WordPress.org's latest move involves taking control of a WP Engine plugin
theverge.com
theverge.com
Thanks for the work, Matt!
Just to preempt people arguing with me, please note that this comment isn't meant to be an ethical defense of them one way or the other, but just a factual correction.
If WP had only fixed the error but not removed all of those things & and hadn't claimed authorship themselves ("By Wordpress.org", and putting themselves at the top of the contributors while they're certainly the one with the fewest contributions), that argument would be different, I believe.
Would wordpress.org allow WooCommerce to be forked, uploaded with no modifications beyond the all references to WooCommerce being changed to YouCommerce and all mentions of Automattic being wiped? I don't see that being allowed.
Wordpress removed all premium features after the hijacking of the plugin.
https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
Where is the CVE? What risk is there continuing to use the original plugin? No details at all. This results in fear: we don't know if the original is safe to use.
> Going forward, Secure Custom Fields is now a non-commercial plugin
Does this imply that Wordpress is potentially going after a revenue stream from WPEngine?
If the plugin had Pro options* then are those closed source and so not available to Wordpress in their fork of the codebase? It's not clear.
This is cited in WPEngine's lawsuit. Like you said, I wouldn't be surprised if this behavior of matt's was a breach.
Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
> Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure)
If I was on that security team, I would be livid they used my team's name on this behavior.
If this was done by that security team, their ethics are disgusting, and likely non-salvageable...
Still looking for the security exploit worthy of a plugin takeover though.
edit; best I can figure tonight is it's some concern over CSRF, but they don't even sanitize $_GET nor $_SESSION, only _POST and _REQUEST... so either it's more complicated than it looks on the surface, or this "fix" is partial at best, and wasn't written by someone from security. (It's also possible or likely that I'm missing some context, it's been a long time since I've had to work on php)
I don't know how much overlap there is between the Automattic and WP security teams but I assume there's some like with most things in WP.
I believe WordPress.org backported the change and named it v6.3.6.1 at that time [1], before rebranding ACF in a later version (v6.3.6.2).
[0]: https://www.advancedcustomfields.com/changelog/
[1]: https://plugins.trac.wordpress.org/changeset?new=3164480%40a...
`Author: WP Engine`
is now
`Author: WordPress.org`
Is that even legal? If they had changed to "Maintained by" it would make more sense.
- public $version = '6.3.6';
+ public $version = '6.3.6.2';
Why would you break the version standard? Maybe there are scripts expecting a specific format or some such. Also, given the majority of this change, I think 6.4.0 or even 7.0.0 is more in order, but at least 6.3.7.Edit: To make matters worse, elsewhere in the code, it's referenced as 6.3.8. Very confusing.
> want free plugins to add functionality to site
> absolutely will not hire developers or pay for software or plugins
> how dare the free plugin for my free software not be coded to the highest standards
- It’s a specific symptom fix: The same problem could occur with $_COOKIE or $_REQUEST always being available
- The cleanup is not done in a finally{}, so random missing vars when an exception occurs.
Exec summary: Horrible code as always in WP.
I'm guessing the WP security team has been pentesting any WPEngine code they could get their hands on to find an excuse to make all of these changes. The security issues do look bad (once again proving that WordPress' worst vulnerabilities come from the plugins they install) but I think the branding removal is pretty wild.
A quick skim through the plugin development guidelines does seem to indicate that trialware isn't allowed, and the plugin seems to be doing all kinds of other stuff that isn't really permitted by the guidelines. I don't know if WordPress is as strict in enforcing those as they are with this plugin, but the changes do seem to be based on them.
With WPEngine recommending people to install their (vulnerable) version, I once again feel like there's no right side in this conflict. What a mess.
The WP security team may have just backported the fix, even using the same line in their changelog [1].
[0]: https://www.advancedcustomfields.com/changelog/
[1]: https://plugins.trac.wordpress.org/changeset?new=3164480%40a...
Because WordPress is licensed under the GPL, all plugins must be licensed under GPL-compatible licenses. This applies to ACF Pro as well.
Matt and WP's position however includes that this applies to the PHP code but not to accompanying assets like images, CSS, JS (because those can obviously be used without WP). Those only need to be GPL if you want to host it on wordpress.org which the commercial versions of those freemium-plugins are not.
My 1080Ti isn't compatible with those drivers, so I do forget about the open sourced ones.
The exact result intended by Matt, I presume. He wants to scare WPEngine's customers away from their services.
At this point, this looks more like a war between personalities.
There only seems to be one personality at play to me.
Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.
Is that an option btw? I.e. is it possible to offer hosting with seamless migration from wordpress.org?
I never said that the license forced them to contribute.
At some point in life, people usually stop believing everything that others “literally said”.
My answer was based on the fact that I’ve seen several people who are unaware of what Mullen’s said that precipitated the row.
Money, more and more money for matt, seems to be the matt's driving motivation here. He seems to be projecting his own greed onto others.
Very astute phrasing. Personal problem.
I've not seen numbers comparing other significant WP users to them, though, only comparing them to Automattic itself, which seems a bit apples to aardvarks to me.
I hate WP Engine - having had first hand dealings with them after they acquired a company I’d spent tens of thousands of dollar with - but nonetheless I fee like there’s probably a pretty strong argument that simple straightforward Wordpress hosting means more people use Wordpress which strengthens the overall ecosystem.
When I first started using Wordpress there was a steep learning curve to get it configured correctly on hosting where stuff wouldn’t break.
I used to pay someone to do that for me, and when they gave up doing that I moved to Flywheel (which was later acquired by WP Engine) and suddenly all of my previous problems with Wordpress from a hosting perspective vanished.
It just worked and the Flyhweel support team was amazing and would even unofficially support the wider implementation of Wordpress (“I changed this and now that thing has broken… I know it’s not your fault but any suggestions?” “Hey, here’s the problem, plus we have fixed it for you!”)
That made me stick with Wordpress for years and build out more sites in Wordpress and recommend it to friends and clients.
Most small businesses (which represents the majority of Wordpress users) don’t want to have to think about hosting: in the same way they expect their mobile phone service to just work, and email to just work, they need Wordpress to just work.
Whatever issues I have with WP Engine they offer a very straightforward “forget about it” service for running Wordpress which ultimately means more people are likely to use it.
If you are a party to this dispute, why on Earth would you comment publicly?
If I were an employee at a company being sued I wouldn't say anything related to it even without an order from legal because I wouldn't want to have to risk answering for it in the trial. Why dangle yourself out there as a target for the opposition's lawyers?
I haven't seen any comments from any WP Engine employees. They have an adult CEO, though, so I'm sure she told them not to comment on it.
If that claim is false, that's perjury.
I feel like Wordpress is going down the same path as Elastic and other companies have done, make something, open source it and then make a fuss when other companies "misuse" their code? If you want that tight control over how others use your code, then maybe consider not picking an open source license?
I wouldn't take how this played out as evidence that WP Engine was opposed to making more significant contributions like sponsoring a real, independent foundation or even putting a significant portion of its revenue toward the project.
And the more I hear him speak - having never really concerned myself with anything he said - the more loopy and disconnected from reality he seems. Post-economic!
Sometimes it’s great to have a slightly crazy visionary with utopian ideals who is prepared to say whatever they think will effect change. But also: Elon.
It's pretty unlikely the company will go completely broke any time soon so their jobs are probably fairly safe.
Damn, where's common sense and logic?
2. It takes one click to find out that she's the "founder of http://Client-Portal.io, a WP plugin for freelancers to use with their clients to keep track of all the deliverables in a centralized portal"
Where's the "attack" part? I thought that was a crucial part in the definition
Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.
That tactic would work, if WP Engine had access to the update server hosted at wordpress.org.
WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.
At this stage no attack has happened(but can happen)
If a bank messes with your money, you ask for your money when that happens. Not defame the bank based that they updated their database, business as usual, but you liked the old one.
how exactly did they mess with your stuff? where's the attack you're speaking about? where's physical harm?
What money? who did you pay? for what?
Who did that? WP Engine was the one making these before the change
I ran servers for an agency with ~1200 WordPress installs on Azure VMs, and I disabled revisions on every one of the sites. How is that different? Did I fiddle too much, despite it being in official documentation on how to do so? Even despite it being actually recommended by Automattic itself for performance improvements? Many of his complaints don't add up. The copyright and WP confusion, I get...but the rest is largely non-sense. Even his Stripe/Woocommerce complaint is largely bunk.
The best outcome is for Matt to step down, Wordpress.org/WP Foundation gets sold to multiple hosting providers (WordPress.com, WPE, 1&1, GoDaddy, etc) and they all commit x amount of money to the project (given it is a very important platform for all of them) and in exchange WPE drops its suit. Unfortunately, I doubt that will happen, because some of this seems very ego driven.
It makes a weird sort of sense. Ie, wp.org backed themselves into a corner where they needed to close the security hole. And to do that, they needed to patch it themselves, which in turn requires them taking over the package.
It’s shocking, yeah. But it would probably be worse if they just left the (known, publicised) security vulnerabilities in.
None of this is necessary.
Pity that there isn’t a comparable eco system that is less…mercurial
https://news.ycombinator.com/item?id=41821336 (165 comments, including 5 by photomatt)
https://news.ycombinator.com/item?id=41824852 (63 comments)
If an app/pluging/package is maintrained and published by X, I want to make sure no one else can interefere with it - even if they have good intentions.
What Automattic should have done is removed the plugin from distribution and told WP Engine to fix the problem. By doing what they did they have breached the trust of their users.
To be honest, none of this makes WordPress look good... It just seems like a douche move.
And then days after WPE makes this update, Matt then hijacks their plugin.
Am I understanding this correctly?
Because the original author (or team?) is probably motivated to move on to other endeavours instead.
He is angry that WPEngine makes money with Wordpress hosting. He thinks wordpress.com should be the only paid WordPress hosting provider.
He demanded 8% of revenue of WP Engine or he would embark on a “scorched earth nuclear approach” to WP Engine.
This is exactly what elastic search faced, which necessitated their changing of their license, and subsequently, caused AWS to fork elastic search.
Elastic search cannot, and do not, have the right to demand payment from AWS.
...What was the end game plan?
We should judge for how it’s being handled now.
In addition, the GPL allows you to do what you mentioned. You can take any GPL-licensed code and use it for commercial purposes without having to contribute back. The license is designed to protect you in this way, and it aligns with the spirit of GPL. Expecting something in return for open-sourcing code is not in line with the spirit of GPL and open-source software. If you're not comfortable with other people making money from your code, it's best not to open-source it.
WordPress.com is only successful in the first place because WordPress was open source and had so many hosting options
Also what do you mean it was modified? WPE didn't fork or modify WordPress any more than other hosts
Now, it's completely radioactive.
1. You are actually building a dynamic site; eg WooCommerce is much easier than building your own storefront.
2. Your users refuse to use Markdown, and are paying you enough to double the overhead and put it all on you.
It gives me a good chuckle when I see posts on here like "We use Wordpress and then scrape the static assets and serve it as a static site from S3". I won't denigrate those people; I'm sure there are good contextual reasons to do that. I just think it's a pretty damning indictment for it to be downgraded from "the software that runs the website" to "a web-hosted WYSIWIG editor for people who can't/won't do Markdown".
- Plugin ecosystem. Marketing people want to use specific plugins for SEO, automatic internal linking, etc. Those plugin only work with wordpress.
- Marketing people want to deploy to production. They hate waiting for dev to do anything (which brings us back to the importance of the plugin ecosystem, to add functionality without developers).
- It's a familiar system that doesn't need to be "learned" by end users (the same way VS Code, VIM, or whatever is your preferred code editor)
If it weren't for the first 2 barriers, I think the 3rd (learning markdown) is the easiest to overcome. Especially with side-by-side realtime markdown rendering, which itself is a form a WYSIWYG.
Edit: FWIW, we moved to Webflow at my company, used to be on Wordpress, and before that used to have a Markdown-compiled site, help docs, and blog. Markdown-compiled was my favorite as a developer (and also the most performant), but it was everyone else's least favorite because it required me to deploy and make code changes, and they weren't patient enough to put a ticket in for every change request. They also understandably didn't want to login Github to make updates to markdown files.
Easy GUI for writing and publishing to production, with no-code installable plugins that extend functionality, is exactly what Wordpress offers that markdown does not.
Webflow has a very similar value prop.
2. Make a fortune.
3. Complain that people are freeloading.
4. Abuse your power as project founder to punish them, torching the community trust you’ve built up over decades.
5. Profit?
Whatever Mullenweg hoped to gain by undermining WPEngine can’t possibly be worth the damage he’s done to WP and his own company.
I can see both sides of the story here, but the scorched earth strategy doesn't seem to be very effective for building trust
But absolutely nothing about a trademark dispute excuses the lies, unethical behavior, and just downright personal animus Mullenweg is pouring into this takedown.
https://x.com/TDKibru/status/1845178985308881146/ https://archive.is/sjuHl
Ironically, Automattic is actively taking legal action against a premium plugin reseller for trademark infringement on modified WooCommerce plugins: https://www.reddit.com/r/Wordpress/comments/1fqw2eh/automatt...
This IS a violent breach of consumer/user trust. Whatever you thought before of this takeover/stealing, this is what trust gone looks like.
No, the core of the dispute is Matt wants either money from WP Engine or for them to contribute to WordPress. He's using the trademark as leverage. However, their usage of WordPress does not imply affiliation instead saying stuff "We bring WordPress to the masses".
The use of WP in their name was them actually following WordPress' trademark policy where they asked people not to use WordPress in their names but WP.
I doubt it will result in a mass migration. Many wouldn't move to a fork. We are very engaged in this kind of news, but the kinds of users who use WordPress often aren't. Our small company actually uses WP Engine, and I asked our owner (who also handles content, marketing, etc, and who I report to) if he had heard of what was going on, and he hadn't.
But, that’s not why he’s getting backlash. He’s getting backlash because he does what the “other side” did in all of these scenarios - invent reasons that are unrelated to the license dispute to cause the split. In this case, delisting their plugins from the central marketplace and implying trademark violations - while claiming that the problem is that they don’t contribute back to the ecosystem.
The real problem is that automattic want wpengine to “contribute their share” - by development or rev share, and they’re using dirty tricks and smear tactics to do so.
I think he has a fair point - I’d be totally comfortable with a standing expectation in a community like Wordpress for companies to pay their way (or be looked down on & excluded from taking part in community events).
But the expectations have to be a fair & transparent, and ideally communicated from the start, so people and companies can make informed choices about how they want to be involved. Not suddenly enforced with no lead time, with demands of money amounts seemingly made up on the spot, and “scorched earth” tactics when the demands aren’t met.
As a rule of thumb, bikes can start and stop fast. Cars should be more predictable on the roads. And trucks should accelerate and turn more slowly still.
If you’re big and powerful (government, standards body, maintainer of a huge opensource project, etc) you need to telegraph your moves and act slowly and predictably so other people can react to you. This is not how you do that.
if only a minority could grow big and sufficiently high revenue generating to be capable of paying anything, then having this concept of "paying back" from the start would've been a chilling effect on the adoption in the first place.
wordpress ecosystem is big, but it is the network effect, rather than the software itself. This network effect require lots of individual participants to kick start it at the beginning. Those participants will benefit from the software being free.
If it was known at the start, that if you grew to a certain size, you'd have to start paying a royalty of some sort (which is the "community expectation of pay or contribution"), then you may not even start using the software in the first place - or at least, consider alternatives. This makes the ecosystem small.
They don't call it bait and switch for nothing. The expectation of contribution will never be transparent from the beginning.
Maybe! But you could say the same thing about every paid service. “Oh, if Netflix charges customers money every month they won’t grow as fast and might never be financially profitable!”. The answer isn’t to remain free forever. It’s to accept the trade off.
And it’s gotta line up with the license too. I’d be happy if the policy was “look, if you’re doing >1M monthly revenue, we expect your company to fund some people full time to work on opensource contributions. (With some specified minimum revenue / developer ratio). After all, your business depends on this free software but software isn’t free to make. If you don’t want to do that, that’s fine - but you’re getting rich off our voluntary labor without giving back in turn. It’s an opensource licence. You’re legally welcome to do that. But know that so long as you do that you aren’t welcome at conferences or community events or spaces since you’ve opted yourself our community of contributors.
I agree with you, but this is a well trodden topic in the development community, particularly on HN - see Terraform for example [0]. One of the problems is that the world WP came to exist in and came to dominate the web in doesn't exist in the same form. There's been a few attempts at thisand they've caused large fractures - nobody has really got it right yet.
On one hand you have a very vocal, and powerful group of people who believe that the freedom of the software is far more important than anything else, and those groups are often backed by large organisations that have the people-power to continue that effort (see: TF -> OpenTofu with Spacelift and co, Redis -> Valkey backed by AWS, and the OG split with Elastic). On the other hand you have a less vocal group who are more concerned with the functionality of the software rather than the original agreement that was signed (fair warning I fall in this category - I'm trying to remain Swiss in this comment), and accept that the terms of the deal have changed in that being Jeff'ed. (My reading of) The value of OSS in this group is the ability to for community to improve things, and to not end up locked into a problem that you have no solution to. The advantage here is that this group can just hitch their wagon to whichever solution appears to win out.
I don't see an easy path out of this that satisfies both camps, unfortunately.
Again I don't see what's wrong with this ? Clearly they have no recourse through GPL but they have trademarks and infrastructure. I don't see anything unreasonable about his behavior.
automattic is worth a few billion. what are talking about?
Wordpress forking and taking over the plugin seems like they've accepted the code/contribution.
Honestly zero sympathy for WP engine, and I don't really see a better way to force them to pay.
While everyone’s ready to grab their pitchforks at Matt, this actually sounds somewhat reasonable. Still, given its impact, this could easily be seen as a breach of trust. Definitely a move that's going to stir the pot.
PS: isn’t WooCommerce doing the exact same?
With my own experience of the WP "community", that isn't a surprise.
WordPress was the one who injected notices into everyone's dashboard. This started because the WP dashboard shows the blogs from wordpress.org, and then they published this post: https://wordpress.org/news/2024/09/wp-engine/
The result was WP Engine removing the widget that shows wordpress.org blogs on their installs.
I assume you work for automattic, right? I've noticed when it comes to comments like this, normally they're made by automattic employees.
Hats of to Matt for at least showing some personality and showing a bit of faith.
Now, go build another CMS. Use Rust or Go perhaps and make sure it can scale wildly
It isn't as one sided as you would imply.
Also, the wordpress trademark policy _explicitly_ listed what they were saying as OK until it was updated last week when they refused to pay his protection racket.