Live data from Hacker News

EmDash – A spiritual successor to WordPress that solves plugin security

blog.cloudflare.com

371–380 of 558 posts

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#371
post #328

In my opinion, Cloudflare are coming at this from the wrong angle. WordPress is so popular because back in the day it was the easiest way to get a website built. So it got a network effect of engineers behind it which is why it persists at 40% of websites today. Same thing happened with React - majority of Typescript sites are written in React and NextJS because of the network effect around it. Yeah the security aspe…

Wordpress has an amazing talent pool of experienced people. EmDash is starting from zero - but you have to start somewhere!

I’m very happy with WP, but I’ll be cheering on EmDash if it gets momentum.

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#372
Tangential rant about WP.

Having got back in to some WP in the last year, the big thing that struck me compared to other framework/environments is... no... build step, or even plugin/module install step. Files are just there in the document root, accessible by default - the logic files are invokable and the asset files are reachable. Most other php frameworks will install a plugin/module outside the document root then have some sort of publish/install step that will copy assets to be publicly accessible as needed. No plugin logic files would be invokable directly from a URL. That one change would make a big difference, imo, but seeing so much of the last 15-20 years of WP involves helper functions to assumed paths, and default assumptions about assets and logic living in the same paths... I'm not sure the ecosystem could adapt or support an alternative approach at this stage. Might be wrong. It's taken me a while to put my finger on why the current situation encourages less-secure-by-default systems, and this is probably the biggest thing I've landed on. There are other issues, but these issues all help contribute to WP popularity in the first place...

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#374

IMO unlike WP, EmDash can he harder to host. With WP you can find a plethora of cheap PHP hostings that offer WP preinstalled. If you need to tweak a theme - just download a .php file via FTP, tweak it and upload back. No server management or restart is required. One big potential benefit that EmDash has - every WP deployment is basically a honeypot.

[deleted]

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#375

> x402 is an open, neutral standard for Internet-native payments. It lets anyone on the Internet easily charge, and any client pay on-demand, on a pay-per-use basis. A client, such as an agent, sends a HTTP request and receives a HTTP 402 Payment Required status code. In response, the client pays for access on-demand, and the server can let the client through to the requested content. Fascinating. Cloudflare is envis…

To be frank, I thought this was an elaborate April Fool's joke, particularly when I saw that. It suggested to me 'you could charge for anything' while subtly implying you should also be paying them (within a handy deploy button every few paragraphs) for the privilege of running their stuff on their hosting solution.

I suppose this is the world we live in.

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#376

Earlier quoted context omitted.

Imho CMS is just a tool that generates static html files on the server. The distinction is a bit artificial. CMSes have static html cashing and CDNs will allow you to "one-click" firewall the dynamic administration and cache the static html for you. Static website generators are cool way for programmers to do that work on their machine but in the end the distinction of what gets served is very small (if you set up th…

CMSs allow non-technical people to update the site - that's why WordPress, Drupal, and all of the shambling corpses of "digital experience platforms" still command the dollars and eyeballs that they do. Go ahead and give your content people access to a static site builder and see how quickly the process falls apart. Static site generators are perfect for engineers but terrible for the marketing people that are the ac…

I did this, and you are 100% correct.

I used Hugo, told the marketing people to send me a markdown file and I'd load it up to Hugo. That was clearly too painful for them. So I told them to send me a Word doc and I'd convert it to markdown and load it up. That was too painful. I told them to send me an email with the words and images and I'd work out the rest. That was too painful.

They got some marketing agency to rewrite the entire marketing site in Wordpress, and then we had to implement some godawful kludges to get our backend to redirect to their shitty WP host for the appropriate pages. It was awful.

But the marketing folks were finally happy. They could write a blog post (that no-one read) themselves in the actual CMS and see it go live when they pushed the button.

We spent thousands, in a cash-strapped startup, dealing with this bullshit.

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#377

Earlier quoted context omitted.

I think this is true, however, when it comes to non-coding clients I've worked with they really do like the ability to make minor edits to a site with a UI rather than having to continually ping a developer. The problem with WordPress (and it looks like this solution largely just replicated the problem) is that it's way too cumbersome and bloated. It really is unlike any modern UI for really any SaaS or software in g…

I hated Wordpress so much that when the clients wanted an admin dashboard I used a neat PHP CMS called Kirby. It was awesome back then! So simple

I wrote my own CMS, as the core WordPress functionality wasn't too much to replicate.

But eventually the WordPress ecosystem was too strong, and the real value proposition was plugins and familiarity. That continues to be true to this day, which is why no CMS has de-throned WordPress in spite of significantly better UX, architecture and developer experience. None of it matters when the client has a suite of plugins they have been using for 10+ years, that are now core to their business.

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#378

Earlier quoted context omitted.

I think this is true, however, when it comes to non-coding clients I've worked with they really do like the ability to make minor edits to a site with a UI rather than having to continually ping a developer. The problem with WordPress (and it looks like this solution largely just replicated the problem) is that it's way too cumbersome and bloated. It really is unlike any modern UI for really any SaaS or software in g…

There are two types of WordPress sites from my perspective as someone who got their start in webdev in that ecosystem. The first and arguably largest is exactly what you describe. Little sites for small businesses who just want an online presence and maybe to facilitate some light duty business development with a small webshop or forum. These sites are done by fly by night marketers who are also hawking SEO optimizat…

I have no idea if it’s still true but it used to be the case that you had 3 choices with a Wordpress install and even a couple plugins:

1) Have a part time job updating it and plugins, making sure you weren’t introducing vulns at every step

2) Leave it as is and hope that no vulns are discovered for your particular version or plugin versions

3) Have things auto-update and pray that your plugins don't get sold or compromised and backdoor your site

Re: EmDash – A spiritual successor to WordPress that solves plugin security

#380

Earlier quoted context omitted.

They called the project EmDash and launched it on April 1st with a blog which brags about how little effort it took to write because of agents before even saying what it is . If the product launch involves dressing the engineering team up in duck suits and releasing to a soundtrack of quacking, it's really not surprising people are asking the guy they hid behind the Daffy mask on why he's dressed as a duck rather tha…

I know that it's discourteous to write-off a potentially valuable project because the release post showed a lack of self-awareness, but I think it's indicative of the larger struggle taking place: that trust is decaying. It's decaying for a lot of the reasons displayed in the post, like you described, but the post also: - is overlong (probably LLM assisted) - is self-congratulatory - boosts AI - rewrites an existing…

This is a great point. I wish we started from this.
Post reply on HN