Oh god, this gave me a minor heart attack. We are using over 20 ACF fields for 150+ sites. I thought it was completely out of the WordPress ecosystem. I am glad they have the zip download and continuing auto updates. EDIT: I confirm our ACF plugins on sites are all switched to secure custom fields. This is so shady, it broke our snippets because we are using prepend and append texts to wrap our field values. Now they…
ACF Plugin no longer available on WordPress.org
51–60 of 151 posts
Re: ACF Plugin no longer available on WordPress.org
#52Re: ACF Plugin no longer available on WordPress.org
#53Oh god, this gave me a minor heart attack. We are using over 20 ACF fields for 150+ sites. I thought it was completely out of the WordPress ecosystem. I am glad they have the zip download and continuing auto updates. EDIT: I confirm our ACF plugins on sites are all switched to secure custom fields. This is so shady, it broke our snippets because we are using prepend and append texts to wrap our field values. Now they…
Re: ACF Plugin no longer available on WordPress.org
#54This is particularly bananas as ACF is basically table stakes for doing anything beyond blogging. I’d assume most websites that make actual money are thoroughly dependent on it. To twist the knife on a personal spat, Mullenweg just blew up uncountable businesses on a double-holiday weekend. At this point, seriously, fuck that guy.
They replaced ACF with a forked version so the functionality is still there. That doesn't excuse it but the situation is not so dire for users.
Given how widely used ACF is, it wouldn't be surprising to learn that a lot of weekends were ruined by the "fork".
Re: ACF Plugin no longer available on WordPress.org
#55This is particularly bananas as ACF is basically table stakes for doing anything beyond blogging. I’d assume most websites that make actual money are thoroughly dependent on it. To twist the knife on a personal spat, Mullenweg just blew up uncountable businesses on a double-holiday weekend. At this point, seriously, fuck that guy.
Not sure about this.
I'd assume most Wordpress sites that make actual money are dependent on WooCommerce and Easy Digital Downloads, and maybe Gravity Forms/WP Forms for member subscriptions.
None of these are reliant on ACF, and there's any number of WP plugins like this that do the whole job of some website niche or other.
(I've been doing bespoke WP builds for at least a decade -- first one probably more like 14 years ago actually -- and I've not used ACF a single time. There has always been an alternative, and for a developer it's a bad choice.)
Either way: I don't think ACF's popularity is the major factor here. It's that it's an outright abuse.
The word "gaslighting" gets overused but it applies quite well to what ACF free plugin users are experiencing here.
As to "blew up": I am not sure how many money-making ACF users this has affected, because they tend to use ACF Pro, which is a separate download.
What appears to have been removed from ACF to make this shady SCF nonsense is the upsell marketing. Not sure what other breakage there would/could have been. I have seen people say things have broken but I suspect they are relatively minor issues caused by the actual ACF security patch which is also shipped here... because they haven't changed much.
Though if Secure Custom Fields is getting the blame for the breakage, that's kismet, karma, whatever you want to call it.
Re: ACF Plugin no longer available on WordPress.org
#56Oh god, this gave me a minor heart attack. We are using over 20 ACF fields for 150+ sites. I thought it was completely out of the WordPress ecosystem. I am glad they have the zip download and continuing auto updates. EDIT: I confirm our ACF plugins on sites are all switched to secure custom fields. This is so shady, it broke our snippets because we are using prepend and append texts to wrap our field values. Now they…
I can confirm this has been escalated internally in the WP slack.
I can also provide this context which I found concerning, given the way this was taken over and rolled out on a Saturday afternoon, of which I have also been dragged into now as a fellow site maintainer.
- Matt Mullenweg "in a few days we'll have a Github where people can get involved, and we can also set up proper build systems, etc"
So its all in flux obviously. I let them know the same thing, that I find this as a malicious supply chain attack that is affecting the community.
Re: ACF Plugin no longer available on WordPress.org
#57Oh god, this gave me a minor heart attack. We are using over 20 ACF fields for 150+ sites. I thought it was completely out of the WordPress ecosystem. I am glad they have the zip download and continuing auto updates. EDIT: I confirm our ACF plugins on sites are all switched to secure custom fields. This is so shady, it broke our snippets because we are using prepend and append texts to wrap our field values. Now they…
Photomatt aka Matt mullenweg hangs out on HN. I’d love to hear how he justifies taking away this engineers’ Sunday? I doubt this person is the only person working this weekend due to Matt’s theft of ACF
His posts on slack [1] show that he sees it as "either with us or against us", and he's willing to harm users to force them to choose a side instead of staying neutral. He probably hopes that people will blame WP Engine for it.
I think his real goal is tortious interference. Hurting devs who use ACF is just a bonus.
[1] https://threadreaderapp.com/thread/1843963052183433331.html
Re: ACF Plugin no longer available on WordPress.org
#58To me this is indistinguishable from an account takeover attack executed by an insider. I doubt any prosecutor would be interested, but to my eyes WordPress.org has violated the CFAA by accessing WordPress instances outside the bounds of their authorization. They were authorized to modify WordPress instances in ways ACF prescribed, not in ways of their own choosing. I'm not saying I'd like to see Mullenweg in chains,…
IMO it's also notable that Mullenweg is in this state of mind and also has access to Tumblr data, with a history of allegedly doxxing the relationships between anonymous user blogs based on non-public information [0]. One doesn't need to agree with the moderation decision, or take sides on the political context around it, to understand that there is a tremendous amount of centralized power here, that norms are going…
In the future, when a BDFL telegraphs that they're willing to abuse their powers like this, we need to fork immediately. Open source is more important than any single project or any single BDFL. We can't allow open source to appear risky or unreliable relative to proprietary software, subject to the whims of volatile personalities.
Open source is kind of like libraries - an institution for the collective good people managed to erect in the past that would be neigh impossible to replicate today. Imagine convincing companies in any other industry to collaborate openly and freely with their competitors merely because it's good for society as a whole. You'd be labeled a socialist and laughed out of the room.
If we lose it, it's probably gone for good.
Re: ACF Plugin no longer available on WordPress.org
#59Oh god, this gave me a minor heart attack. We are using over 20 ACF fields for 150+ sites. I thought it was completely out of the WordPress ecosystem. I am glad they have the zip download and continuing auto updates. EDIT: I confirm our ACF plugins on sites are all switched to secure custom fields. This is so shady, it broke our snippets because we are using prepend and append texts to wrap our field values. Now they…
How did the sites auto-update to have this plug-in removed/replaced? Are your sites set up to just automatically take push updates from WordPress central command or something and auto-modify themselves?!
It was extended a couple of years ago to automatically apply plugin updates for you if you opted in, and I think automatic plugin updates may now be the default.
(This is on balance a good thing; almost all WP vulnerabilities are outdated plugins, and until this mechanism was prevalent, WordPress occasionally had to live-patch existing installations of third party plugins in the case of severe vulnerabilities.)
The reason this nasty little takeover worked is that they (Matt, whoever helped) have stolen ACF's slug (advanced-custom-fields). So as far as the updater is concerned, it's just another plugin update to the same code base.
And in fact, very little has changed.
Re: ACF Plugin no longer available on WordPress.org
#60Oh god, this gave me a minor heart attack. We are using over 20 ACF fields for 150+ sites. I thought it was completely out of the WordPress ecosystem. I am glad they have the zip download and continuing auto updates. EDIT: I confirm our ACF plugins on sites are all switched to secure custom fields. This is so shady, it broke our snippets because we are using prepend and append texts to wrap our field values. Now they…
How did the sites auto-update to have this plug-in removed/replaced? Are your sites set up to just automatically take push updates from WordPress central command or something and auto-modify themselves?!