WP20 and Audrey Scholars
ma.tt
ma.tt
Gutenberg can still be an error in judgement his part and as a key element of WordPress strategy.
I can have enormous respect for his business ethics and still think in one aspect of his business he has made a mistake.
One of the few in US tech that got bigger and bigger with projects and did not go into full censorship mode to court more money.
Very admirable indeed.
I couldn't find any alternative store fronts that weren't way beyond her near-zero budget but if anyone has recommendations please let me know.
You aren't going to get better than Wordpress for that price. Closest options are Shopify and Squarespace. Both of them definitely not 0, with Shopify's starter coming in at around ~5 with the next jump up being 50/m, and Squarespace commerce at around ~20. Worth the price of admission for how much easier they are to use. The plus to both of these are that it's much easier to start adding different features to incentivize purchases and return customers.
If the price is seriously a concern, it's advisable instead to help your sister in law move away from a dedicated platform and instead utilize Etsy, Instagram (Shopping/Shops), and Gumroad to their advantages, and the cost there is 0 (until you sell things then they take a slice of the sale). Several reasons for this beyond cost, your sister in law is likely already using platforms like Instagram for social reach, and most people are going to trust platforms like Etsy over individual sites if they aren't built well. So more easy sales. Once she's grown past a certain stage she can then fully hire someone to manage a custom solution, but until then do not let her underestimate how great Etsy, Gumroad, etc are!
I highly recommend it as a platform though, just make sure the business maths works.
And security vulnerabilities.
Core WordPress is fairly well hardened because it gets a ton of attention. Third-party plug-ins, not so much.
There’s also the problem that WordPress builds upon and relies heavily on being able to modify its own code. Although this does allow you to reliably do things like unattended automatic updates, which would probably be net good (normally improving things, though occasionally harming), it also means that even the slightest security vulnerability tends to become immediate total server takeover. This is why I blame WordPress core architecture more than individual plugins: in most ecosystems, most security bugs apparent in plugins wouldn’t be so exploitable. This design decision is probably responsible for most WordPress site hijackings (… which are very common). Taking all things into consideration, I suspect that going read-only file system and not supporting installing/updating/removing any code via its web interface would probably be good for WordPress’s security, despite it meaning most sites would never be updated—but it would certainly harm its ease of use, and I can easily see why it’s basically a non-starter.
By contrast, choosing another PHP system as an example (since it’s one of the few popular languages that particularly supports this kind of self-modification), last time I dealt with Drupal (back in 5 and 6 days), it would actively complain if it could write to its own directory, urging you to make all but the directory it uploaded user files to read-only to the web server user account. Updates were then done out-of-band, using your user account on the machine which had write access to replace the files, rather than the web server’s account. (There were manual steps involving the web interface and local file operations, or tools like Drush to make it a single command.) Bad for ease-of-use, excellent for security.
I haven’t had much to do with WordPress, but I gather storing executable PHP code in the database is also fairly common, which is almost worse than having a writeable file system. My vague recollection of Drupal is that although it supported “PHP code” as a content type, you had to turn it on in the config file, where it warned you of the vulnerabilities this opened.
(My qualifications in this comment: I’ve helped recover several hijacked WordPress instances, mostly around 2015 and 2022; migrated one business off WordPress in 2022; done almost nothing else ever with WordPress; worked fairly extensively with Drupal 5 and 6 on a few sites quite a few years ago; worked a fair bit with Django over the years, and some in other web frameworky things in Node.js and Rust; haven’t done anything serious with PHP for years now, preferring Python, JavaScript and Rust. Certainly don’t trust me for any insights into WordPress. I could easily have made errors in this comment.)
That's great, but if you remember drupalgeddon, the attack vector (sql injection) used the url routing system, which very conveniently would map a path to any php function + arguments. Ugh.
SQL Insert a call to php's eval + the code of your choice as the args and voila, SQL injection becomes rce instantly.
I can understand a CMS having read write access to the database, the main benefit is to update the content of course. But mapping paths to executable code, straight into the database is a highly dubious choice.
It’s not just technical API design, though — it’s also business logic and community architecture. WordPress didn’t stay a blogging engine, but became an everything platform, with plugins needed to fulfill vastly expanded ambitions. The inadequacies of the extensibility design have much more severe consequences when stretched to encompass such sprawling scale and scope.
Remade it but thought before I installed and suddenly the site is performant and secure.
Wordpress gutenberg is like a bad experiment that has no end game. They have spent years developing something is incrementally improves at snails pace. Wordpress is just plain and simple super accessible from a strong ecosystem of plugins, php is simple and widely known, it's an easy platform to host. The problem is all the alternatives like jamstack generators, headless cms, and even better CMS tools like craft just don't have enough popularity to leverage away from WP. I could easily spin up a woocommerce site just as fast as Shopify, but in reality not a fan of either. From an agency perspective, most clients could give a rats ass about things technically, they just want something working.
Not much WordPress’s fault, aside from making writing and installing plugins easy and maybe not including a bazillion features few will use out of the box.
I think Gutenberg is still not ready, but when it matures, it may be a better alternative to the page builder plugins like Elementor, etc.
Comparing a hosted open source solution to Squarespace and the likes is non sequitur, IMO
how so?
People who drift to WordPress also want the cost to be lower and to be able to host almost anywhere (meaning, almost any web host should support it).
The cost and usability combination hasn’t been solved well by tools other than WordPress. If there are any, I’d like to know or re-examine them.
Sounds like the libraries and open source software I work with everyday, to me.
It can be very simple to administer if the site is built right, but someone has to get it there and that takes some budget.
Anyone in OP's situation I push towards Shopify/Squarespace.
Tongue in cheek, but genuinely as well, it is probably the most attacked CMS platform on the internet. That not every WP site is taken down by the automated attacks they all get means they must be doing something right.
Anyone would be lucky as fuck to have the success and influence of Wordpress and yet we have clueless folk who speak of it as a cautionary tale.
overall i find it balanced. certain topics will draw certain vocal crowd more and then it will look unbalanced.
on the other hand it's really funny to see "modern development practices and patterns" mentioned in a topic about WP.
are you sir one of them expert technologists from tok tik?
i agree that WP is a cautionary tale but one thing they got really well: never do a rewrite from scratch while being the top dog. it must have been hard to resist that siren song and now we'll have WP till the heat death of the universe.
WordPress is the Windows of content management systems.
They both are widely used, have an outdated architecture, are keeping compatibility above all, therefore don't innovate, are very extendable, can run almost anything, and are the go-to for many people.
It's up to you to decide, if these are good things or bad things.
Except CL squandered the opportunity to rebalance the power dynamic between landlords and renters.
Then, its continued reluctance in many fronts fragmented local P2P into a dozen marketplaces, greatly impacting its own marketplaces’ liquidity.
At this point I think Wordpress is doing more to sort itself out than CL.
Earlier days of web there were so many projects fighting for this crown. Starting from Movable Type to PHP Nuke, Xoops, Joomla, Drupal (and a billion others). Well done open source and free software community. Shoutout to all those people who worked on all those platforms to make this a possibility.
It's not fancy and you will have to deal with a lot of horrible plugins that clients will want, or their marketing team, however from the product perspective it's an amazing technology - just like any that lasts 20 years in web dev IMO.
This isn't by any chance a defense of WP but before dunking on it think what else can you offer to a small business for the same price and functionalities.
Edit: Sorry, that was snarky
WordPress has served me well over the years, and even though I don't use it anymore, it has certainly been easy to setup and get going with templates, plugins and SEO.
I still see a lot of brands using WordPress for their official websites, which always surprises me, but it also assures me that WordPress still is relevant to this day.
Thank you, WordPress!
He was recounting how much better the experience of building the site was, and how much more responsive the content management was, when divi was not part of it.
Then we threw in few plugins to cache and minimize and presto, a simple site up and running that non devs can go and add content, and does well in speedtests.
Critics pop out of the woodwork whenever it's mentioned on HN, but most of them have very little meaningful experience with WP. The ecosystem around it is huge and mature and if you work with the right partners it's a remarkably hassle free way for a business to serve tens of millions of users. Most of the issues with plugins are resolved simply by being picky about which plugins you install, you are not required to use any, you can code everything yourself if you think that's safer (hint: often, it's not).
Most large corporate clients are already familiar with WordPress and partnering them with a managed hosting solution like WP-Engine to handle security / support has worked really well.
Smaller, more agile companies that might want something a little more fun tend to do well with Webflow.
The larger the site the more likely I'd want it on WordPress over Webflow.
Happy birthday! If nobody replace you is because you are the best in town for most people and organizations.
I prefer my minimalist static site generator setup better and hope someday we could top Wordpress but realistically I wouldn't recommend betting against them. They've done a great job.
I just quit my last job which was a RoR/React shop. I've been working with NodeJS and JS frameworks for the past 10 years. I never really got into PHP.
Now, I'm working in PHP again and specifically making Wordpress sites for a non profit agency as a contractor. It has been a joy. In particular, we're using root.io with Valet and heavily relies on root's version of Laravel blade system which makes building websites super fast and seamless and I've gotten a lot of satisfaction building things this way.
At some point, every client decides they are better off switching to an extremely cheap agency for maintenance. But these bottom-of-the-barrel agencies don't seem to have any programmers on staff at all. They have no idea what to do with composer, git, or any cli.
It is both excellent, and terrible. Choosing to use WordPress you will experience both in equal measure, without knowing when exactly.
Enjoy.
What I mean is that you can install WordPress plugins with WordPress itself, live. The PHP scripts which are essentially files in a folder, will go download more PHP files essentially augmenting itself without ever having to restart or redeploy the server.
It's an interesting capability that few other web frameworks have.
File extensions on websites used to be Very common until about 10-15 years ago
[1]: https://wp-cli.org/
Long live WordPress.
https://ma.tt/2023/05/with-mike-little-and-dries-buytaert/
or go direct to the video:
https://www.youtube.com/watch?v=QYhIItlPPOs
"WordPress co-founders Matt Mullenweg and Mike Little sat down with Dries Buytaert, founder of Drupal, to discuss the history of WordPress over the last 20 years."
WordPress is great as a Product. It clearly works and a lot of people make a living out of it. It powers a big chunk of the internet and that's admirable.
But engineering wise (or tech wise, or "good practices" wise or however you want to call it) it is the worst aberration ever built on this world. You can see all the possible bad practices in this industry in both the code and the coding practices most of its community follows. They're stuck in the year 2000 and have no intention to move forward.
It is the perfect example that technology doesn't matter if you have a good product.
As a developer that used a lot of other things in the past, I feel miserable every time I have to do anything on it. It's frustrating as nothing else I've done in my life.
That's mostly because a headless CMS is a component for a piece of software you write.
Wordpress is a thing you poke at in a control panel, and that speaks to a way different audience.
We're all making our own stuff according to our important tastes... And yet WordPress is out there massively more successful than just about anything.
How? Why? Is it just that they were early? What's the secret to their success?
To me, it's that it seems (even if it isn't) like it makes website building simple.
is the problem just that it's different to the way it used to be?
Gutenberg was designed for people like you who (were/are) new to WordPress and there was a rocky transition as well as a complete reworking of how to build WP themes (almost everyone’s bread and butter work).
However, I have a list of a few items that just haven't sat right with me during the post-Gutenberg WordPress world.
1. The way that it saves the HTML output from React blocks directly to the DB is a cumbersome and unfriendly approach for all. Having a client ask for what would have been a simple tweak pre-Gutenberg and having to resave every page on the site so the deprecation pathway can "update" the block is not friendly to developers or editors. I know you can use PHP (aka "dynamic") blocks, but then you're duplicating the same exact UI between React and PHP and have to take on the technical debt to make sure to keep that in sync. We've moved to relying on ACF Blocks instead of React blocks for most things due to it having a better developer experience and a lot of our clients being used to how ACF works, but obviously this comes at the expense of the fancy inline editing that was the whole "wow!" factor of Gutenberg.
2. The documentation was lacking at launch, and it still feels that way sometimes. It was really aggravating to try to figure out what exactly you could change and remove in core blocks. I remember a coworker and I trying to reverse engineer their columns block since there were a lot of missing features we wanted and realizing that a very, very core block to the Gutenberg experience was utilizing functions marked as experimental without much documentation about what they were or why they were experimental (that we could find). I remember doing our usual upgrade on a new version year after we finally built our own version based off theirs, and the editor completely broke in one of the upgrades (can't remember if it was a major or minor release). Turns out those imports weren't experimental anymore (and no hard feelings on us having to update our imports. We knew we'd need to, it was just the length of time that passed that was "scary", because it doesn't feel great that the core backbone of your site is experimental, haha!).
3. Full site editing being rolled out has felt like Gutenberg's launch all over again. I think #2 is partially responsible for this, but I've watched coworkers have to fight with this a ton for very little benefit, and in some cases those folks end up just saying "hey, you know what instead of trying to rely on their new/weird templates, we'll just add header/footer.php back." This may be less of a problem of Gutenberg itself, but more just a continuation of the lack of decision making and planning that lead to Gutenberg's flaky launch to begin with. Like Gutenberg itself, it's a good idea, but launching it half-baked to just get it out the door makes me hesitate to want to incorporate it until years have passed. My experience has been somewhat limited with their FSE implementation since I've been doing a lot of NextJS work lately, but what little I've dabbled in it wasn't going to have me giving them glowing reviews.
4. It feels like they reinvented the wheel to "do" React SSR in PHP since they save React output directly to the DB. Sometimes I wonder if they wanted to actually have Gutenberg be a standalone project, move to Node, and do real server side rendered React, but were afraid of the very real pushback a move like that would cause and the loss of decades of plugins and backwards compatibility. I know we're toying around with the idea of headless WP + Next since it would hopefully get around the poor pathway for updating React components, but at that point we wonder is WP really what we want to go with or would another CMS be better for our needs.
All that said (didn't mean to rant so much!), I agree with what lenova said a few comments over that Matt has always appeared like a decent person from afar, and I've always respected that he's a web titan (in my eyes, at least), but doesn't come across with the same high and mighty attitude and harshness that a lot of other folks in a position of status like his do.
Having said all of that, we use Headless WordPress for many many client projects and have got it working really well for us. For us it’s much better than Sanity, Craft and Prismic. The WP-GQL plugin and ACF are really amazing.
If you were looking to close out those problems, you'd move to a platform which was coded more safely and I very much doubt it would be PHP.
I don't know what it would be. Maybe something targeting node.js but with type safety in front of a compile phase? (to get similar platform independence that PHP brings)
Or, a static site re-publisher which took a PHP master and committed out the door faster to render, safe pageviews.
not ghost - too clunky to use. what else?
What happened to Ghost (haven't kept up to date)? I remember in the first few years it felt so promising, snappy and delightful.
But I think it highly depends on what kind of projects you work on.
EDIT: I do wonder if the website is just broken? That seems like a crazy price to charge, while being such a specific number. That is definately what I'm being asked for however.
EDIT: they do automatically add VAT based on your location so maybe that’s completely broken for you? Only thing I can think of.
You rapidly find an insecure spaghetti mess, that's almost unmaintainable, especially when you find loads of random plugins installed and the previous developers cut corners and started hacking code into the core and the plugins, which of course then breaks stuff when you update any of it. Which you need to do. Often.
Why over just using a static site generator?
- lots of cheap wordpress hosting out there
- no need to "rebuild" whole site when you publish a new article
- friendlier to non-technical people
- upgrading version is just a click away
of course there are cons too (some are mentioned in the other comments), but for me, I can accept those trade offs
And the economics of the Wordpress ecosystem mean that there’s no incentive to fix this and bring more of these critical features into Wordpress core.
I also find the templating system unintuitive compared to something like Mustache that gets out of your way.
For these reasons I’m currently working on an open source batteries included CMS with a specific aim on improving the developer experience compared to Wordpress. It’s early days but always interested in other peoples thoughts on Wordpress’s strengths and weaknesses.
I should also say that despite all my criticisms, Wordpress is a monumental achievement, one of the great open source projects, and the world is so so much better for it. Imagine how much worse things would be it something more like Wix or FrontPage had become the default way to get a website online in the Web 2.0 era.
Abusing a blog engine to make it run small EC sites becomes a cheap and half manageable route. Even for super simple things like a site with a presentation page and a contact form, a wordpress blog is faster to set up, cheaper and more manageable and ultimately more reputable than many solution out there (the "cheaper" part being of course the more critical aspect)