2 ms·
It was a stupid, stupid decision on WP's part. After reading it, the first thing I did was to make sure that I and all WP sites I have access to had automatic
by mklepaczewski 2y ago
It was a stupid, stupid decision on WP's part.
After reading it, the first thing I did was to make sure that I and all WP sites I have access to had automatic updates disabled. This always seemed like a good policy to me, as it is such a massive attack vector. After all, some popular
plugin developed by someone in Nebraska (obligatory XKCD: https://xkcd.com/2347/ https://xkcd.com/2347/) might be hijacked at some point. WP did the stupidest thing ever by hijacking ACF.
WP is the villain now because they can inject unknown, unvetted code into my site (if I had enabled automatic updates). While I find ACF's code abhorrent, at least it has a proven track record of working and not crashing my site. Someone who just took over the plugin does not enjoy the same trust from me.