WordPress.org is officially dead

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • just a punk
    So fuckin' bored
    • Jun 2003
    • 32385

    #1

    WordPress.org is officially dead

    I mean as a platform for independent themes and plugins. You won't find any professional plugin or theme there anymore.

    By professional themes and plugins I mean those that made from professional webmasters who want to somehow insert HTML, CSS, JavaScript and PHP code into their WordPress posts, sites (e.g. sidebar, footer, header) etc.

    This is officially forbidden now and I've got an official confirmation on that.

    You may say: "that couldn't be true, because there is a ton op plugins like PHP anywhere are freely hosted at wordpress.org".

    Yes, they are. But not for a long time, so make sure to download them while they are not removed or not castrated on their functionality.

    Here is a quote from the official email, that explains the new WordPress.org policy on 3rd-party themes and plugins:

    We're saying IF your plugin allows people to insert arbitrary HTML/JS/etc, then it is not currently permitted for new plugins.

    We are actively working with the older plugins to retire them or improve them and make them safer.

    Since that's an ongoing process, and has been for a couple years, we've only closed a couple. We're trying not to break existing users, while still protecting them from what has become one of the biggest vectors for kiddie hackers

    --
    WordPress Plugin Review Team | [email protected]
    https://make.wordpress.org/plugins/
    https://developer.wordpress.org/plug...in-guidelines/
    Obey the Cowgod
  • Tube Ace
    So Fucking Banned
    • Nov 2008
    • 4941

    #2
    Time to fork WordPress?

    Comment

    • brassmonkey
      Pay It Forward
      • Sep 2005
      • 77386

      #3
      nope
      TRUMP 2026 KEKAW!!! - The Laken Riley Act Is Law!
      DACA ENDED - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com

      Comment

      • blackmonsters
        Making PHP work
        • Nov 2002
        • 21001

        #4
        Seems reasonable to me; unless I'm missing something.
        A post made by a random user should not contain any HTML/CSS/JS/PHP

        Security "101" it seems.

        Your neighbor will murder you with frogs
        Click here

        Comment

        • RyuLion
          • Mar 2003
          • 32365

          #5
          Originally posted by brassmonkey
          nope

          Adult Biz Consultant A tech head since 1995
          Affiliate Support: Chaturbate | CCBill Live

          Comment

          • zijlstravideo
            Confirmed User
            • Sep 2013
            • 806

            #6
            "What is HTML, CSS, JavaScript and PHP?" - 99% of WP users
            Contact: email

            Comment

            • just a punk
              So fuckin' bored
              • Jun 2003
              • 32385

              #7
              Originally posted by blackmonsters
              Seems reasonable to me; unless I'm missing something.
              A post made by a random user should not contain any HTML/CSS/JS/PHP

              Security "101" it seems.

              Not a page visitor. By a website owner. Like this: https://wordpress.org/plugins/php-everywhere/

              I have submitted this plugin: https://www.wpadinserter.com/ - read its documentation. It' just an ad inserting plugin (a quote): "The plugin works with all existing WordPress themes and supports all types of ads. Use any types of ads like including banners, popups, AdSense codes etc. Mix HTML, JavaScript and PHP in any manner."

              They said they don't accept those anymore, because some WP user may enter a wrong code, which will break his site or let other people to hack it.

              I asked how my ad plugin will work, if the site owner won't be able to use Google or Amazon ads that obviously contain HTML/CSS/JS?

              The answer I've got:

              IF you can find an acceptable alternative (like 'here are a list of ads we support, put in your custom IDs here...') we're happy to keep working on this.
              Is that clear enough now?

              P.S. How visitors may add something to a 3rd-party site? Only in comments, IMHO. How it could be relate to a plugin?

              ...
              A WordPress user - a person that uses WordPress engine at his site.
              A visitor - a random person who visits that site.
              Obey the Cowgod

              Comment

              • zijlstravideo
                Confirmed User
                • Sep 2013
                • 806

                #8
                Originally posted by CyberSEO
                They said they don't accept those anymore, because some WP user may enter a wrong code, which will break his site or let other people to hack it.
                At least they know their target audience really well, gotta give 'em credit for that.

                But yeah, I agree, even "banning" stuff like custom css or plain html to be inserted through plugins doesn't make much sense.

                Seems like they really want to put the focus back on being "the" blogging CMS for the "non-technical" audience. And to be honest, I don't really understand why anyone with technical skills would pick Wordpress over a much more lightweight, custom code anyway.
                Contact: email

                Comment

                • zijlstravideo
                  Confirmed User
                  • Sep 2013
                  • 806

                  #9
                  Also, those that are looking to install plugins such as "include PHP" or whatever, likely won't have any issues with manually downloading and uploading a zip file to their WP dashboard anyway.

                  In a way, I think it's just them saying - you can install plugins from a third party server but "use at your own risk". Now it's no longer their fault when some popular plugin turns out to have an exploit (which they already deemed "risky"). I think they just want to keep the Wordpress core as secure as possible for the average user and get rid of anything that may, even if it's slightly, could potentially cause some sort of risk.
                  Contact: email

                  Comment

                  • LaSexorcisto
                    Confirmed User
                    • Mar 2022
                    • 95

                    #10
                    Originally posted by CyberSEO
                    We're saying IF your plugin allows people to insert arbitrary HTML/JS/etc, then it is not currently permitted for new plugins.
                    Are you sure you're reading that correctly? It didn't say that your plugin couldn't natively insert HTML/JS/etc. It says you can't enable your end user to insert their own custom HTML/JS/etc.

                    Comment

                    • just a punk
                      So fuckin' bored
                      • Jun 2003
                      • 32385

                      #11
                      Originally posted by LaSexorcisto
                      Are you sure you're reading that correctly? It didn't say that your plugin couldn't natively insert HTML/JS/etc. It says you can't enable your end user to insert their own custom HTML/JS/etc.
                      My end user is a person who uses my plugin at his/her site. Why he can't insert HTML/JS/etc into his own site with my plugin?
                      Obey the Cowgod

                      Comment

                      • just a punk
                        So fuckin' bored
                        • Jun 2003
                        • 32385

                        #12
                        Originally posted by Tube Ace
                        Time to fork WordPress?
                        I have no problem with WordPress which is hands down a great product. I have a problem with wordpress.org and a bunch of arrogant hypocrites that moderate plugin submissions. They have no relation to the actual WordPress coders. I bet they hire 'em cheap somewhere in India...
                        Obey the Cowgod

                        Comment

                        • zijlstravideo
                          Confirmed User
                          • Sep 2013
                          • 806

                          #13
                          Originally posted by CyberSEO
                          My end user is a person who uses my plugin at his/her site. Why he can't insert HTML/JS/etc into his own site with my plugin?
                          What about this quote you posted:
                          IF you can find an acceptable alternative (like 'here are a list of ads we support, put in your custom IDs here...') we're happy to keep working on this.
                          This suggests that you are allowed to, for example, add a form where the user can enter his partner ID for whatever affiliate program.

                          Then you can sanitize that ID, and safely insert the ID into the rest of the banner code.

                          Perhaps I'm wrong but it looks as if they only disallow end-users to insert any code themselves (probably due to security risk when there's an exploit, as anyone would now be able to insert any evil javascript or PHP code he wants).

                          However, when you only allow the user to insert his partner ID through a form, the plugin can first sanitize that input (the partner ID), before including it into the final code (non-editable) and finally embed the output on page, thus eliminating the risk of "evil code".

                          For example, a form where users can submit:
                          - an affiliate url
                          - the link to media file (for the banner)
                          I think, would be totally fine, because you can then sanitize and validate both user input, before including it into the final <a href='ÚSER INPUT 1'><img src='USER INPUT 2'></a> code, which then gets injected on page etc.

                          Might not be what you were trying to build exactly, but I kinda get it from a security stand point. I mean, what if the user ends up using your plugin (allowing code to be inserted without sanitizing it) in combination with some sort of heavily outdated theme, full of XSS holes?
                          Contact: email

                          Comment

                          • just a punk
                            So fuckin' bored
                            • Jun 2003
                            • 32385

                            #14
                            Originally posted by zijlstravideo
                            This suggests that you are allowed to, for example, add a form where the user can enter his partner ID for whatever affiliate program.
                            Who will use such a plugin then? E.g. you (as an adult webmaster) want to display a chaturbate chatroom code. How will you do it? What if it will be say some JS for an ad popup window?

                            I don't want to release a useless nonsense. I want to release a quality product and it will be released. At my own site. For free.
                            Obey the Cowgod

                            Comment

                            • just a punk
                              So fuckin' bored
                              • Jun 2003
                              • 32385

                              #15
                              I ended up publishing my plugin here: https://www.wpadinserter.com/

                              Download it, try it and let me know if you'll find any bugs (they should be there and I always open for any suggestions.
                              Obey the Cowgod

                              Comment

                              • NoWhErE
                                Too lazy to set a custom title
                                • Sep 2005
                                • 10583

                                #16
                                Originally posted by CyberSEO
                                Who will use such a plugin then? E.g. you (as an adult webmaster) want to display a chaturbate chatroom code. How will you do it? What if it will be say some JS for an ad popup window?

                                I don't want to release a useless nonsense. I want to release a quality product and it will be released. At my own site. For free.
                                You would need to offer ad templates from chaturbate. The site owner would then enter their chaturbate ID in a form and pick whatever options you allow him to do.

                                From what I understand, Wordpress is trying to tighten security around themes and plugins by not allowing end-users the option to add their own code. I assume this is because it's the most common form of attack Wordpress experiences.

                                I'm not saying it's a good move on their part. I don't agree with their decision. This is what I assume their intention is.
                                skype: lordofthecameltoe

                                Comment

                                Working...