TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Secure Custom Fields by WordPress.org

172 pointsby ValentineC7 months ago

29 comments

akira25017 months ago
&gt; This update is as minimal as possible to fix the security issue.<p>&gt; This is a rare and unusual situation brought on by WP Engine’s legal attacks, we do not anticipate this happening for other plugins.<p>So.. is this fixing a security issue.. or is this because of WP Engine?<p>&gt; and are forking Advanced Custom Fields (ACF) into a new plugin<p>And stealing their place in the plugin store. A fork generally implies that you are going to set off on your own, and not inhabit the dead flesh of the project you just killed.<p>Matt Mullenweg is the biggest child I have ever seen in operation.
评论 #41822423 未加载
评论 #41821760 未加载
评论 #41822651 未加载
CharlesW7 months ago
So WordPress-the-org — which is effectively Matt, as far as I can tell — just Sherlocked a developer&#x27;s plug-in using the developer&#x27;s own code, ostensibly as retribution for a security issue that the developer had already fixed. <a href="https:&#x2F;&#x2F;www.advancedcustomfields.com&#x2F;blog&#x2F;acf-6-3-8-security-release&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.advancedcustomfields.com&#x2F;blog&#x2F;acf-6-3-8-security...</a><p>What am I missing?
评论 #41821790 未加载
评论 #41821872 未加载
评论 #41823351 未加载
评论 #41821880 未加载
评论 #41821829 未加载
RobotToaster7 months ago
Wordpress banned forks from the plugin directory a while ago, so they&#x27;re doing what they ban everyone else from doing. <a href="https:&#x2F;&#x2F;make.wordpress.org&#x2F;plugins&#x2F;2021&#x2F;02&#x2F;16&#x2F;reminder-forked-premium-plugins-are-not-permitted&#x2F;" rel="nofollow">https:&#x2F;&#x2F;make.wordpress.org&#x2F;plugins&#x2F;2021&#x2F;02&#x2F;16&#x2F;reminder-forke...</a>
评论 #41821877 未加载
评论 #41821901 未加载
Kye7 months ago
Related: the main developer on the Fields API proposal is calling it quits on involvement with WordPress.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;sc0ttkclark&#x2F;wordpress-fields-api">https:&#x2F;&#x2F;github.com&#x2F;sc0ttkclark&#x2F;wordpress-fields-api</a><p>I&#x27;m not entirely sure what it is but it has over 350 stars and quite a few forks so it&#x27;s probably important.
评论 #41822327 未加载
bullenweg7 months ago
If anyone from Automattic is reading this and would like to confidentially leak any internal information about this behaviour from Matt, please email admin@bullenweg.com and I will publish it on bullenweg.com.
评论 #41821742 未加载
partiallypro7 months ago
This is one of the sleaziest things I&#x27;ve ever seen. I fear a hard fork of WordPress is now inevitable and unfortunately, it&#x27;s possibly going to kill the platform, all over one man&#x27;s ego. How can I now sell my clients on using WordPress for mission critical things if on a whim the owner of WordPress can break my site or lock out my security updates, just because I chose the &quot;wrong&quot; host or plugin? I don&#x27;t see how the Board can sit by and let this all unfold like this, it&#x27;s practically business suicide.
评论 #41823094 未加载
righthand7 months ago
If anyone is interested in the extended controversy surrounding Wordpress, there is a site that has been tracking everything.[0]<p>[0] <a href="https:&#x2F;&#x2F;bullenweg.com" rel="nofollow">https:&#x2F;&#x2F;bullenweg.com</a>
评论 #41821794 未加载
0cf8612b2e1e7 months ago
Link to the delta from the latest code revision where they replaced “ACF” with “SCF”.<p><a href="https:&#x2F;&#x2F;plugins.trac.wordpress.org&#x2F;changeset?sfp_email=&amp;sfph_mail=&amp;reponame=&amp;new=3167679%40advanced-custom-fields&amp;old=3164480%40advanced-custom-fields&amp;sfp_email=&amp;sfph_mail=" rel="nofollow">https:&#x2F;&#x2F;plugins.trac.wordpress.org&#x2F;changeset?sfp_email=&amp;sfph...</a><p>Not a lawyer, but since WPE sells ACF services, can WP redirect users away? That is directly impacting a competitor’s bottom line.
评论 #41831007 未加载
discostrings7 months ago
Blog post on wordpress.org concerning this: <a href="https:&#x2F;&#x2F;wordpress.org&#x2F;news&#x2F;2024&#x2F;10&#x2F;secure-custom-fields&#x2F;" rel="nofollow">https:&#x2F;&#x2F;wordpress.org&#x2F;news&#x2F;2024&#x2F;10&#x2F;secure-custom-fields&#x2F;</a>
评论 #41821660 未加载
评论 #41823726 未加载
评论 #41825054 未加载
评论 #41821693 未加载
评论 #41821701 未加载
chx7 months ago
According to <a href="https:&#x2F;&#x2F;make.wordpress.org&#x2F;plugins&#x2F;2021&#x2F;02&#x2F;16&#x2F;reminder-forked-premium-plugins-are-not-permitted&#x2F;" rel="nofollow">https:&#x2F;&#x2F;make.wordpress.org&#x2F;plugins&#x2F;2021&#x2F;02&#x2F;16&#x2F;reminder-forke...</a> this is piracy.<p>Let&#x27;s look at newer documentation:<p><a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;plugins&#x2F;wordpress-org&#x2F;detailed-plugin-guidelines&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;plugins&#x2F;wordpress-org&#x2F;detail...</a><p>&gt; The use of trademarks or other projects as the sole or initial term of a plugin slug is prohibited unless proof of legal ownership&#x2F;representation can be confirmed<p>The plugin is at <a href="https:&#x2F;&#x2F;wordpress.org&#x2F;plugins&#x2F;advanced-custom-fields" rel="nofollow">https:&#x2F;&#x2F;wordpress.org&#x2F;plugins&#x2F;advanced-custom-fields</a> and advanced custom fields filed for trademark last December <a href="https:&#x2F;&#x2F;trademarks.justia.com&#x2F;983&#x2F;21&#x2F;advanced-custom-98321164.html" rel="nofollow">https:&#x2F;&#x2F;trademarks.justia.com&#x2F;983&#x2F;21&#x2F;advanced-custom-9832116...</a><p>Also<p><a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;plugins&#x2F;wordpress-org&#x2F;plugin-developer-faq&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;plugins&#x2F;wordpress-org&#x2F;plugin...</a><p>&gt; We also don’t accept 100% copies of other people’s work<p>There&#x27;s a clause which looks applicable <a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;plugins&#x2F;wordpress-org&#x2F;plugin-developer-faq&#x2F;#what-happens-to-a-plugin-if-the-plugin-owner-gets-blocked" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;plugins&#x2F;wordpress-org&#x2F;plugin...</a><p>&gt; What happens to a plugin if the plugin owner gets blocked?<p>however the page says &quot;Last Updated: 12 October 2024&quot; and <a href="https:&#x2F;&#x2F;github.com&#x2F;WordPress&#x2F;developer-plugins-handbook&#x2F;blob&#x2F;75d06a1d9c8572e2ee20667c6f8e4364647221d6&#x2F;wordpress-org&#x2F;plugin-developer-faq&#x2F;index.md">https:&#x2F;&#x2F;github.com&#x2F;WordPress&#x2F;developer-plugins-handbook&#x2F;blob...</a> (permalink at the time of writing this) doesn&#x27;t have this section. So it really looks <i>someone</i> manually edited the page on wordpress.org without editing the source. Now, who has such permissions and has the motive to do this?
评论 #41823058 未加载
评论 #41822730 未加载
delichon7 months ago
As a builder of a small specialized CMS for which WordPress is a large generalized competitor, thanks Matt. Refugees welcome.
评论 #41821732 未加载
评论 #41821795 未加载
asmor7 months ago
I thought there weren&#x27;t any hinges left for Matt to unhinge. He <i>dug</i> for that minior vulnerability to be to able to justify that takeover.<p>Who can ever trust this guy and his company, ever again?
notamy7 months ago
Good lord, why?? That’s such a petty move and is just doing further damage to the WordPress ecosystem.
评论 #41821818 未加载
sureIy7 months ago
This gets better by the day.<p>I&#x27;m so rooting for WPE and I hope the judge will lay it heavy.
mirzap7 months ago
Pathetic. Matt banned one of the most popular WordPress plugins. Then, he forked the code and hosted it on WP.org, which is against the Terms of Service. He also hosted it in the plugin directory on the same path as ACF, stealing its SEO traffic. Wow!<p>Matt&#x27;s state of mind is clearly not good. If I were an investor in WordPress, I would start thinking about cutting my losses. WordPress will not recover from this self-inflicted destruction<p>*Update* Oh, it&#x27;s worse than that. He just renamed the ACF to SCF and claimed all the installations and reviews from ACF. I still can&#x27;t believe this happened. This can&#x27;t be legal!
评论 #41822198 未加载
sgdfhijfgsdfgds7 months ago
OK so:<p>1) WordPress clearly lacks functionality like ACF that belongs in core<p>2) Many developers clearly like ACF<p>3) Many do not (it&#x27;s messy in the DB, if you ask me)<p>4) Core functionality that was if not API-compatible, at least API-familiar with ACF would be welcomed by many<p>5) Creating a new plugin that did this, that was transitioned into core (like other functionality has been), would be a good plan<p>6) Commandeering the slug for a decade-old commercial plugin like this, to replace it with a fork, is so obviously fucking bad form that it&#x27;s still hard to believe it is happening even given all the other whatthefuckery that has been happening.<p>ETA: 7) &quot;<i>Secure</i> Custom Fields&quot;? Really? The difference is what?<p>What the fuck, Matt?<p>ETA: personally I understand many of the frustrations with WP Engine&#x27;s positioning. I have experienced exactly the trademark confusion issues that the lawsuit has been about, where clients have assumed WP Engine is WordPress itself. I don&#x27;t use them after some iffy customer service and technical issues early on. But this is absurd behaviour.
评论 #41821787 未加载
xenago7 months ago
So, wordpress is being burnt to the ground by Matt. Just great. :&#x2F;
mattbee7 months ago
I can&#x27;t even follow what&#x27;s going on here, and I used to be an expert in software licensing drama. All I see is a bunch of unilateral actions driven by Matt Mullenweg that breaks so many implicit promises of how a free software steward should behave.<p>Wordpress sites quite often seen to be a hodge-podge of plugins, each with their own UI and conventions, and (as a host) I&#x27;m never an expert in anye one of them. Has one of the site designers used a plugin that has offended Matt? Or that might offend him in the near future? How do I even audit for that?<p>I don&#x27;t need much of a push to move my position on this. Before: &quot;eh, use Wordpress if it&#x27;s cheaper&quot; Now: &quot;please don&#x27;t, that decision will probably cost me&quot;.
评论 #41822642 未加载
cendyne7 months ago
It is as if Wordpress [1] is asserting that the original author is a danger to public safety. Their terms read: ...<p>To that end, we reserve the following rights: ... to make changes to a plugin, without developer consent, in the interest of public safety.<p>[1]: <a href="https:&#x2F;&#x2F;x.com&#x2F;WordPress&#x2F;status&#x2F;1845179613783142426" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;WordPress&#x2F;status&#x2F;1845179613783142426</a>
butz7 months ago
ProcessWire CMS (<a href="https:&#x2F;&#x2F;processwire.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;processwire.com&#x2F;</a>) is a neat alternative if one requires quite complex set of custom fields on a website.
johnchristopher7 months ago
So, is the next step to capture wp-migrate (or another prominent WPEngine plugin) or to update the core to degrade ACF pro ?
butz7 months ago
I wonder what will happen to old websites I built with ACF and did not touch for years? Are they vulnerable now, as owners cannot get updates for ACF?
评论 #41821967 未加载
评论 #41824125 未加载
getcrunk7 months ago
Posted this in the other thread:<p>A lot of the comments seem to call out Matt (right or wrong). But that’s the easy thing to do.<p>No one dares address the systemic issue of for profit corporations exploitatively (ab)using open source software.<p>There is a social contract that people should contribute back, and while it’s largely unenforceable, as it should be, when it’s happening on a systemic level something has to be done. And we are all complicit if we don’t at least say that much and spare some good will towards the guy actively in that fight at least superficially<p>*Following is a response to some replies on the other thread, that clarifies my points *<p>Matt being a poor steward of gpl is by definition not a systemic issue … unless ur claim is that many people in positions like him do what he does which is in turn caused by invariant factors?<p>The systemic issue is companies the world over not giving their fair share back in terms of contributing to foss.<p>I might agree with most of your points, I’m just trying to get people to realize there’s the local issue of Matt&#x2F;wp and then there’s this global issue of companies building businesses off foss and not giving back.
评论 #41823244 未加载
评论 #41822857 未加载
评论 #41822930 未加载
martin_a7 months ago
Just stealing plugins right now? Or is this some kind of &quot;eye for an eye&quot; situation?<p>I&#x27;m really turned down from the whole ecosystem by this total shitshow. Seems like everything could be pulled from under running sites if some clown decides he doesn&#x27;t like it anymore.<p>At this point I just hope that WP Engine wins whatever lawsuit happens and Matt Mullenweg (and everybody who was involved besides him) has to pack his things and leave everything WP-related forever.
wkirby7 months ago
We no longer do custom WordPress work --- it turned out to never be worth the hassle --- but when we did, our company used ACF extensively. High quality plugin with responsive support and very fair licensing terms.<p>This --- to me --- smacks of complete bullshit.
评论 #41821832 未加载
评论 #41821884 未加载
jrflowers7 months ago
This whole saga is surreal because I thought myself to be constitutionally incapable of rooting for a private equity firm to win a fight, but this is like watching a guy violently strain to shit his pants while yelling “Look what they made me do!”<p>Also the guy is in a hot tub with all of his friends and employees
trog7 months ago
If you were an insider deliberately trying to tank WordPress, it is hard for me to imagine anything you could do that would be more effective than this.
评论 #41825634 未加载
stefanos827 months ago
The URL though says &quot;advanced-custom-fields&quot;; Matt...I can&#x27;t find the words to comment; I just shake my head -_-
评论 #41821510 未加载
yard20107 months ago
This is a human being, making a mistake, only to be bullied by literally the whole internet?<p>Never have I ever witnessed a lynch with any positive consequence whats so ever in my entire life.<p>Empathy all the way. We all make mistakes. Stay kind and positive.
评论 #41832008 未加载
评论 #41831246 未加载
评论 #41827390 未加载