4 ms·
WordPress is a lot more than it's core code. There's a whole ecosystem of plugins, for example, and the usual place to share them (wordpress.org/plugins) is, es
by troymc 2y ago
WordPress is a lot more than it's core code. There's a whole ecosystem of plugins, for example, and the usual place to share them (wordpress.org/plugins) is, essentially, controlled by one guy. It's not so easy to fork that.
- econ 2y agoThen start with a new place to share plugins.
- magic_smoke_ee 2y agoExactly. It's a SPoF. Depending on ego and whims of a malicious tyrant is stupidity or insanity.
- Timon3 2y agoThe first people to take this step will most likely have their plugins stolen, just as Matt did with ACF. This means taking this step is a massive danger for the first contributors - those with the highest impact are those with the most to lose.
- Ringz 2y agoWhat do you exactly mean with „stolen“? Honest question.
- dalmo3 2y agoHe forked the plugin and pointed the original uri to his fork: https://news.ycombinator.com/item?id=41821400 https://news.ycombinator.com/item?id=41821400
- Timon3 2y agoMatt's company will fork your project, replace your original plugin listing and claim all your reviews as theirs, while also stopping you from distributing security updates to force people to switch to their fork. Imagine if you make your money from selling your plugin, and Matt does this to you. Every WP plugin developer has to live in fear of this happening at any moment, and you can be certain it will happen if you show any kind of resistance towards Matt.
- mysidia11 2y agoI'd suggest guerilla-scraping the entire plugin site under the radar, unbeknownst to them. Go live with a new site that simply has all the same directory data as the existing site and additional mirror site links for each plugin, And create a process for plugin authors to claim the existing page in the directory. Matt may be able to fork plugins, but they won't be able to fork every single plugin in the directory, as it isn't very feasible. It also would then not necessarily be obvious to Matt which plugin listings in the new directory have been claimed, and which plugins are being updated by other people from the community.
- Timon3 2y agoJust scraping the site isn't quite enough. You'd also have to fork Wordpress to be able to use a plugin directory not under Matt's control, which is important for the average admin to quickly patch security-relevant issues. But even when you do that, I'd expect him to just give people an ultimatum - either "officially" host on his plugin directory, or others, but not on both. You'd have to reach critical mass pretty much immediately, or Matt can bully the ecosystem into compliance.
- econ 2y agoIf that mass doesn't accumulate fast enough he is right and people want him to run things the way he does. It might look weird to me or others, they might even say the opposite but only ones actions count.
- Timon3 2y agoNo, that's not how consent and preferences work. If someone has power over a group of individuals, and that group doesn't act due to threats, it's not confirming that they want to be controlled by that someone.
- econ 2y agoThey are to blame for his power. If someone else decided the time to act is now then they must choose now. The default is to not change anything. I may ignore what people say and look what they do. I do this to make people angry :-) What is the alternative? To tell people how sad it is they can't possibly anything ever? Why bother? Does more harm than good.
- gitaarik 2y agoWhat do you mean? If you create a neopress.org and host the existing open source plugins there, how can they be stolen? Just the code of WordPress needs to be updated that the plugins are downloaded from the new URL. It's not so hard.
- Timon3 2y agoDid you look at the other comments, where someone asks the same question, and I give an answer?
- gitaarik 2y agoDo you mean that your plugin can get stolen? Well, you can ask plugin owners to upload a particular file with a particular key to their plugin on WordPress.org. That way they can prove they have access, and they should be allowed ownership of the plugin on the fork.
- Timon3 2y agoNo, that's not the "stealing" I'm referring to. Instead of guessing what I could mean, just read my response to the person who first asked what I mean with "stealing".