Pain Points of Web Development with WordPress
medium.com
medium.com
I've found there are various gradations of WordPress developer and the "pro" guys are a very competent and very pragmatic bunch.
- Most "pro" guys limit the number of plugins they use.
- They use ansible or similar for provisioning and deployment.
- They use sane theme frameworks like sage, timber or stem.
- They know how to do caching without using clunky caching plugins
- They try to adhere to 12-factor where possible
- They do their own devops
I mainly consider myself an iOS/Cocoa developer but I do my fair share of web development including WordPress. I even sell a pretty technical WordPress plugin (https://mediacloud.press). I don't recommend or choose WordPress because it's a great platform, but because it can be a solid pragmatic choice considering all things like time and budget and client experience.
But for the average joe, it sure provides plenty of ways to shoot yourself in the face. That said, what other options exist for them if Wix isn't enough?
No doubt there are pros who do it the way you described, but what percent of WP installations do you think are managed by people like that?
There are many developers more skilled than "average joe" but below the level you describe, and they have plenty of other options: https://headlesscms.org
The other day I saw a ms-excel to webpage builder shared on news.yc voted to the front-page, there's also a google-sheets to app builder that did YC last year... I wonder if there's a market for notepad / word / docs to webpages, too? This article makes it seem like there might be one.
I personally use https://1mb.site for simple pages, but it still isn't easy to use.
Themes, yes, that's valid, they can be constraining. So is buying the wrong type of automobile. Deal with it.
Wordpress is PHP (and html/css/js/etc)and SQL. WP does not inherently do staging, so you set up a dev environment. You sync content from prod to dev, make code tests on dev, then copy them to prod. It's not hard.
> works fine on simpler sites [...] but it is not production-ready yet
Or, and maybe I'm being crazy here: don't use Wordpress if all you need is a static site?
I've written database diffing and bulk replace tools just to make this simpler and I still have ways to go before it becomes anywhere near sane.
I honestly think WordPress has cognitohazardous effects on developers, after enough exposure you start normalising the most insane development practises.
but... that seems to be any WP tool that is popular. Many of the WP ecosystem stuff I've seen is popular precisely because it's not maintainable.
[1]: https://kinsta.com/wp-content/uploads/2018/12/wordpress-5.0-... [2]: https://kinsta.com/wp-content/uploads/2018/12/wordpress-5.0-...
Falling 2, or even 1 release behind makes maintenance a nightmare.
I also explain to people that even though WP and WC are free, and very easy to install/setup, you're essentially running your own ecommerce software platform, and are on the hook for maintenance and any problems (security/scaling etc.) whereas hosted platforms like Shopify take a lot of that off your plate.
Because as questionable as it may be resources wise, well it compares pretty well to the likes of OpenCart or OS Commerce, and significantly better than other WordPress shop plugins I've seen in the past (like Shopp). At least you can take your WordPress development knowledge and apply it to templates/plugins, have some decent documentation lying around to fall back on, and don't have plugin developers trying to nickle and dime you for every little thing.
There's probably a market in there somewhere, if someone wanted to actually create a decent ecommerce system that doesn't require a ton of resources, doesn't rely on another system to function and whose community actually knows what the hell they're doing.
I've seen many customers struggle with it and move to Hybris or Magento.
Hybris has a very good comprehensive and stable and extendable ecommerce solution. The only downside is its from SAP and not open source, which might not be bad for a medium sized to big ecommerce shop.
Unless you have a very large set of products, in which case Wordpress grinds to a halt.
Unless, of course, you find the magic plugins that don't update product counts on every update... or figure out how to hook into the system and override it myself.
I meant to write up a blog post about this, but honestly, once the problem was solved, I had very little interest into peeling up that particular bandage to poke around underneath.
All in all, it downgraded the Wordpress development experience from a hell to a heck. It was still unpleasant, and we still had a lot of pain points, but it did solve problem #3. (Although, I do have some other issues with Pantheon as well, but they're largely orthogonal to Wordpress proper.)
I'm a fan and a customer of https://www.hardypress.com/ –– they run Wordpress in a sandboxed environment, and have a "publish" function that exports a static site.
Of course that limits what you can build – for example, you would need to use 3rd party services for blog comments and for contact forms – but for many use cases that's OK.
There is also the "Simply Static" Wordpress plugin that can export a static site.
How fast is the exporting , for a big site(thousands of pages)?
Nor will the attack surface issue to be as much of an issue for similar reasons.
Similarly, most longtime devs will code their own WordPress themes for every project (or use a framework they developed themselves), and have things like local versions of sites as everyday procedure.
This isn't a large company and WordPress guru thing. It's an 'anyone who's worked with WordPress on a more technical level for more than a year or so' thing. Web development and marketing agencies do this, freelancers do this, startups do this and individuals running their own sites often do this too.
Hell, it's what I do for all my own projects.
So yeah, it's not really about pain points developing with WordPress. It's about pain points from people installing WordPress + themes and plugins who aren't skilled at developing for the system yet, or who are mostly non technical and relying on premade resources.
Someone submitted article about Wordpress alternatives like an hour ago
For me the only issue with Wordpress is the security problems
Using wordfence atm
It's a little clunkier but I can ignore the endless CVEs wordpress generates.
So I'm looking for a solution.
Did WPEngine solved all of your security issues ?
What kind of expertise does it require , how does the process of using it looks ?
Drupal's abstraction layer is what keeps it secure. You also can restrict permissions granularity, and it's core functionality does most of what you need to create a simple site.
Administration menus don't change with themes chosen (unless you specify it to). If you have a high traffic site, you can simply use cloud flare, or system caching, or pay for higher tier services like Akamai.
I'm not an evangelist for Drupal though, it's not meant to fit every case, so I'll just leave it at that.
* non-validated user input from ad-hoc code * not being up to date * plugins not being up to date * plugins not being understood, malicious code (eval, header manipulation and so on) * unsanitized output (wp offers sanitization for common types but you have to use it explicitly) * code being accessible that shouldn't be * users (clients) having too many capabilities
No. Because I'm paranoid and have been hacked before, I still apply additional "hardening" to WordPress. We use various plugins, and Cloudflare to further enhance our client's security.
However hosting with WPE had allowed me to sleep at night, whereas previously I was constantly worried about performance and security of our VPS/dedicated boxes. I'm not a server admin, and if more webmasters were honest with themselves they'd admit that too. WPEngine takes care of running the infrastructure and I can focus on design and building great websites.
The reason I still host and advocate for WPE is the quality support. It is by far the best hosting support I've ever worked with. I have other beefs with WPEngine (for another time) but am happy to continue working with them - never going back to a "VPS" model.
But, if something like TypeRocket was added into WP core, I believe, the plugin ecosystem of WP would greatly improve moving forward.
These frameworks not only add MVC into WP but they also provide a common interface to create plugins. These common interfaces can be a simple as input fields with model binding but also extends to interactive HTML tables with model binding and OOP and autoloading and dependency injection and IOC and so much more.
I get that WP is trying to move toward JS and Guten-Blocks at the moment but the neglect of MVC and adding a common interface causes me to wonder what WP is really trying to do.
It seems like an easy win to add something like TypeRocket to WP core. And, the benefits: a proper layer of security built into forms, unified design athstetic in the WP admin, plugin interoperability, huge reduction in code bloat and plugin hell, and the list continues.