WordPress 18
ma.tt
ma.tt
The thing is, of course you can fk this up. Install Wordpress on crap hosting, install 100 plugins, fail to keep them updated - things are going to go badly. But now think about what happens if you do the same with literally any bit of software, even the hip jamstack stuff doing the rounds right now.
There is good. There is bad. There are people who claim they “do Wordpress” when in fact they can just install plugins and a builder theme. There are people who do it well, with good deployment, repo management, backups, updates.
But the end thing is always the same. Your site owners / editors just want something flexible where they can make content changes. They want familiar. They want flexible.
There are times when Wordpress is the wrong solution. There are bad ways of doing it. But, really, you can’t argue with 40% of the web.
So yeh, I take your point, but it's the peripheral stuff that makes this important IMO.
Do you buy the best dishwasher or do you buy the good enough one?
You're allowed to dislike it, but for me windows 10 is a great OS with a thin removable layer of crap sprayed on top, and more importantly it's just the right balance between osx and linux.
To each his own, but you shouldn't be making such generalizations, especially in a message telling people not to make generalizations.
But! My company's website runs on WP nonetheless, mainly because I don't want to spend time on creating a website when I could work on our product. WP allows my less technical employees to tinker with the website and the marketing oriented folks to do whatever marketing oriented folks do.
It runs conveniently on its own isolated VM where people can bikeshed it all day long. If your website is not your primary product, I don't see the point in writing your own stuff unless you got some leftover time you're willing to sacrifice to write it in.
I've had customers using WP in the past, and defacement was just part of the routine. It's an annoyance for the business owner for sure, but so are personnel issues, finance, legislation changes, etc.
For most businesses, there are more important issues than having a perfectly optimised and hardened website.
WP, as bad as it is, is 'good enough' for most websites.
Which, as I say, is the same for Every Bit Of Software Ever.
Like, consider this: your friends PC gets hacked and he loses everything. Turns out they were running ‘doze 95 and had failed to update or backup. Where is your sympathy? Right, you’re thinking “you’re a fool!”. And you’re right. They failed to look after their stuff, and it created a problem.
Why is this any different with WordPress?
Do it well, and the “security for Wordpress is pretty bad” trope just goes away.
But... we started this thread with 'WordPress isn't for you, the alternative isn't a static site and a CI pipeline', so it's supposed to be for people who don't know what they're doing, often do use $50 a year hosting that comes with 'cPanel', keep installing different plugins until one kind of does what they want and then leave all the others, and never update anything until something breaks/they want something new and they start installing plugins again.
But, then I look at my neighborhood and the 1,000 small-business WordPress sites, with blogs that have been abandoned in 2015, should be one-pagers and not seen an update since because their owners don't understand WordPress and also can't afford to pay someone for every small change and now they think the whole Internet is like that (40% as you say), and changing that is going to be one hell of an uphill battle.
I don't have to hate WordPress or knock their efforts to see ways to improve things with more modern approaches.
Or, if you send me a message via the contact form and tick 'submit', you can sign up to our newsletter at the same time.
I'll split that out into a separate newsletter signup in the next few days.
Thanks so much for the kind words, much appreciated!
That's not a failing of WordPress. That's:
1. A failure of how the business owner just couldn't be bothered. Wordpress, Wix, Squarespace, there's a fairly good chance they'd fail at all of these. They won't pay for the design, marketing etc etc, and the reason why?
2. their business doesn't need a website e.g. local plumber or the only game in town for a specific vertical.
3. They're on their local Facebook groups and don't need anything more.
These folks also abandoned Yellow pages, Thomsons etc years ago but yet they survive through word of mouth. The internet and these other marketing services can't compete with that (especially outside certain confined bubbles). The local plumbing and heating guy in my area gets on fine without all the paraphernalia of "being on the web", as do all other trades.
Not everyone needs a "website", especially if they've a well developed funnel of incoming business that, by now in 2021, they still get on ok without needing to be internetized.
What does get these folks business without websites is other folks recommending them "on the internet", via local Facebook groups or whatever. Why would you waste time having a website when FB funnels the business to you, it's already job done.
It's almost like HN has a large community of people who find setting up a static site simple and would find the technical constraints of WordPress offensive. People for whom WordPress is the wrong solution.
So now the question is - what should those people say about WordPress? Obviously they have no reason to praise it, so they will damn it, if you say they should not damn it because it is not for them then this raises that old HN question - why is this here? It's here because it would be of interest to Hackers, but it seems hackers would be the people most likely to dislike it.
It's here for the 15 minutes hate.
Most likely, but Hackers Spirit for me is also finding the right tool, for the right job.
Meaning for me, I allmost use vanilla JS and html only, because that way everything is under my control behaving exactly like I want it.
But I clearly see, that other people need a more convienient tool, to enable them to get things done, with their skillset. Why should I hate that?
Oh, but about hate - I really do hate PHP, so I could probably chime in with the choir.
But I know my hate comes from having to take over a half finished webproject, long ago, with badly written PHP and I was new to it. I never touched PHP ever since ... but I am aware, that other people get stuff done with it, so good for them.
that's been a combination of my experiences with pretty much every other tech as well.
I've done php, java, perl, python, javascript ruby, asp and poked at a small cold fusion project over the last 20+ years. Every one of those had baffling parts which, after some time, and after reviewing it with people far more proficient than me in that target stack, I learned it was "crap code". "Yeah, they didn't know what they were doing." "That's n00b code." "Garbage. How did they get hired?"
I've also seen some good 'clean' projects in some languages, but not as many. I guess I can not, for the life of me, figure out how someone looks at some bad PHP projects and writes off the entire language, yet if I do the about Python, for example, I'm somehow close-minded, or a n00b, or... "just not ready for it yet" or... something. Have had conversations like this at tech conferences (back when those were a thing!). Seems like projection going on, but maybe there's something more.
FWIW, it's often not specifically the language itself which is a stumbling block, but the entire ecosystem around a stack. If there's not a good, usable patterns and tools for easy testing, or integration between FE/BE, etc, I don't care how "tight" or "sleek" or "elegant" a specific language is; it's going to be a pain to deliver a full project with.
And since I care about that and there were alternatives - yes, I just wrote off PHP entirely ;)
After you've worked with perl for years, none of those sorts of criticisms against PHP seem to hold any water with me. ;)
The comparable replacement for Wordpress isn't a static site but something like Ghost: https://ghost.org/
But it is outdated and I offered a better alternative as an example of why Wordpress receives so many negative reactions at this point.
Are you aware WooCommerce is an ecosystem in itself?
Yeah I do do this.. for my personal site. If I did this for a client then they wouldn't be a client haha
The problem I see is that, in many instances, WP is pushed by dodgy developers running a template for what is a static site. This is easily the case for 90%+ of the small business sites I see. Many are never changed.
WordPress is a much larger attack surface than static hosting. There are fairly obvious ways of automating using WordPress to generate a static site that will be faster and more secure. I believe this is generally referred to as headless WordPress. Why does this not happen more – or do I just not see it when it does?
"Can you put our holidays on the main page?", "Can you adapt this text?", "We have a new image of our main shop, can you update it?", ...
I've seen plenty of people building a website for someone and thinking they made good money, but after all the requests that come afterwards, it's not worth the time.
These consultancies strike the right balance in terms of knowing their product, managing expectations, and knowing when to say "no".
It's created lots of jobs in South Africa for what that's worth. Can't speak for other countries.
WooCommerce began as a plugin by a wordpress theme company in South Africa (WooThemes). And then they were aquired by WP/Automattic in ~2015. A really cool case of pivoting.
imho the best part of WP is the dashboard stuff, so headless WP is a good choice. It's also frequently hurt by PHP's heavy push on inheritance, which can be at-odds with what is actually a very good events-based architecture in WP. Sad part is that the very good events-based architecture is so overlooked, most people who have spent time developing in WP aren't even aware it has events.
That's IMO just a wrong understanding of the average business owner. Wordpress is much more useful to web agencies with the necessary skill set to heavily customise it than to the average Joe SMB Owner.
To them, Wordpress is just as much a black box as Wix or Squarespace is, and all the web agencies using Wordpress to make websites for that demographic modify it so much with so many mutually exclusive plugin pipelines that getting their website from one to another often involves a complete rewrite anyway, if you want meaningful changes done.
And for a long time, it was just the cost of doing business. But now? Nowadays, Squarespace et al. are probably a much better fit for them. Effectively the same vendor lock in if you're not a web agency yourself, but with much less overhead involved.
That’s why I’ve completely changed my position on who should be using what tech to build sites. There is no one-size-fits-all solution.
I now recommend clients three options, based on the type of business:
1) If they’re a local small business (eg. Restaurant, flower shop) or solo creative business like a photographer or videographer, just do Squarespace. Wordpress is way too complex for their needs and they will easily shoot themselves in the foot.
2) If it’s a Saas company, tech startup, design agency, or enterprise, I strongly strongly recommend Webflow for their marketing site even though they think they want JAMstack. When the marketing team starts pulling dev time to redesign parts of the site every week, they immediately will regret the JAMstack decision.
3) if it’s a media/content business, always go Wordpress. Their employees will already be familiar with it, and the collaborative editing and SEO experience cannot be beat for publishing content on a daily basis. Combine this with plugins for newsletters and social integrations and the extra hassle of Wordpress is worth it for them.
* Only one person can edit code at a time - this caused us to have to split who was doing what and we even ended up losing work when someone overwrote someone elses changes https://wishlist.webflow.com/ideas/WEBFLOW-I-39 (this goes back to 2017)
* Tracking changes in VCS easily (https://wishlist.webflow.com/ideas/WEBFLOW-I-381) another from 2017, we tried out flowgater though in the end have just settled for exporting the code as is and then just committing it by hand.
* A max limit of 10k characters (edit - as pointed out in comment, that's per file, I think IIRC we had all our JS in one single place which is how we hit this our side) in site code (https://forum.webflow.com/t/embed-html-10-000-characters/443...) - this caught us on doing some embedding, we worked around it in the end and not a massive deal but still felt a little annoying having to work around it.
For example, I work with a Saas company that has their designer throw together landing pages for competitor comparisons and integrations in like a day, and they change them weekly based on testing.
You just can’t do that on Wordpress at that speed without making a mess with heavy plugins and bloat.
There are sure builders that are as good as Webflow, but without losing WP power
A brief investigation says it's 10K characters per file, but still how the hell does a web site enforce that? Sure seems arbitrary and silly.
Absolutely. Unfortunately, tools create confirmation bias, and given WP's market share those voices are collectively the loudest.
The point being, the general perception is WP is *always* the solution for *every* need. And Automattic and other leaders with the WP "community" don't make much of an effort to change that.
I like WP. I use WP. ButI find the one size fits all attitude very annoying and ethically suspect.
We still use wordpress occasionally, but no longer for those customers.
This (with a slight modification).
I built websites back in the Web 1.0 days. I know how to use HTML, CSS and a bit of javascript. When I needed to build a "brochure" site for my professional services business, I could have done it from scratch, I could have waded into the convoluted and plug-in dependent mess that is WP, or I could go to a simple tool like Squarespace or Wix. I am capable of learning anything I needed, but the real question is: when I need to update a page, do I want to relearn all that stuff I forgot because it isn't my day job?
When comparing Squarespace to Wix, I realized that Squarespace doesn't have backup and restore capability. That is a mindblowingly huge hole to me. So I went with Wix. Yes, I am "locked in" to Wix. If I wanted to go to another solution, I could pay someone pennies to replicate my existing site.
Contrast to my experience with WP. I inherited a WP site with the non-profit I work with. I ended up getting them to pay godaddy to manage the site and the SSL because I don't have the time to deal with it. I dread the day when the next WP upgrade breaks the janky WSIWG plug-in (elementor I think), which already doesn't work properly on one of the pages, so I have to edit the HTML. As soon as our long contract with godaddy expires, I am paying someone to replicate the site in Wix.
Like you pointed out in #3 above, I guess there are some applicable use cases for WP, but anyone who doesn't need more than a brochure site is ill served by that choice.
Yeeeah but no. Companies (especially those ones) can have plenty of good reasons to need more control / custom code / integrations / etc. I think a lot of people don't realize how crippling and limiting committing to Webflow can be, and how much you end up hacking around it. Raises hand
https://www.plasmic.app gives you the same (actually, a FAR better) visual editor that plugs into whatever codebase you want. More people need to know about them.
Using Plasmic + JAMstack on a marketing site would be the worst of both worlds IMO. All the static site hassles with none of the stuff that makes static sites fun for me.
It gives design and marketing the ability to edit landing pages, but they still have to bug the engineers for bigger changes to the site structure.
The biggest advantage to Webflow is its super versatile CMS, and separate simplified editor for content teams. Our engineering team literally never has to touch anything on our main domain. Marketing/Design completely owns it. Our engineers focus entirely on our product.
Like all developer-centric tools coming out of the JAMstack ecosystem, Plasmic seems to ignore the existence of content marketing and SEO (Wordpress's writing experience and friendliness for non-devs is why they won the internet), which is the entire point of having a marketing site in the first place.
Just wanted to share that our main use case actually has been for marketing sites (apps are a minority) and giving content editors autonomy. We do spend a lot of time on page performance, SEO concerns, etc.
Publishing new pages and other site structure changes (and even publishing new sites) does not actually require bugging engineers. Letting marketers/designers own the site and freeing up developers is our entire focus.
We are also working on a simplified content editing mode that restricts design changes.
Appreciate your following along with our progress, and hope we can continue hearing your feedback - that's how we make the product better for you.
Also agree re: lock-in. This is actually improving somewhat with Gutenberg, but transferring data from a WordPress site to another platform is still usually going to be a giant pain in the butt unless your content is extremely simple - no metadata, widgets, forms, custom blocks, etc.
To be fair, every time there is a WP post on HN, there is also always the inevitable comment complaining about the "haters" and to just think of the "business owners" tangent.
Then there is my comment - now it is like the movie inception :P
It would be nice if we all just used those tools/software that works for us and simply ignore the rest.
What are the best resources that describe how to "do it well" in Wordpress? I've made several attempts to google, but due to the enormous popularity of Wordpress, and the low technical level of most of the users, the signal-to-noise ratio is incredibly poor.
At the end of the day, regardless of other usability and adoption merits, it’s just a really poorly designed architecture.
Of course that would be ideal development-wise. Business-wise, I doubt most agencies or small teams are going to rewrite W3 Total Cache, Yoast, WooCommerce, Elementor, ACF, Gravity Forms and all the top popular plugins... not to mention all the battle-tested security options.
It puts too much of a burden on the site owner from a security perspective.
Quite frankly, Wordpress leaks like a sieve. I wish this wasn't true because it is really one of the best/most accessible CMSs around. If they fix the security issues, it would just be wonderful.
Wordpress is pretty secure but putting everything in a shared hosting with lax security like dreamhost or hostgator et al its asking for trouble.
I have many wordpress sites, some large, some small, and only 1 was ever hacked and it was on a shared host 10+ years ago. Today I have sites that I haven't updated in 5+ years, no hacks no problems. Good wp depends on good server config and good wp setup.
This is because WordPress is the equivalent of PHP. Sure it can do the job but there's a very big BUT in there, always.
And no, I don't use it either.
The only reason I switched to Hugo is because I wanted custom domain + javascript (for adding some embeds that wordpress doesn't support by default), and I didn't want to pay 8 bucks (I think 10 CAD) for that on .com, and didn't want the hassle to host on Amazon anymore.
But I surely miss being able to have all my drafts available everywhere, and publish with the click of a button.
EDIT: I also miss that all other bloggers from my circle except another one, all use wordpress, and follow each other on the wordpress reader, and comment using wordpress comments. I'm likely missing a good chunk of views and comments because of that
I'm attracted by static site generators essentially because I like the idea that no dynamic code is run when the website is visited, but WordPress almost gets you there after the first visit. Plus, you don't have to regenerate the whole website for each change, WordPress generates pages "lazily". So, maybe WordPress can be lighter in some cases than a statically generated website when considering everything if setup this way? It still requires a potentially stronger server than when everything is static.
edit: For Wordpress only install reputable, necessary plugins. Turn on auto-update. Keep backups. Things should be just fine. Now you aren't locked into a single platform and you can extend your website as much as needed (unlike Squarespace/Wix which severely limit what you can do).
Having been paid quite well to migrate to and from WordPress, and to help maintain the WP sites of major publishers, I have to say that this is questionable advice. In most cases in my experience, the publisher has employed third-party providers (at huge cost) to develop frameworks and custom plugins that can easily be broken by automatic updates.
Updates need evaluation and testing in staging sites before they can be rolled out. For publishers, the first install of WP is free - everything after that costs plenty.
'Make sure you keep everything updated!' has a ton of caveats and pitfalls, that's just the reality.
Btw, I'm a senior full stack software engineer. But for my digital media business I operate several Wordpress websites. I don't talk to any Wordpress devs and do any custom Wordpress theme or plugin development (aside from what is available in the GUI and extremely minor CSS tweaks).
https://krebsonsecurity.com/2021/05/using-fake-reviews-to-fi...
Wix and alikes are proprietary software, that lock in users on their services, have limited customization options, don't allow you to edit code and have little to no export options.
Whoever pays someone else to have it's website built on wix or alikes is getting a very bad deal, due to the above mentioned restrictions (compared to WP) they'll end up very dissatisfied in few years if things go well (meaning more traffic and more needs).
Source: experience. As a developer I feel the frustration coding for WP, but at the same time it's the best compromise to provide a CMS that the average user can manage
Step 2 is difficult to even define properly. What is a plugin supposed to be able to do, and what is a plugin supposed to not be able to do? If you can answer that question precisely, then you can solve the problem, but if you can answer that question precisely then you probably don't need plugins in the first place.
If you are building a simple brochure website, none of this matters.
i set up my first real blog over a decade ago. i picked wordpress, because that seems to be the default, and i didn't know any better. oh my god, i hated maintaining that thing so, so much. it pretty much killed my desire to blog, as a matter of fact.
i recently started another blog, and this time i used a static site generator. i wouldn't recommend such a thing for non-technical people, but if you are willing to get your hands a little bit dirty, it is a hell of a lot easier to fix than wordpress ever was.
Plus: what headaches? Do it well, keep it updated ( uh, yeh, like literally ALL the software, ever ) and it’ll work flawlessly for years.
And you know what I have learned by talking to these businesses? It's that WordPress is still not easy enough to use for non techy people.
Nobody wants to touch their website, out of fear of doing something wrong. So they have to go pay someone to do it every time.
I'm running pinkpigeon.co.uk, which tries to actually make websites easy enough to use for everyone. But I am actually running into a problem where people expect all websites to be like WordPress and the first thing you hear is "oh I don't want to learn another thing". It's only when I show them the system, that they go "oh wow, that really is a lot easier". The problem is trying to convince anyone of this remotely via the Internet. Much easier to do in person.
I have the utmost respect for WordPress and used it much myself, but at the moment it's challenging to have to be compared against it when simpler solutions exist.
Not sure if suitable WYIWYG editors are still around, or if Word exports to HTML have become usable.
I doubt there is beauty to be found.
And websites are a lot about beauty.
Nope
How often does a construction/handyman "online flyer" webpage need a change? Once a year, maybe. The primary point I am trying to make is that websites of a lot of small business (obviously ones that are not webshops) serve more or less static content and therefore have no need for a backend at all.
You have a food blog where you publish recipes/reviews daily? Surely a blogging platform is a much better fit for you. You have a restaurant page where you publish contacts, coordinates and a menu which changes every second year? Well, maybe a static site generator is a better fit.
Those are just some examples that with Wordpress, it's a click and pretty much plug and play. With the static site generator you're proposing, you quickly need to do coding yourself.
Why do you need a backend for GA or image gallery?
If that is a photo-sharing website, then yes, proper backend is needed. But for a portfolio website of a photographer, which gets updated once a month at best, static manifest will work wonders.
The frontend code which eventually renders the image gallery does not care whether fetched image list is produced by PHP code or is served by http server directly from filesystem.
I can't tell if u missed a /s or genuinely think that isn't additional dev.
My business requires a what now?
“Say what now? Where do I login to update a photo on the site?”
In short everything has to be continuous, otherwise you'll stall and die. Now go buy some CI/CD from the shop.
[1] wikipedia
What most people want is to have something that works, where they can focus on their content and not on your tools. Wordpress works for people.
If they get a CI/CD pipeline maintained by someone, how do they create pages, get updates, fix those pesky security issues, write a blog post on their mac that when saved automatically gets posted? How easy is it to apply a theme to your CI/CD pipeline? Your tools work for you, but are you going to maintain them with the same level of features as Wordpress?
Oops, it's holiday time, will you write a greeting card plugin for your CI/CD pipeline for them to purchase cards on their website and send site-specific cards to their email list by Monday? No? Sorry, they just switched off of your CI/CD pipeline to Wordpress.
When moving to a different hosting provider, people want to conduct business not learn a to use a new CI/CD pipeline to match the tools at the new hosting company.
What about when you get tired of updating their site generator code for them? They will need to start over, and they won't pick another CI/CD tool that's unmaintained and is expected to get horribly outdated after a year.
People go into business in order to conduct business.
Wordpress has 1 click install for all those things as plugins (or work out-of-the-box)
Static site generators are bad for dynamic websites, but that does not mean you have to try and fit a whole dynamic platform into a static website. Different use cases, different tools.
And, that's false. Unless you make them run one of your restricted platforms that doesn't have the features they want and need for their business.
Wordpress runs 60% of CMS websites. 15% of the most viewed websites run Wordpress.
> You only need to worry about security issues if you build such a site on top of a dynamic platform.
Do you actually believe that there are no security issues with static websites?
Thank you for the conversation, but I'm going back to running my business.
i think it's a mistake to believe that this is a problem to be solved, or that the reason people don't want to touch their website is just a "fear of doing something wrong". it's not a question of how easy the admin panel is to use - the vast network of people willing to handle wordpress sites is a feature of wordpress. a business owner doesn't want to deal with their website, they want to pay somebody else to do it for them. tech people like self-serve solutions that they can log in and administer themselves, but there's a whole lot of people who really don't want that - they want to just call somebody up, explain what they want, and have it taken care of. the reason wordpress runs 40% of the internet is because it delivers that experience.
Why would a software engineer hate Craigslist? It's one of the most streamlined, responsive web sites I interact with on a regular basis. No third party scripts. It's built to purpose and it works very well without any fuss.
I suppose I have some minor gripes - with noscript it looks awful and they killed off their RSS feeds a while back. But hardly enough to inspire hate!
Technically he subtly shifted from supporting free software to open source. Just pointing that out, not making a big deal about terminology or anything as WP is still GPL'ed.
And the whole blogging community was so great, people exchange links not for SEO, but from appreciation of content or styles.
I handled the performance drawbacks with best hardware, cache etc.
I even accepted the premium for above activities. But random database errors was the final nail in the coffin.
After a decade of WP usage, I have ditched it for good. My current web stack for the past 2 years has been -
Simple websites- Vanilla HTML, CSS, JS.
Blogs - Hugo.
Complex Web Applications with CMS - Custom Go framework.
I understand that none of the above is applicable to someone who doesn't have web-development experience, Even in that case website-builiders[1] are a better option than WP. At this point, the only reason I'm not nuclear on WP is because I believe there's a thriving economy based on WP especially from developing countries.
[1]https://startuptoolchain.com/#website-builders (Disclaimer: Mine).
a lot of digital marketing/service company use WP to quickly setup a website for their client. my current employer's website is a WP site build by a third party.
Good for that 'digital marketing/service company', But there are better options for your employer in terms of cost/performance/security; Better options have been available for over past 5 years.
Of course website-builders do come with the caveats of vendor locking, But then again the typical relationship between 'digital marketing/service company' and the client mentioned in the parent comment is often much worse.
company tend to see company's website as part of marketing thus marketing dept usually have the final say and they tend to go with what digital marketing/service company recommended.
edit: not sure if that's a blessing but at least I don't have to deal with marketing people going over some small details like color...etc. the website that I build is web application for internal use.
It started out as a landing page and a blog. But then I needed a forum for my users -> install BBPress and done!
Was getting some spam comments and posts, so installed some anti spam plugin and captcha plugin.
Seemed my users want to post their own games on my platform, so installed the BuddyPress community plugin.
Wrote my own plugin to integrate my game builder with the website.
I run a Discord server and wanted to notify Discord when a new game is published on my platform, so installed the Discord plugin to push posts to Discord. Plus, I can show Discord activity on my website.
Wanted to send out a newsletter for user retention. Very expensive options out there, so I installed a pay-once solution to run this from a wordpress plugin (50k subs and counting).
Soon I'm going to implement a marketplace where my users can sell and buy resources. And guess what, you have a WooCommerce plugin and some other one that enables this.
Oh yeah, I want to do this with virtual credits, and of course there is a plugin for that.
Absolutly awesome! And in the meantime, I can focus my developments on my RPG making tool.
I also sometimes hire a cheap developer to implement some custom things, and it works great.
Edit: plus, it's really fast to run experiments without losing development time. Just install or enable something, and if it doesn't add value, remove it again.
But I do have a custom script to create staging and test environments. Custom developments happen there.
It's basically copying all files and database, do a few config changes, and you have an exact copy of production that you can play with.
I looked into a proper development flow for WordPress, but it's very hard. Mainly because both data and config lives in the same spot. And you always want to work against the latest production vesion, since things might have changed there.
So no local setup, only multiple hosted ones. The DevOps flow could be improved, but right now it seems to work out fine.
So for custom developments, my developer works on test. Then I check it and move it to staging. There I check again if the update works fine, and do the same on production.
It's a pretty good flow for a 1 person project.
I built an entire frontend around it (my username .co.uk) which tries to reshape how tech novices work with websites.
I have found small business owners I talked to (n=10) to be allergic to dealing with their WordPress or squarespace sites, because despite everything, they are just not simple to use. They just try to cater to too many use cases. Being everything to everyone comes with complexity that's very difficult to navigate as a tech-novice. Though I think squarespace do a better job than WordPress. Albeit more expensive.
The funny thing is, people have grown such an aversion to dealing with websites that I am also having quite a hard time trying to get anyone to look at it. As soon as they do though, it's like a lightbulb moment for them, to see how simple it can really be.
Naturally the trade off is flexibility, but I haven't had any complaints about that yet. I am not dealing with very complex sites though (and wouldn't want to either).
Here's looking for more innovation and possibilities ahead!
For me and I guess for many other engineers it's quite normal to develop a site locally (or at least on a staging non-public domain name) and then move it into production under the final name.
In Wordpress, the site name is baked in all over the place — in config, in database, in generated stylesheets and so on. In theory, this should not be like this (if you use barebones install w/o plugins), but then you buy a theme or some less-than-perfect plugin and boom, you need a separate plugin just to handle migration (which may or may not work 100% of the time).
It should be "gather all things, move it to another place, change the domain name somewhere", but instead it's "gather all things, move it to another place, change all the links, change the domain name in two different places, hope you didn't forget anything or made a mistake somewhere". There are plugins to help you do this though, but all-in-all it's an annoying inconvenience.
If you do need help doing it then migratedbpro or migrateguru are seamless.
It’s, like, really really easy to move Wordpress.
WP-CLI is your friend:
wp search-replace 'http://example.test' 'http://example.com'Wordpress store some information fields and the length of the string of those fields. Use a plugin that search and replace for those and recalculate the length.
Also, search for //example.test, not http://example.test.
Edit: I read a bit too fast, maybe it does implement the string size but I can't be sure https://github.com/wp-cli/wp-cli/issues/1224
Edit 2: https://github.com/wp-cli/wp-cli/pull/1261 sweet, looks like it does ^^.
By the way, I very much prefer the wpmigrate-db plugin.
Edit: And it does:
[--export[=<file>]]
Write transformed data as SQL file instead of saving replacements to the database. If <file> is not supplied, will output to STDOUT.
Well, wpmigrate-db allows to replace multiple strings in one command and that's something wp-cli default search-replace doesn't provide. define('RELOCATE',true);
The Wordpress will be in the relocate mode the next time you visit wp-login.php.
It will reset all the URLs.Documentation: https://wordpress.org/support/article/changing-the-site-url/...
One of its function name is literally "the_content();" where you output the main content in a theme, no class, no context but just a dumb function that sits globally to force the output and there are global variables like "$wpdb" that keeps the database methods.
Of course, you don't want to look how messy the database schema is. Configuration values are just thrown into the db with serialized strings with random keys, you'll never know what's where.
Seriously a first year high school student would put out a better code and no wonder it took so long to iron out vulnerabilities and performance issues to acceptable levels but the mess is already there and people have to live with it unless someone brilliant creates a new platform with theme and plugin compatibilities to WordPress, so the ecosystem lives for people to move on to it.
Name me an alternative CMS frontend that any client can use to update/create content (without learning Markdown) and visually design a page with pre-defined blocks, that doesn't cost $200+ a month.
If only they would include a localisation solution, I could say goodbye to slow and cumbersome WPML.
It is flexible, fast, and secure - especially on a host that specializes in craftcms - like Fortrabbit - and combined with cloud flare.
Squarespace, yes, you're locked in.
Re: the portability of Wordpress, I'm not sure how many Wordpress site migrations you've done...but I wouldn't use the word "portable" to describe the process.
Webflow CMS solves that problem, but with vendor lock-in.
I rejoined the ranks in 2013, and holy smokes. WordPress. WordPress everywhere. It's even more so now. These days, to be in Web Hosting is to be in WordPress Hosting.
It doesn't seem like Matt has any intent to go public, yet he's raised $700M+ [0]. I've heard anecdotally it's a profitable company but not sure if that's still the case after the Tumblr acquisition.
And not something that anyone who really understands software engineering should scoff at.
I would go so far as to invite the downvotes with a comment like this: WordPress may now be the most powerful (low-code/no-code) application development platform ever created.
What is the WordPress of the 2020s? Something built on web assembly or TypeScript or Python or whatever maybe?
And you would be correct.
The WP API is mature and stable, so much so that tools around fast WP scaffolding are already available. You can create a site in Webflow, export the HTML and use a tool like Pinegrow Theme Converter to attach WP functions to HTML elements, such as Posts loop, ACF fields, WP Customizer, etc. No PHP knowledge needed. Pinegrow will export a fully featured WP theme to your site folder, and handle enqueuing the functions and stylesheets. You never have to open functions.php again.
Add to that the vast library of plugins for things like Ecommerce, online courses, appointment scheduling, user accounts, social networking etc. and you can create a pretty complex prototype.
(a) Wordpress (b) SquareSpace (c) https://strapi.io/ (d) https://prismic.io/ (e) https://www.contentful.com/
The output will be a simple website, we already have all pages in HTML, and from the tech perspective we could use any of the above.
What I've seen was: SquareSpace is still rather limited, Prismic and Contentful are around $500 per month in their non-free-tier, and Strapi is just too expensive to find devs for. Plus their editor looks the same as Wordpress's if I'm honest.
On the other hand, Wordpress has a massive community of reasonably priced freelancers, has updates many times a year, and most things you want out of the box (such as SEO, or easy hosting on Heroku or elsewhere). The only thing it doesn't have is the excitement to work with it :)
Is there a good business case for any of the competitors?
I cannot take them as anything other then grossly incompetent.
WordPress is 18 years old, there's a good chance that it will be around for quite some time longer.
I've worked a bit with Contentful, and it seemed like a pretty good CMS, but pricey. The client was moving off of it because they wanted the more familiar WordPress UI.
Webflow is basically a super good editor that spits out static sites on build.
As easy to update as squarespace for non-tech folks, but as customizable and secure as a static site generator (since you can build everything from scratch).
WordPress alternatives like Wix or Squarespace are closed-source, but the HTML/CSS generated by these services is simply dreadful.
As for Static Site Generators (SSG) - liked by developers but by no-one else - they are particularly unsuitable for non-technical users and lacking in features (by design). They are certainly not a serious alternative to WordPress.
About 5 years ago I saw a lot of requests like "When will WordPress move to MVC?", but those questions seem to have died out mostly. Then there is the OOP architecture of data and communication that is loved by a lot of developers. I think Joomla and Drupal have moved into this direction.
This makes the code in WordPress look oldfashioned, it is partly still procedural code, with some classes added into it. WordPress community very much wants things to be backwards compatible, and so far that works out.
It's a simple blog. So, I've always tried to use plugins sparingly, and avoided massive database model changes if I could help it. But I like to think it wouldn't have been possible without the care put into WordPress upgrade path.
At the same time, the focus on backward compatibility, to my mind, has held it back. Sure, innovation happened at the visible level, the surface level. New themes, new administration UI, Gutenberg, Blocks,... all of that have improved the author experience. But looking under the hood, the codebase simply isn't in line with modern PHP practices adopted by major PHP framework communities. Which leaves quite a lot to be desired for.
Granted, part of the appeal of Wordpress is simply being able to grab the PHP files and (S)FTP them to a shared hosting. No need for complex CI, no need for composer, no need for complex configuration. That's what lowers the bars for many people who simply wanted their own self-hosted space on the Web.
My other major gripe is how WordPress authoring experience evolved over time into a direction which I don't agree with. The editor in modern WordPress feels heavy handed: every item you add to an article morphs into a distinct component accompanied by a contextual menu with myriad options. I feel that this just gets in the way of what's actually important: writing. Personally, I like(d) the terseness of a simple textarea form element with limited affordances as to what you can add in terms of markup. Then again, the ambitions of Automattic are beyond simple writing and moved even beyond authoring and publishing. I think that's just par for the course and I don't fault them for that. It just has made WordPress less of a good fit for me over the years and that leaves me some with a sense of saudade.
Either way, I owe a lot to WordPress. And I'm curious to see how it will evolve in the years to come.
Clients wonder how to use it and internally, it's a mess like all the other core part of WordPress.
They leave a bug having the previewing feature broken with any custom fields for 2 years and they don't know what to do.
https://github.com/WordPress/gutenberg/issues/16006
There are plenty of better visual editors out there.
Many years later, I'm happy to see Wordpress thrive – the power of one person's voice is more important than the platform itself. This is how any platform should work: empower their users, not control them.
Localization is mostly a solved problem today but empowering the user and respecting their rights isn't. I hope us developers can help pushing the ball in that direction.
I know there’s value in Wordpress even if it’s just potential future revenue supporting a subset of the 1/3rd of the web running on Wordpress. So I’ve pushed but when I loose spend twelve hours over a whole week trying to work out how I’m supposed to manage my database (don’t even get me started on how frustrating it is that you are basically forced to use MySQL) and basically giving up because there both appears to be nothing other than do it yourself with SQL DDL if you don’t want the plug-ins doing it for you, and the fact the web is full of SEO for how to “migrate” your content from one Wordpress site to another hosted somewhere else…
Id love some recommendations as it feels like I’m making an uphill slog through a river of 18 years worth of outdated info posted by users and decaying SEO bacon written by developers.
I think this is probably both the most painful and most useful way to learn how Wordpress works under the hood. It will probably take you another 12 hours (and another week), but at least those hours won't be wasted.
Edit: oh, and take notes while stepping through with the debugger. Having a document you can refer to later that has some kind of outline with your own ideas and opinions is a huge help.
I suggest going through the VIP docs as well as they have some really good advice on securing and speeding up wordpress along with what to avoid.
https://docs.wpvip.com/technical-references/
Also just a tip: https://github.com/WordPress/WordPress-Coding-Standards
Don't try to use WP for anything involving a lot of programming. It will just hold you back. Use it for projects simple enough that you don't mind writing a few MySQL DDL statements with DIY migrations.
Personally, I think trying to apply modern development practice to wordpress development is a waste of time. You're going to fight an uphill battle. Instead, just treat it as a legacy platform and use legacy development methodology: have at least two or three copies of the site (dev, staging and production). Use sftp to live edit the code on dev/staging, then copy to production regularly. Make sure to have a versioned daily backup in place which at least can pull the last 7 days daily backup and the last 6 months monthly backups, and you're set.
If your app is getting too complex for this development method, you can always switch back to django or other modern frameworks with modern tooling.
The last time I looked, WP was running ~1/3 of the public-facing web. I use it for all sorts of things, as it makes a perfectly usable CMS. It's easy to keep it updated and secure these days, plus they've had an emphasis on security for a while now - or at least a better attitude with regards to security.
Jamstack is nice, but it's either for personal developer blogs or larger teams. Outsourcing is too expensive with coders being in high demand.
Everything WP can be easily outsourced when needed, and there really isn't much of a speed benefit with Jamstack sites if you cache your WP site on the edge (e.g. with Cloudflare APO) and use a fast DNS. Security of the origin server isn't a problem with a good host or going static.
You can generate static sites from a local WP install if you find secure hosting too expensive, here's a nice docker based tool for this: https://lokl.dev/
WP is really as hard, ugly fast or slow as you make it, you have to find the right theme and plugin ecosystem within WP.
I don't have to and don't need touch the code building sites with it, so all those weird WP code conventions don't really bother me.
I’m glad they are doing so well.
I haven't been around the open source CMS world this long, I only started with Drupal 17 years ago (to the day as of yesterday) https://i.imgur.com/TsNTYqZ.png
I definitely look at those days with rose tinted glasses and had basically forgotten about the time before I used VPSs and knew enough of bash and Linux to set all these things up myself. And even that was quite awhile ago now I write frontend and back ends and deploy them to AWS or Heroku. I guess it just shows how much the web has changed and matured compared to using shared hosting from websites that only a few hundred people max used.
This thread is a giant bucket of nostalgia for me and I’m not even 30 yet. Crazy to imagine what the web will be like when I’m 50 longing for the days of React and Flask.
I used it for my blog and decided to not write a single line of code, because I would use my time to write articles: https://gioorgi.com
I started using it on 2004 about 17 years ago. I migrated about 4-5 times my VM provider, doing backup and never lost a bit.
After moving to a fast provider, my machine works fine, and I find out JetPack is quite a CPU eater; now I prefer a more huge set of plugins and avoid JetPack.
I used it sometime for building customer's Web Site, and, yes, Drupal was better for general purpose CMS at least on 2009.
But Ghost did not buy me and I think WordPress is still a good tool.
Looks like a combination of Elementor + Oxygen, and looks like it is producing very clean HTML and some how compatible with Gutenberg (haven't tried this yet)
Thank you WP
Unfortunately my own blogs are quite niche in topics, and there wouldn't be much value in sharing socially as my network wouldn't really get it.
I wish it had stronger open source competition.
WP is ripe for disruption in so many areas:
||| Price |||
WP succeeded in part because it was cheap and easy to host. This is still true to an extent but the story is weaker than it was.
WP hosting is a race-to-the-bottom market, but hosting secure, fast WP sites with good backup and support remains valuable. The WP hosting market matured and there are enough customers who won't pay for cheap hosting because they've seen their sites get hacked or experienced performance and reliability issues. This supports an industry offering expensive managed hosting at a high markup tiered by monthly visits.
So it's not surprising that Squarespace/Wix/Shopify price points are no longer the turn-off they used to be for many at the low to mid end, and that larger businesses are looking at Jamstack and static sites for the potential cost savings at the mid to high end.
Takeaway: A CMS built for “start for free” hosting platforms like Cloudflare Pages and Netlify could provide an even more compelling story than WP, reignite the DIY open source site building movement, and be a more natural fit for enterprise customers.
The “Jamstack” movement is the closest thing we have to this, but there's no strong frontrunner that includes both a modern and compelling admin area for publishers coupled to the mechanisms for previewing, building, and deploying a site out of the box. Devs still have to cobble pieces together into a semi-coherent whole. This is currently touted as a strength because you can “use the best tools for your unique scenario”, but it might be healthier for the Jamstack community to start treating this as a major flaw blocking wider adoption instead. That way they could just build a good apple pie instead of asking everyone to first create the universe.
||| Deployment |||
When technical users in a company get to pick the stack, it is easier, cheaper, and faster to deploy to Netlify/Cloudflare|GitHub Pages/Vercel using modern deployment practices (like the ability to preview multiple deployments — one for each PR) than it is to ship updates to a WP host. Cloudflare Pages pricing is also tiered on deploys/month instead of visits/month or bandwidth, which is more palatable for most.
Takeaway: A headless CMS that deployed the admin app and website to an edge network could outperform WP for ease of deployment, performance, affordability, and access to other built-in perks of edge hosting platforms that are hard and expensive to get right with WP today (caching, security).
||| Marketplace |||
WP.org offers free plugins and themes, but it still does not (and may never) offer paid themes and plugins. This makes commercial WP options decentralized, but it provides users with a poor experience: comparing, purchasing, updating, and getting support for paid themes/plugins is a wild west that is still harder and more frustrating than it should be. It also means anyone who wants to sell themes or plugins has to manage their own sales infrastructure.
Takeaway: A CMS platform with a built-in marketplace could be more compelling than WP for end-users. It could also pull plugin and theme developers away from WP — most plugin/theme devs would probably prefer to spend their time making themes and plugins than figuring out how to sell and deliver updates securely.
||| UX and ease of use |||
WP can be overwhelming for new users, in part because of the disconnect between the promise on its homepage (“the freedom to build anything you want“) and the journey people have to go on to achieve that lofty goal.
The main issue is that there is no real guidance — you can build an ecommmerce site or a podcasting network or a gated content blog or a newsletter or even just a simple blog with WordPress, but in all cases you're basically on your own to figure out how to achieve those things. Yes, there are a huge number of blog posts with titles like, “9 Best WordPress LMS Plugins to Sell Courses” and “We Pretended to Test the 46 Best WordPress Contact Form Plugins and Then Just Recommended the One that Gives us the Highest Affiliate Commission” that you can sift through, but WordPress itself gives you very little help.
Takeaway: A modern CMS or user-friendly application platform that claimed you could “build anything you want” would actively help you to do that. It could perhaps offer starter templates for different scenarios, tutorials, or _basically anything at all_ that didn't just dump you into an admin area that was last refreshed in 2013 containing some vestigial apparatus for blogging but no real clues as to how to even succeed with that goal let alone anything more complex.
||| Localization |||
It's 2021 and you still need plugins to translate content in WordPress. Naturally there are a lot of localization plugins that you'll have to compare and experiment with first, and you'll find that all of them offer a worse experience than you can get with a hosted CMS like Contentful or GraphCMS.
The good news is that built-in content localization is on WP's product roadmap, so this should eventually improve. The other positive is that while content localization is pretty bad in WP right now, plugin/theme localization is generally quite good.
Takeaway: there's a small window of opportunity here to present a more compelling content localization experience than WP does by default.
||| PHP and the developer experience |||
A large number of developers who use WordPress would rather not. (WP was the “most dreaded platform” in Stack Overflow's 2020 survey with 67% of developers who are using it not expressing an interest in continuing to do so.[1])
Of more concern for the health of WordPress is that new web developers generally aren't picking PHP. It's not even that PHP is especially bad these days, and even WP APIs are gradually improving — it's just that new developers targeting the web as a platform are probably writing JavaScript or TypeScript. And, because they're not writing PHP, they might not choose WordPress if a compelling alternative existed in the language they prefer.
Yes, Headless WordPress is a thing, and every WP host is jumping on that boat because they can see the writing on the wall. But WP is going to be tightly coupled with PHP for a long time, and that may be an opportunity for a CMS that can attract new blood simply because “we use your favorite language instead of PHP” becomes a competitive advantage.
||| ECommerce |||
WooCommerce is used for a huge volume of transactions ($20 billion a year was mentioned in State of the Word 2020).
But if you need to build an online store today, Shopify is in most cases a quicker and more stable path that will let you focus on your business and products, simply because it's built for commerce out of the box.
If you need to sell products casually, Gumroad/Stripe Payment Links[2] are probably a better choice than WooCommerce.
If you need to gate content behind a paywall on a multi-author content site, Ghost is increasingly a more compelling choice than WP, since it includes subscription commerce as well as audience building and outreach features by default: https://ghost.org/features/
WP can be an ecommerce platform, but it isn't one by default. Making WP do ecommerce feels very much like any other form of digital alchemy or contortion.
A CMS built from day one with commerce and monetization in mind would look quite different to WP. It could be all the more compelling for users who want those options out of the box.
[1]: https://insights.stackoverflow.com/survey/2020#technology-mo...
If I may attempt a summary..
- Secure, fast hosting with good backup and support
- Admin area that allows publishers to preview, build and deploy a site
- Headless CMS that deploys the admin app and website to an edge network
- CMS platform with a built-in marketplace
- User-friendly application platform that actively helps you to "build anything you want" - such as starter templates for different scenarios, tutorials
- Built-in content localization
- CMS using "your favorite language", such as TypeScript
- CMS built from day one with commerce and monetization in mind
Throw on top of it the architecture of plugins (no sandboxing!) and the culture this has developed for websites being "built" with a combination of 50+ outdated plugins and it frankly becomes a nightmare. Of course this can occur with any huge software project, so I somewhat concede this point.
The real turning point for me was the push to move to the "block" editor and effectively turn WordPress into Wix or Squarespace or whatever
But it still has the ability to just type away and write stuff without ever leaving the keyboard. I think it’s not bad. And it gives the graphic designers some control.
It’s a weird ecosystem though, you need a solid theme to start and finding those is a little hit or miss. Same with plugins, it’s hard to tell the great from the ok sometimes.
We in the startup culture often forget that the market for building bespoke webapps using the latest and greatest frameworks is only a tiny part of the web. The vast majority of people who order websites just want something that works out of the box, and they want it yesterday.
I don't think anybody is particularly fond of WordPress's medieval internal structure or its byzantine plugin ecosystem. For the time being, though, I'm glad that there exists a well-known, open-source, self-hosted alternative to Wix and Squarespace.
There was a time when lots of people wanted something bloggish. Now that time is over, and WordPress has pivoted accordingly.
You can definitely turn it into practically anything, and it quickly becomes a mess due to the fact that it was never meant to be an application platform. But WordPress is still best in class at what it was meant to do; a simple self hosted blog.
A guy I know runs a blog for his non-profit on WordPress. At one point he asked me for help because pages were loading extremely slowly. It turned out the blog had been hacked and was being used to host gigabytes of junk pages with SEO boosting links to really trashy websites.
I used to recommend WordPress wholeheartedly for self-hosted blogs, but these days I strongly prefer something that doesn't have any back-end code that the site owner has to maintain and/or update -- a static site generator, a JAMStack-based blog, etc. Or consider using someone else's hosted blog platform (someone you really trust to host a secure platform).
Or better yet, any static site generator (Hugo is nice) + Netlify.
WordPress is still best in that, even when it kind of sucks.
I myself prefer the "static builders" for small websites, like Hugo/Jekyll, but WordPress also have built-in editor and access control; with small websites it's whatever, but with bigger websites, it comes handy.
The plugin marketplace, on the other hand, is a disaster area. Plugins are marketed to non-software people who don't understand security and don't know how to evaluate products for it, even though they might care in the abstract. The result is that the typical WordPress installation is a festering mess of insecure plugins, and sites get hacked all the time.
Yeah sure I’d be glad to quickly change over this theme to match new designs. Wait every plug-in also has to be fought with since the templates for those have also been “customized.” Wait I have to match the HTML almost to a tee because the chrome plugin no one else has ever heard of says you have perfect SEO (despite only getting first page results with a highly specific query no human would ever type) and you think this will lower your score? :(
I’ll take a stressful 10 hours at a startup over that any day.
That's hilarious. I'm assuming it would not have gone well to try to tell them otherwise?
To me WordPress is a relic of a time long gone, of internet that does not exist anymore, and sometimes wish I could get back to - it enabled so many people to just put out things that they wanted, without having to learn HTML
Automattic's failure IMO is making Wordpress.com feel like a blog platform for far too long. A lot of what users would consider reasonable functionality for a website was not provided in WP core but by the plugin ecosystem. So people just defaulted to plugins for everything, which eventually gave WP a bad name, because plugins were often janky and poorly supported.
I stopped using WordPress over a decade ago. I use other website//blog platforms now. I may go back if there is nothing better available, but I have a control-streak in me.
At the time I started WordPress I just didn't have the knowledge coupled with just needing to start something quick.
I moved on.
Anyone who needs to install a plugin to add a table or to do a redirect is already well catered for.
They have forked from WordPress 4.9. I'm not sure yet about their long term feasibility.
Yep, this as well as seeing random ads appear in my blog while scrolling through my posts. Recently, I tried going back to WP, but only if I could use the classic editor but they made it so confusing to find it and use it that I gave up. Too bad. I was a happy customer for many years prior to the block thing.
Kudos!