Category Archives: WordPress
Non-Blog WordPress
On WP Security
Wincent Colaiuta has no problem throwing flames at WordPress, but doesn’t see fit to enable comments. (Apparently disabled to make Movable Type more secure.) His table-layout blog isn’t too notable but it got linked from Daring Fireball so a lot of people saw his article trying to draw the line between a routine point release and encouraging people to never use WordPress on the public internet. Here are a few points for thought in response:
- The SQL problem in 2.2 requires both registration to be enabled (off by default) and the blog to be upgraded to 2.2. It is a serious problem but I’ve heard of fewer than 5 exploits from the flaw. Even if you assume there are 100 blogs for every one we heard about, that’s still an incredibly small percentage of the millions of WordPresses out there, especially considering, as Wincent points out, the problem has been in the public for a while now.
- Getting people to upgrade web software is hard. We work as best we can with hosting companies, but a consideration is that it’s best to roll several security fixes into one release. It’s not responsible to do a release if we know of another problem, so sometimes there is a lag between an initial report and a final release, not to mention the testing required of a product used as much as WP.
- Wincent digs up the server crack that modified the files of 2.1.1 for a few days. Ignoring the fact that it was a server issue and had nothing to do with WordPress the software, we actually had NO reported exploits of the problem. (Though I’m sure there are at least a handful out there with problems, it wasn’t enough to hit our radar.) Despite that we took a hit and publicized the issue as much as we could to get the word out.
- Also about 2.1.1, the problem was found through someone proactively auditing the codebase.
- Finally Wincent says of WP “[a]nd if you insist on installing it, then you need to watch the trac like a hawk.” You would think complete transparency of the problems (it was on our bug tracker and mailing list) would be a good thing, especially considering the software Wincent uses doesn’t have a bug tracker, and the only way to submit a bug is through a contact form.
We can and do review new code for problems, and pick the vast majority up before any releases. I think the real issue though is not that WP has bugs which are sometimes security related, which all software not written by djb does, but that the mechanisms for updating complex web software are a pain. Right now the best experiences are probably with folks like Media Temple or Dreamhost that have pretty foolproof one-click upgrades and are quick with updates.
Making notification better and upgrading more painless for people not lucky enough to be on a host like that are problems with some very clever minds on them, and I’m confident that we’ll have good progress toward each in the next major release of WP.
Finally, I suppose we could act more like our proprietary competitors and try to downplay or hide security issues instead of trumpeting them loudly in our blog, but I think the benefit of having people well-informed outweighs the PR lumps we take for doing the right thing. I truly believe talking about these things in the open is the best way to address them.
In some ways it’s a good problem to have. When a product is popular, not only does it have more eyes from security professionals on it, but any problems garner a level of attention which is not quite warranted by the frequency of the general event, like Angelina Jolie having a baby. There are certainly things intrinsic to coding that can make software more or less secure, but all things being equal the software with the most eyes on it, which usually means Open Source, will be the most robust in the long term.
Avoiding Widget Slowdown
Mike Davidson: How To Keep Widgets From Slowing Down Sites: WEDJE. I’m thinking about making this a requirement for all external widgets on WordPress.com.
Flickr Switches to WP
The official Flickr blog has switched from Typepad to become a WordPress.com VIP and introduced some cool language features in the process. We’re all such big fans of Flickr and their team it’s been a real pleasure to work with them and have them on WordPress.
WP Contributors
Lloyd has a great post about all the people who contributed to WordPress 2.2, thank you! Open source is about so much more than code and licenses.
CNN on WP
Many of you have written in that CNN’s new Political Ticker blog is on WordPress. We know! They’re part of our VIP program which allowed them to launch quickly and serve millions of pageviews with no problems. The team there has launched dozens of blogs on the system, including ones for Fortune.com and CNN Money and is a real pleasure to work with. To the extent blogs are going to have an impact on the 2008 election they need to be able to reach millions of people in a short period of time without problems, I hope that WordPress.com provides that platform for folks.
Announcing HyperDB
I’ve started a new mailing list to discuss an enterprise DB class for WordPress.
Community Tips
2.2: Three Things
2.2 Dropped
WordPress 2.2 “Getz” is now available. Go get it! It’s totally worth upgrading. Here is Stan Getz and Dizzy Gillespie playing It Don’t Mean a Thing if it Ain’t Got That Swing to listen to while upgrading, you’ll be done before the song is.
DePo Clean Theme
Derek Powazek, an inspiration to many of my early online activities, is now blogging with WordPress and has released his theme, the DePo Clean WordPress Theme.
WordPress Stats
On Saturday night (because that’s how we roll) we launched WordPress.com stats plugin for WordPress.org bloggers, and it’s gone incredibly well so far. We’re coming up on our first full weekday since launch, it’s running on 2,750 blogs already and tracked about a million 1.3 million pageviews today. A few bugs popped up, of course, but that’s life in software.
AllthingsD on WP
All Things D is a fantastic new WordPress MU powered site that I think is a really good example of what the platform can do. Being from Walt Mossberg and Kara Swisher, they anticipate a healthy amount of traffic so they’re hosted on our VIP platform. Toni has some more details, including all the cool people involved in bringing the project together (the real work).
Random Redirect Plugin
I wrote a quickie plugin based on an idea from Techcrunch, when you visit the URL it redirects you to a random post from your blog.
Delaying 2.2
The WP dev team has decided to hold back version 2.2 for at least a week or two from the original date of April 23 while we polish things up. I’ll post an updated release date as soon as we figure out how long everything is going to take. (Which is extra-hard in open source development.)
NASA on WordPress
J. J. Toothman wrote in that NASA is using WordPress for their new Ames Research Center project. Sweet!
Plugin Authors Get No Love
One interesting thing in the whole adware themes discussion is the people claiming if we require GPL it’ll kill the number and quality of themes out there, that the best themes have ads in them, that they couldn’t make themes if they weren’t getting the SEO gaming money, et cetera and so on.
There are two types of WordPress add-ons, themes and plugins. Are there any similarities?
- Plugins are just as hard or harder to write and design as themes.
- All plugins in our directory are required to be GPL or compatible.
- Plugin authors almost never get links on the front-end of a blog.
- I’m not aware of any plugins that bundle advertising with the intention of gaming search engines, like themes are.
Despite all of this, the plugin ecosystem around WordPress is flourishing, especially since we made the plugin directory, and hundreds have been added. It seems any of the doomsday scenarios people are expecting to happen to themes would have happened to plugins years ago. If ad-bundled themes really are better, a suggestion I find insulting to all those who volunteer their time for WordPress, then maybe they should start their own theme directory with only adware themes and they should get a ton of traffic.
(And just to respond to the title, I think plugin authors get tons of love, and hopefully we can help them get more with upcoming revisions to the plugin directory.)
Sponsored Themes Essay
I’ve posted my essay, On Sponsored Themes, on Weblog Tools Collection to continue the discussion that’s been happening there around themes with embedded adware. Check it out and comment over there if you have an opinion, there is also a WordPress Idea on the matter.
NYC Meetup Update
Based on the comments on the last entry I think we’re going to kick off the April 11 meetup at Bryant Park at 6:30, and if needed migrate for drinks at 8 PM when the park closes to someplace like Heartland Brewery on West 43rd. How’s that sound to the New Yorkers in the audience? Update: Scott says “The northwest corner of the park is the most accessible (south of the Starbucks, east of the Verizon shop). Plus that’s where the coffee is.” That’s where we’ll meet. I’ll be in a beige overcoat and green shirt.