So long WordPress
chriswiegman.com
chriswiegman.com
Of course, my company does have an affiliation with WP Engine. We use their service to host our website. Therefore, nobody on my team can register for a WordPress.org account.
I wrote an open letter to Matt Mullenweg complaining about the requirement and stating that I believe it violates the Sherman Act and Section 3 of the Clayton Act by being an overly broad prohibition that is clearly anti-competitive and has no clear business justification (aside from limiting competition).
Matt and the rest of the people backing Automattic should take note: Moves like this that destroy your community will eventually usher in a replacement. WordPress is pretty neat, but it only got that way because thousands of people put millions of hours into building add-ons and hosting services to make it blossom into what it is today. If their efforts are redirected in another direction, WordPress will wither away to nothing in a few years.
https://www.linkedin.com/posts/ksimpson_open-letter-to-matt-...
Does no one understand what "affiliation" means anymore? Just because I bought something from Amazon doesn't mean I'm now affiliated with Amazon. "Affiliation" (usually) means something like a formal association, partnership, or close connection, not that you're just a customer.
Besides that, dump Wordpress regardless, clearly they've lost focus from the actual users and Matt seems to be fighting some war others can't even see the reason for.
I have a competing product and shouldn't get too far in the weeds on what I truly think here, but the predominant feeling across people that have to interact with this is that it's done on purpose.
It's not so much that people don't understand what the word "affiliation" means, it's that you'd have to be completely certain that a lawyer, hired from what is clearly a litigious org, would have the same understanding.
For example, say your company ends up on Matt’s legal radar and he trawls the logs looking for accesses from your IPs and says you violated CFAA – even if you’re totally comfortable that you’d prevail in court, that could be an expensive process and discovery might turn up things you’d prefer not to be public. In situations like that it’s easier simply not to risk dealing with him since people who are focused on vengeance will often waste resources on pointless activity just to prove a point.
Somebody should really force the issue to "have standing" to fight the ridiculousness. I'm shocked WP Engine hasn't already
I could see a breach of contract argument too.
IANAL.
For example, if you register on wordpress.org while claiming you have no affiliation with WPE, but you did have any sort of affiliation, they could consider the contract null/void, and claim the access was unauthorised because the contract wasn't valid.
His responses to perfectly sensible questions about this ridiculous box has been awful.
(Or, much less charitably, the intentional use of vague language in bad faith.)
No? If my employer asks me to clarify my employment agreement, I don't have an obligation to be their armchair counsel.
It's totally reasonable to ask the party introducing "shall not associate with" into a contract exactly WTF "associating" is supposed to cover.
I’ve made edits to employment agreements. It would be totally inappropriate for the other side to demand legal advice from me. It would be polite for me to clarify. But I’m under no obligation to.
I suspect most people asking Mr. Mullenweg "what do you mean by X" are doing so with a subtext or next-step of "now go fix the text to correctly capture what you really meant."
> with a subtext or next-step of "now go fix the text to correctly capture what you really meant"
That’s unreasonable. An e-mailed clarification is a reasonable ask. (Adding a clarification is nice. But not a reasonable expectation. Especially from a proven nutjob.)
Matt was just asked if the spirit of the checkbox was to keep out customers and wouldn't answer. That's not really the same as asking him for legal advice.
This is fair.
He cannot tell you what Matt means by it. The question stands.
https://www.isba.org/committees/governmentlawyers/newsletter...
I have neither a WordPress.com account (I mean, that I know of, anyway) nor an affiliation with WP Engine. However, can we back up for a minute? If a website is asking me to make an assertion that may have legal consequences, it should absolutely be spelling out the intention and meaning of the language it uses. If you ask me what "affiliation" means, I'll give you my best answer as to what I understand it means. If you ask me to sign a document that says I do or do not have affiliation with some entity, I will tell you to clarify what an affiliation is and refuse to sign without it.
If you use WP Engine, you have an ongoing agreement with them to provide and support a service on which your business depends. A reasonable and literate person could construe that to be an affiliation.
In securities, yes. In general use, not necessarily.
It looks like it's a legitimate legal issue [1][2].
TL; DR It may make sense to explicitly clarify when you're using the term 'affiliate' as it is defined in 17 CFR § 230.601 / Rule 144 [3] versus "affiliate, including but not limited to []," or whatever.
[1] https://www.sackrosendin.com/blog/2017/03/landlord-loses-ove...
[2] https://casetext.com/case/iqbal-v-ziadeh-2
[3] https://www.law.cornell.edu/definitions/index.php?width=840&...
Matt also refuses to provide any elaboration on intent and instead says “you should talk to a lawyer”.
This has the chilling effect he is looking for. No-one is “talking to a lawyer” to create or use a Wordpress.org account. Anyone who has sniffed the same air as WPE knows the intent.
Boilerplate words have all been litigated. Boilerplate clauses are well understood.
Affiliate, affiliated, affiliation, words like these are boilerplate, unless you go to the trouble of locally redefining.
Boilerplate is good but definitions are best, even with boilerplate words that have boilerplate definitions. Incorporating those definitions into the document at the time of execution benefits all parties. Again: minimize ambiguity, anticipate what will make dispute resolution easier.
Source: have worked through a lot of contracts, license agreements, labor agreements, and disputes over the same.
We see the reason. That reason is money. The lies / gaslighting aren't for OSS, etc. It's about MM's bottom line.
My interpretation of their story [1] is that holding the WordPress trademark wasn't enough for 501(c)(3) status, so they had to do something educational like promoting free software.
They transferred the trademark once they received 501(c)(3) status, and could have transferred the operation of dot org too if they wanted.
I believe the consensus among the moderate community is that Matt continues to hold onto dot org for "control", just like how the Foundation's board mostly comprises Matt's friends, and never had actual external community involvement.
[1] https://wordpress.org/book/2015/11/the-wordpress-foundation/
Matt tried to put Wordpress.org as a 501(c)(3) but they ran into problems, e.g. it was a lead gen for paid plug-ins that Automattic owned. So Matt has used his and Automattic resources for wordpress.org for a long time. You can read more about this in the WPEngine suit (page 12). [1]
[1] https://wpengine.com/wp-content/uploads/2024/10/10.18.2024-P...
> Matt tried to put Wordpress.org as a 501(c)(3) but they ran into problems, e.g. it was a lead gen for paid plug-ins that Automattic owned. So Matt has used his and Automattic resources for wordpress.org for a long time. You can read more about this in the WPEngine suit (page 12).
Where in the lawsuit does it mention that "they ran into problems" transferring operation of dot org to the 501(c)(3)? All I see on page 12 is:
> Until recently, Defendants had given the WordPress community the impression that wordpress.org—the repository for the WordPress software and plugins—was owned and controlled by the WordPress Foundation.
Edit: I found it from a link in a different comment:
https://www.pluginvulnerabilities.com/2024/10/28/matt-mullen... (primarily https://x.com/photomatt/status/1840948013360910448)
A more appropriate question perhaps: can a lawyer specialising in US nonprofits corroborate Matt's claim?
[1] https://old.reddit.com/r/Wordpress/comments/1g5o4n5/why_is_w...
It’s a well trodden path used by tons of nonprofits like the Smithsonian, Mozilla, OpenAI, etc. when they need to operate something that the IRS won’t grant tax exemption.
They formed WordPress Community Services PBC, which now runs the "official community" WordCamps, so sponsors didn't have to restrict their messaging:
https://wordpressfoundation.org/news/2016/introducing-wordpr...
Are these supposed to be examples of how this kind of setup turns out well for the community? Because they are the opposite.
Mozilla Corporation is the one receiving the hundreds of millions of dollars from Google that funds almost all the the development of the Firefox browser. Without it, Mozilla would be a tiny fraction of what it is now and FF would be dead in the water.
This is entirely orthogonal from the community. It's an IRS requirement.
How do you know? I mean sure if the Mozilla Foundatio wouldn't have bothered with any alternative fundraising opportunities, but that's not exactly a realistic alternative realtity, is it?
> and FF would be dead in the water.
FF is dead in the water. It's market share is small enough that devs don't care about it anymore and it doesn't really provide any real advantages to users unless you really care about telemetry data going to Mozilla instead of Google. Mozilla has don't pretty much all it can to kill any kind of differentiation while refusing to innovate at all.
Someone's getting paid something for the hosting referrals here:
https://wordpress.org/hosting/
I quote from the page:
> If you do decide to go with one of the hosts below and click through from this page, some will donate a portion of your fee back
https://www.pluginvulnerabilities.com/2024/10/28/matt-mullen...
Whether or not Wordpress.org makes money is irrelevant to its for/non profit status. It’s a legal technicality due to IRS tax exemption rules for unrelated business activities. They have to put those operations into a separate subsidiary, even if it never makes any profit.
If the nonprofit can’t afford to run Wordpress.org then the whole nonprofit was a farce anyway.
[1] https://projects.propublica.org/nonprofits/organizations/205...
He needs us. We don't need him.
Unfortunately, anecdotally, there's a lot of group thinking in WordPress. It's one of the reasons "The WordPress way" is able to run counter to industry best practices. Most people don't know any better, and the handful who do don't speak up. It's a textbook case of toxic kindness.
Given the collective actions / behaviors / culture, I've been saying this for close to 10 years:
It's not a community. It's a cult.
It also leads to "big fish in a small pond" syndrome, where people in the inner circle start to think highly of themselves, to look down on the "newbies" and users. They value thier expertise in this niche without realizing its relative poverty and low quality in the larger context. It's a mix of arrogance and ignorance that insulates their ego.
I hope the collective disillusionment that WordPress is going through will be healthy for ecosystem in the long run. Let a hundred forks and alternatives bloom!
Nope, that's a bus factor of one. I'm done.
You may not consider yourself an affiliate but if the lawyers decide you are a teapot then you are either a teapot or were very rich.
If only he'd said no as well - not doing so seems petty.
Send a copy to your state AG [1]. Copy your governor’s office [2] and state representatives if you have the time.
Insert Twitter, Reddit, Digg, MySpace, etc... at the beginning of that quote. The people who own the social networks rarely give a shit about the users once they hit critical mass. And the owners will eventually burn it down or enshitify it beyond recognition.
yes!
bitkeeper tried licensing shenanigans and lost to git.
smalltalk did licensing shenanigans and lost to Java.
Qt almost died and motivated Gnome.
In software, inacceptable licensing gives birth to your worst competitor.
/s
I'm not involved in any of this except as a spectator. I don't even use Wordpress. Just saying, I could see why someone might not want to split legal hairs with their leadership right now, even where it's very likely you'd win such an argument in court.
I wouldn't be so sure. He seems to have gone off the deep end. I know folks, including some successful ones, who legitimately believe that anything that commercially hurts them is illegal, and when a judge sides against them, it's due to bias and not the law.
(I don't know if this type of auto-victimisation has a name. You see it parodied by South Park in "The Worldwide Privacy Tour." And, less hilariously, by public figures complaining about their free speech on talk shows and at press conferences they called.)
Sounds exactly like one of the candidates running for POTUS!
One time a friend of mine was showing me a bunch of fancy camera gear he'd bought for his wife's ghost hunting business. I pulled him aside and asked him if he really believe in the spirits and apparitions she talked about. He replied, "oh, for tax purposes I completely believe this bullshit."
By analogy, even if Matt's lawyers privately agreed that a lawsuit over the meaning of "affiliation" is silly and doomed to lose, I can imagine them replying "oh, for billable hours I completely believe it."
Most commonly this comes in the form of false victimhood, e.g. look at how hard they are trying to shut me down. Other times it manifests like this. The problem is it's a logical attractor; whatever belief it first attaches to, it monotonically increases faith in.
In the JS ecosystem if you have an issue then you usually go look it up and someone either recommends a fix or a NPM package to get around the issue you are having. With WP when you tried to figure out an issue it was always endless blogspam with an upsell to a plugin or consulting services in the end.
I remember reading so many articles on really basic topics where the author would dance around the solution before finally going "well if you want the real answer, please hire my WP consulting firm and we can take a look".
And with plugins I found it very hard to find anything open source or free. Every plugin, no matter how small, always seemed to have it's core features locked behind a "premium" version. Now I get it, plugins take time to develop and people want to be paid for their work but it was just really jarring to go from a community where folks contribute to developing the best solution for something together versus everyone hacking it on their own because they wanted to sell a plugin.
You ran into all these commercial plugins and consulting services, because that's what most of the WordPress community is. People having their own company, hosting or maintaining sites for others and on the side developing commercial plugins.
To me this begs the question, whether making everything open source and available for free in your own free time or while working at some big corp as is the standard in the JavaScript world, is really the better alternative?
At least the WordPress community has found a way to sustain themselves, provide services to tens of thousands of small to big businesses, while the JavaScript community seems to be mostly dependent on big tech to keep the lights on for most services.
https://chriswiegman.com/2024/10/this-site-now-runs-on-hugo/
I can understand WP for non-technical users but I'm still amazed at web dev teams still not using static sites for blogs and marketing sites.
Hugo might be easier as long as there’s no customer facing CMS, but as soon as you introduce that back into the mix it’s significantly worse. I heard if one shop using CraftCMS successfully but they weren’t really super content forward.
Thus, to cover the spectrum of needs, it just makes sense to have a Wordpress stack - one team of developers, on team of technologies.
Hugo is great, but I haven’t used it a ton. For a lone wolf dev maintaining a personal site, probably the way to go. I built some sites with Gatsby and having to do Node updates was actually way worse than Wordpress updates, and required a much higher skill level to accomplish.
Not sure what you mean. You can use any DB you like.
There are even storage services like CF Workers KV if you don't need relations etc.
- easy client login for template tweaks, uploads, and redirects
- forms
- extremely minor server-side functionality thing
WordPress is perfect for this.
Wordpress killer that accomplishes these things you mentioned would interest me. Statamic looks interesting in this context but it wasn’t super well formed 4 years ago when I dug deep into this ecosystem
Maybe something along the line of a Cloudflare Worker (but using the open source stack) or possibly something minimal and flexible based on WASM or JS that could be invoked from different servers could work.
When I figured out that Wordpress literally is executing every piece of PHP every time the site loads it was kind of a “woah” moment for me
Interesting idea with the Cloudflare thing
I don’t think Cloudflare workers, as deployed by Cloudflare, really tick that box either. Some of the university “scripts” systems, with CGI backed by AFS, came kind of close.
They mostly do. You can map different Workers to different paths in your site. A Worker can only access the resources it is explicitly bound to. E.g. if you create a KV namespace for storage, a worker can only access that namespace if you configure it with a "binding" (a capability in an environment variable) pointing at the KV namespace. Workers on your account without the binding cannot access the KV namespace at all. Some more on the philosophy in this blog post:
https://blog.cloudflare.com/workers-environment-live-object-...
There are a couple of caveats that exist for legacy reasons, but that I'd like to fix, eventually:
* The HTTP cache is zone-scoped. Two workers running on the same zone (domain name) can poison each others' cache via the Cache API. TBH I want to rip out the whole Cache API and replace it with something entirely different, it is a bit of a mess (partly the spec's fault, partly our implementation's fault).
* Origin servers are also zone-scoped. All workers running on a zone are able to send requests directly to the zone's origin server (without going back through Cloudflare's security checks). We're working on introducing an "origin binding" instead, and creating a compat flag that forces `fetch()` to always go back to the "front door" even when fetching from the same zone.
Note that if you want to safely run code from third parties that could be outright malicious, you can use Workers for Platforms:
https://developers.cloudflare.com/cloudflare-for-platforms/w...
(I'm the tech lead of Cloudflare Workers.)
(EDIT: lol wrote this without reading your username. Hi, Andy!)
In the old days, if I wanted to deploy a little script (on scripts.myuniversity.edu, for example), I would stick the file in an appropriate location (~username/cgi-bin, for example), and the scripts would appear (be routed, in modern parlance, but the route was entirely pre-determined) at a given URL, and they could access a certain set of paths (actually, anything that was configured appropriately via the AFS permission system). Notably, no interaction was needed between me and the actual administrator of scripts.myuniversity.edu, nor could my script do anything outside of what AFS let it do (and whatever the almost-certainly-leaky sandbox it ran in allowed by accident).
But Cloudflare has a fancy web UI [0], and it is 100% unclear that there's even a place in the UI (or the command-line API) where something like "the user survey team gets to install workers that are accessible at www.site.com/surveys and those workers may be bound to resources that are set up by the sane team" would fit. And reading the "role" docs:
https://developers.cloudflare.com/fundamentals/setup/manage-...
does not inspire confidence that it's even possible to pull this off right now.
This kind of thing is a hard problem to solve. A nice textual config language like the worker binding system (as I understand it) or, say, the Tailscale ACL system, is nice in that a single person can see it, version it, change it, search-and-replace it, ask an LLM about it, etc. But it starts to get gnarly when the goal is to delegate partial authority in a clean way. Not that monstrosities like IAM or whatever Google calls their system are much better in that regard. [1]
[0] Which I utterly and completely despise, but that's another story. Cloudflare, Apple, and Microsoft should all share some drinks and tell stories of how their nonsense control panels evolved over time and never quite got fixed. At least MS has somewhat of an excuse in that their control panels are really quite old compared to the others.
[1] In the specific case of Google, which I have recently used and disliked, it's Really Really Fun to try to grant a fine-grained permission to, say, a service account. As far as I can tell, the docs for the command line are awful, and the UI kind-of-sort-of works but involves a step where you have to create a role and then wait, and wait, and wait, and wait, and maybe the UI actually notices that the role exists at some point. Thanks, Google. This is, of course, a nonstarter if one is delegating the ability to do something useful like create two resources and link them to each other without being able to see other resources.
(Hi Kenton!)
1. If you have a relatively small number of users whom you want to permit to deploy stuff on parts of a Cloudflare account, you may need to wait for finer-grained RBAC controls to be fleshed out more. It's being worked on. I really hope it doesn't end up as hopelessly confusing as it is on every other cloud provider.
2. If you have a HUGE number of users who should be able to deploy stuff (like, all the students at a university), you probably want to build something on Workers for Platforms. You can offer your own completely separate UI/API for deploying things such that your users never have to know Cloudflare is involved (other than that their code is written in the style of a Cloudflare Worker).
Heck, one could probably even build middleware to deploy regular workers for this type of use, where the owner of the worker has no Cloudflare credentials at all and only interacts with the middleware. (Other than the origin and cache API issues.)
To be clear the two caveats don't apply to WfP. The cache API is disabled there. The origin thing can be solved by installing an "outbound worker", which intercepts all outbound requests from the untrusted workers and so can block unwanted requests to origin.
Eg, you'd drop some html into public_html folder and an executable into cgi-bin dir. I would performance engineer some scripts into C++ binaries and just checkout the source & run make to produce binaries in-place. This approach made it easy to use local dev tooling to test/debug stuff instantly via oldschool emacs TRAMP/sshfs.
There is a system that replicates the simplicity of what we lost (while letting you use fancy modern JS frameworks): https://www.smallweb.run/. It also offers a path to cloudflare-like edge computing migration without any code change via deno deploy. With smallweb, one drops a bunch of files into own dir (eg, you could give a dir to each student), which results in https://<dir>.domain.name running stuff ondemand in that dir. No build step, no exotic runtime to transpile into, full ability to use local dev tooling to test/debug stuff instantly. It's still early days for smallweb, but it's specifically designed with the philosophy of "edit some files and stuff runs..while remaining compatible with standard deno way of doing things".
I love the concept of cloudflare workers[1], their fancy state management, bindings, etc, and the fact that they took inspiration from cgi-bin. However, the fact remains that it's an exotic system with weird restrictions (hello changing your apps around 500mb chunk limits ala https://github.com/cloudflare/serverless-registry). This limitation can make it difficult to work with libraries that aren't tested against the cloudflare runtime. 90% of code I write would run better with cloudflare than with deno (due to awesome cold startups), but dealing with these restrictions is too much engineering overhead upfront.
In contrast, with deno/smallweb, I just drop some files into a directory, don't need to bother with package.json, lockfiles, etc, but can gradually opt into those and then gradually switch to CI/CD mode of operation. You can't expect a student new to web development to deal with the exoticness of cloudflare's solution from day 0.
[1] Kenton, it's a fantastic design, I sang praises to it in https://taras.glek.net/posts/cloudflare-pages-kind-of-amazin.... But after trying equivalents in deno ecosystem like val.town and smallweb I would love for it to be less exotic(I know you guys have more node compat work happening).
It's trivial to bundle and deploy some server-side code with a static site on Vercel, Cloudflare, Firebase, or Netlify.
Usually you simply create a /functions directory wth your JS code and that's it.
Well said. Our agency chose WP Engine over 8 years ago because they were hands-down the best managed WordPress hosting provider. It revolutionized our WordPress hosting offerings and allowed stable, mostly headache free growth. Without the WP Engine's platform, and their investments in making WordPress hosting modular and safe we'd still be in the stone ages of dedicated/vps hosting.
What kept us as a customer for these 8 years though, has been the quality of support. It can't really be measured, but I've found their support to be unmatched and highly competent over hundreds of interactions.
We've grown over 400% with WP Engine and this entire fiasco with Matt blindsided us. Begrudgingly, we're diversifying our hosting allocations to protect against this new threat but we'd be much happier continuing with just WP Engine.
It's sentiments like this that really undercut Mullenweg's arguments. "WP Engine didn't contribute to core" when Core was just the preapproved feature list that was important to Automattic. Even if WP Engine wanted to contribute, their work would have just lined Automattic's pockets (hence why he just asked for money in the shakedown).
https://www.reddit.com/r/Wordpress/comments/1fsie1i/top_word...
Any others that people recommend? Will be looking for a basic website platform, blog is secondary, no e-commerce, minimal use of plugins, open source and hostable, where everything can be done in a Web UI with exception maybe of site templates. API would be nice to help with conversion from WordPress.
HTMLy also seems to be similar to what you describe. I've been trying it out with a couple of basic projects, and it seems to be a good option that I don't see many people mentioning.
With WordPress, there are 5 different plugins already built that have more features than the dashboard you're planning to build, and the agency/person maintaining the site may already be familiar with them. WordPress and other PHP CMSes may not have the best architectures (Drupal was downright atrocious), but the ecosystem is thriving with pre-built, customizable tools for the 99% of customer needs.
Virtually all web hosts, including very cheap ones support PHP-cgi and MySQL, so deploying WordPress is frictionless. CMSes written in other languages have deployment more friction.
You find 4-5 real people that need a Wordpress site every month? Where do you find these people?
Designers and agencies are more than happy to continue to use it, and frankly they should -- it is their bread and butter. The WP drama is news for us web-devs but will affect their market in no way whatsoever.
Most successful shops I meet or talk to are all-in on Wordpress and I don’t think this drama has affected this calculation. Big Indian SEO + Wordpress firms with American sales teams rule this market.
I haven’t done freelance web work in a couple years, but I remember pouring a couple hundred hours into exploring static generators and alternative CMSs just to decide that yeah, Wordpress was probably the cheapest and most user friendly option to.
Drupal does have a learning curve, it doesn't have the robust marketplace of off the shelf themes that WP has, but I love it.
I don’t know if any place where Drupal has been successfully used except for large corporate blogs, which I think it seems well suited for, but I’m happy to be corrected here.
It wasn’t for me but I’m glad you like it! If you’re well suited to it I think it’s a great career path.
The situation has really improved in recent years. Drupal 10 and 11 (the latest stable versions) are mature, the module ecosystem is robust, and there has been a renewed focus on usability.
It's not the right choice for every site of course, but I think people who have had a bad experience with it in the past should give it a second chance.
My assessment of Drupal is that it really is only for enterprise blogs - it doesn’t offer the things a more robust framework would offer. So it makes sense if the scope of work is a blog for a large organization that has 100,000 to spend on a blog. It seems like most Drupal contracts are in that range, so it becomes more of a game of scoring those contracts than anything else.
You really need a team for that. I switched to Wordpress for just that reason, it’s a lot easier to tinker with.
I love to hear that has changed.
It's definitely a good choice for migrating from d7, and could also be a great choice for a new site for someone who enjoys working on a classic drupal stack.
The people behind it are great, but the community right now is kind of small.
The underlying source code is terrible, but it's pre-existing plugin ecosystem is unbeatable.
There are not many other self-hosted services that really compete at the same level.
It is a fascinating code base that is a result of it evolving through end user needs, over years, rather than being a grand software architecture with developer ergonomics at the core. Last time I touched it, changing domain names and sync dbs all required plugins. Yet in page editing works like magic.
I assume no-one building Wordpress today would build it like it is build.
and then a bunch of SaaS platforms. what are the market leading open source CMS's?
These days I’ve moved to Laravel but all of my friends in WP world are bummed that their livelihoods are being toyed with by the former BDFL now just DFL.
Definitely been tempted to use it but as others have said to do anything useful requires a ton of plugins that integrate in weird ways and have to pay subscriptions for the useful features.
But still I think it is one of the best ways for non-technical people to creating websites quickly.
People who are serious about building community will put their trust in others. They will delegate. They will listen to advice. They will compromise. They will be imperfect; they will fail to do the best thing for the community from time to time. But when that happens, more often than not, they will listen and adapt to criticism. We may still call them BDFL. But they aren't truly a dictator.
People building petty fiefdoms will inevitably betray the community.
When I read about Mullenweg, something I'm struck by is his cry bullying. I see him responding to complaints like, "are you threatening me? I get a lot of death threats." I bet he does get death threats, and to be clear it's not okay that he and other public figures have their lives threatened.
But it's common for him to respond to people telling him to go to hell as if they were making an actionable threat. See [0]. I would be upset if someone hoped I "[died] a forever painful death involving a car covered in hammers that explodes more than a few times and hammers go flying everywhere." But I would know they were being hyperbolic and flipping me the bird, not making a threat. (Especially if I was familiar with Tumblr's culture and the texture of humor on the platform. Like you might expect from the CEO.)
And I certainly wouldn't respond by doxing them. And this is really important; doxing someone is actually putting them in jeopardy, with no hyperbole. Doxing someone is an actionable threat of harassment. This is a betrayal of the community's trust, and the exercise of power against the community's interests.
I've seen some other examples of him mischaracterizing insults (including milder ones than this) as threats, but I wasn't able to find them in my timebox. These were screenshots from Twitter and possibly Slack, presumably I could find them if I had accounts on those platforms.
You can also look at the recent controversy as an exercise in cry bullying. "WP Engine is so unfair to the community," he cries. "They deprive people of the essential feature of having more than 3 revisions without changing a setting." Then cuts a large subset of the community off from things that are actually critical, like logging in and updating plugins. He betrayed the community and exercised his leadership position to prosecute his personal quarrels at the community's expense.
I apologize if this was a rant, but here's the point. We should be thinking harder about open source governance, because there are no benevolent dictators. Positions of power corrupt, and they also attract the corrupt to them. When BBS operators were powerful in our community, they attracted (at least one) con artist(s) [1]; now we see a BDFL using our community to rule as a petty tyrant.
When we want to adopt an up and coming project, we should ask the BDFL what the plan is for turning over power to democratic mechanisms in the community. When a new project starts only 1 or few people are there to make decisions, so a BDFL is the natural state of things. But we should expect governance to become more sophisticated as a project becomes more important.
We should learn to recognize the rhetorical mechanism a petty tyrant uses to conflate their interests with the interests of the community. Be suspicious of them. Push back. Ultimately, there are two mechanisms to hold a petty tyrant accountable; forking and rewriting. We should be prepared to do that.
Maintainers reading this might say, "oh, great, not only are people going to open up spurious issues and feel entitled to my time, but you're asking them to be a peanut gallery trying to hold me accountable to democratic mechanisms. What a pain in the ass." This is a solid objection which I do not have a good response to.
Another objection I don't have an answer to is the very real issues projects like Redis and Elasticache have encountered, where platform giants capture the value without contributing back financially. That's a real problem I'm not smart enough to solve, and it does complicate what I'm suggesting.
[0] https://techcrunch.com/2024/02/22/tumblr-ceo-publicly-spars-...
A recent one, from 9 Oct 2024: https://x.com/kellie/status/1844007729284923901
@kellie (Kellie Peterson) asks:
Has anyone tried turning @photomatt off and restarting him?
@photomatt (Matt Mullenweg) replies:
By “turning off” do you mean my life should end?
As someone who's interested in community dynamics like these, I think pure drive-by democracy wouldn't work (I dislike bikeshedding [1]), but a system where people who've contributed either money or quantifiable effort over a recent period of time in exchange for voting rights to elect administrators might.
"A recent period of time" is important, as communities don't really appreciate some old founder-type who's not active in a project anymore trying to use their clout to feed their ego.
As I've seen in other comments, the community seems to be a lot of plugin developers wanting to make money with their plugins. And the quality of the code seems to be patches on patches and have become quite a mess and not nice / easy to work with. Well it's PHP for starters so that's already not a great start in my opinion. That is why I moved away years ago from my first language PHP, to a in my view more mature and more professional community like Python and Django. And I really don't think stuff like this would happen there. Because people are more about working together and making something really nice instead of making money with plugins.
Do you need it?
There are way better options today.
It looks like whoever owned that site transferred it to someone more willing to take on some (possible) legal risk.
It's like WordPress, but instead of digital, it's physical.
It requires no servers or computers at all.
Just paper, which you can make from naturally growing trees, and ink (I'm not sure how that is made).
Your blog will last a long time, like hundreds of years.
You can read it while sitting over your poo hole.
Visit our worksite and check it out.
- Johnny Gutenberg
Sorry to be an asshole but this is a good lesson on not to over index your life on a single idea.
Things change, and you move on. If someone got divorced, would you say that's a good lesson to never get married?
Whether after 10 years you don't end up regretting the decision or not is something you probably can't control.
Marriage like any other social constructs primarily focuses on preserving culture in sacrifice of individuals.
That said, I don't think the author's experience with Wordpress has poor transportability into other niches anyway.
Java is open with competing implementations from Oracle, Redhat,AWS and of course OpenJDK and several other providers.
IKVM.NET is active but only supports Java 8.
Being disciplined about this is very difficult, see RMS. But it is the way.
So is every piece of software implicated in this drama, including Advanced Custom Fields (free edition)
I really don’t see how the discussion of open source pertains to Wordpress