge.com

1–10 of 222 posts

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#6
> It’s not clear what security problem Mullenweg is referring to in the post.

Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use.

> Going forward, Secure Custom Fields is now a non-commercial plugin

Does this imply that Wordpress is potentially going after a revenue stream from WPEngine?

If the plugin had Pro options* then are those closed source and so not available to Wordpress in their fork of the codebase? It's not clear.

* https://www.advancedcustomfields.com/pro/

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#7
Mullenweg calls it a fork. I could see that being somewhat okay if it's indeed for security fixes, but removing the upsells is petty at the very least. But a fork doesn't take control of the original, so I wonder what they did there? Perhaps a redirect from the ACF entry to SCF?

To be honest, none of this makes WordPress look good... It just seems like a douche move.

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#8
post #5

They either have some of the best or worst legal counsel; or they just ignore the legal counsel.

Some people just think they're above the law. This Matt guy has gone mental.

Yeah, but pretty sure some of the employees/volunteers are in on it or "just following orders."

Re: WordPress.org's latest move involves taking control of a WP Engine plugin

#9

> It’s not clear what security problem Mullenweg is referring to in the post. Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use. > Going forward, Secure Custom Fields is now a non-commercial plugin Does this imply that Wordpress is potentially going after a revenue stream from WPEngine? If the plugin had Pr…

My understanding is ACF injected notices for their personal legal gains on everyone's dashboards. I wouldn't be surprised if such thing is a breach.
Post reply on HN