There's a reason WP has withstood the test of time. (WordPress developers being a dime a dozen also help make the case)
There's a reason WP has withstood the test of time. (WordPress developers being a dime a dozen also help make the case)
And its also really easy for it to be left without updates or security patches, with an insecure admin account password, and with a set of plugins that open up more security problems.
It might be a bit harder to get up and running with a static site generator but the fact that it's essentially unhackable (through the site itself; the host server has the same issues as any website) is a massive advantage.
The plugin issue is not specific to WordPress.
The fact that other platforms and applications are insecure isn't relevant; we're comparing static sites to WordPress.
However, to answer the point, static sites are significantly more secure than every single dynamic platform that supports a plugin architecture because plugins can be, and often are, written without security in mind.
Unless you really need a dynamic website you should be deploying static assets to the enduser. Practically every business website would be better off being delivered as a static site, even if the admin still use WordPress to edit the content.
> It might be a bit harder to get up and running with a static site generator but the fact that it's essentially unhackable
You could also use WordPress to generate a static site, just add a caching level on top.
JAMstack sites are annoying to build, so much minutiae and configuration, abstractions on top of abstractions, and you never own the codebase as it's frameworks and libraries all the way down. You spend half your time trying to figure out if X could work with Y, rather than just making X do Y's job by writing some actual code for a change.
Frameworks and libraries aren't really necessary for JAMstack. JAMstack really just means relying on external services for dynamic content. You don't have to use Gatsby or Hugo or whatever. A JAMstack site can be a single HTML page with a script tag (and all mine usually are).
I built my own static site generator and I feel so much more ownership over the code. You should try it. Not only is it my code all the way down, but it only runs on my machine. All the generated assets will remain functional and security bug free as long as browsers understand HTML, CSS and JS, even if I never update the code again.
what is the implication of such a trademark? can unaffiliated companies not use the term now? this is a little surprising.
Or all of the above. And that might be a good enough reason, but to imply it's the best technical option warrants some skepticism.
Not to mention things little security issues.
I don't have an agenda against WordPress and very often when people ask me what they should use for simple projects I say "just use WordPress."
My rule of thumb is that will probably be alright for a simple, small project, but will have to grow up to something else to scale reasonably.
WordPress essentially generates static pages and is trivially set-up to run behind a CDN like Cloudflare.
You can easily have WordPress sites in the Alexa top 50k that run on a $5 VPS - behind Cloudflare.
> My rule of thumb is that will probably be alright for a simple, small project,
Right. Simple, small projects. Like whitehouse.gov.
As long as you use Wordpress for what it was designed for, it really doesn't matter what scale you have.
Check out Cloudflare's Automatic Platform Optimization tool from last year [0]. It uses Workers to cache static and dynamic content from WordPress on the edge. Just $5/month.
IMHO, that would "scale reasonably" for many use cases.
[0] https://blog.cloudflare.com/automatic-platform-optimizations...
It's an expensive compromise that you shouldn't need unless you're in Alexa top 100 territory.
Not a snarky or leading question, I honestly don’t know. I use Hugo for my own internal design things, because I want partials and such, but I have no idea where the ecosystem is at for the “we need a poli-sci intern to copyedit this” use case.
Used be that we had writers, editors, type setters, printers and book-binders, and I think the output was more professional.
I think there’s still a case for the non-technical users just writing the words, and keeping away from the presentation and delivery.
- continuously serialize WP to static files
- Make it easier to work with Wordpress as a CRM (No Code or at the very least don't force developers to touch PHP)
JAM stack would near instantly cease to make any business sense (though developers would still love using it of course).
A lot of the issues with Wordpress are sort of long-tail -- combinations of plugins exposing leaks in the abstractions, etc.
BTW, if anyone is working on solving this, I'd love to know about it.
Any cache plugin for WordPress does this already, but if you mean something that does this in order to host elsewhere (like in Netlify), WP2Static is a solution.
Do some cache plugins actively walk your site and generate the pages? How do they handle when user login plugins are present? I'd expect a naive/basic caching plugin to add to the cache when a page was visited, not necessarily ahead of time.