Not just (forking and) signing, but considering he runs the "official WordPress plug-in repository" as well, he pretty much conducted a supply chain attack.
I’m not sure how and why controlling it today is seen as an important thing. It’s not irreplaceable, you could reimplement all its basic features easily in a weekend with AI, as well as the plugins and theme you’re using with it. And you could pick a language other than PHP while you’re at it. You might have your own security vulnerabilities, but anything’s better in that department than running WP.
Why do people care about wrestling over control of this particular ship?
I'm saying that every web property I've ever seen logs for is swept at least daily for /wp-admin/... and similar URLs. I've also seen WP instances left unpatched become completely taken over by spammers in a matter of days.
Any software package with an install base of 1, whether human coded or vibe coded, by junior engineers or by Fable, will not have an organized ecosystem of "webscale" exploiting, unless the property in question is of incredibly high value. In that event, dedicated black-hats and state actors will always be targeting it explicitly no matter what software it runs.
This isn't a joke, this is now part of my pre-launch SOP. I even have it tracking everything so I can log stuff to fix vs. known shippables vs intentional design/false positives vs. upstream stuff which doesn't have a fix available yet, and keep track of which builds have the fixes. Almost entirely automated, I mostly review the findings and do some categorization/enrichment during the pentest review stage, and do a human code review pass as patches are submitted.
Stuff that used to take me multiple hours to write a fix for and then weeks to get code reviewed and deployed now get done in minutes.
It's pretty simple, you could probably set up something like that by:
Configure some kind of CLI tool to talk to your ticketing system and git repo so you can programmatically interact with them. If you don't have a ticketing system, instruct the agent to use local text or markdown files to track issues and progress.
Ideally, make your code runnable in a way the agent can use. For my webapps I build a test harness so that I can run all the endpoints and workflows via reproducible tests against an embedded database. This is easier than it sounds, e.g. there are libraries out there to embed PostgreSQL or SQLite into source code, you can set up a test harness so you can run unit tests, integration tests and workflow tests that use your real frontend, server and database.
Paste this comment thread into the agent prompt and tell it to run a similar loop on your code base: a session that searches for vulns and writes up a report, some way for a human to do a review pass on the report, a session that indexes the reviewed findings into tickets, and sessions that fix the fixable issues and submit patches to your repo. The next search session should first read all the open issues so it doesn't duplicate work of earlier sessions.
LESS IS MORE - avoid fancy agent tooling and skills, don't cargo cult from others, build your own tools as you find your own needs. If something can be automated, use the agent to write tools and tests for it, don't just keep prodding the agent to do it.
I remember Facebook's corporate news sites [1] were running on WordPress.
I just checked. Some of them still are.
Oh, the irony.
[1] e.g. https://about.fb.com/news/
Cloudflare did that:
https://blog.cloudflare.com/emdash-wordpress/
I haven't heard of anybody but Cloudflare using it though.
Name recognition still means a lot. WordPress is baked into most hosting platforms now so SMBs just reach for it. Most of them won't hear about this b.s. and honestly the platform can continue to run on momentum for years.
There's a whole ecosystem behind WordPress that, while it's a security nightmare, is also pretty damn useful. You can't vibe code that yet, you have to build it over years, if not decades.
To be fair, I think a lot of people would have far better user experiences if they asked Claude/ChatGPT/preferred AI to rip out nag screens that many of the plugins are riddled with.
That's probably the first step to them vibecoding their own sites, but most people would likely just want to stay on the WordPress sites they already have, because they don't want to spend time and effort getting up to speed with new UX, or worse, being their own website product manager if they have to vibecode something from scratch. (Until something catastrophically breaks and they need to do a new greenfield site, I guess.)
It is very empowering for people with limited skills.
It's not the code or product, but the user base and time with it. Google, meta, etc aren't successful because of their product. It's because of the momentum and product scale. You could make a new Instagram easily. You can't get the user base to switch easily.
And I even get that large, complex WP-based sites at least seem to have a lot of inertia keeping them there.
I'm just saying that I'm shocked Wordpress is something that anyone thinks still has upward momentum left in it. I would expect that 50 competitors to WP would be expanding their abilities to replace it, replicating and improving all its features, adding import functionality to make that migration easy, and building their own in-house plugins that would probably work for 90% of deployments without the malware risks of the wider WP plugin world.
And yes, I get that WP is still Free Software, but in my career I've seen most businesses paying for all-inclusive "WP hosting" (including what I assume is most of the work, patching). So the competitors I'm speaking of would specifically be competing with WordPress.com SaaS, rather than the "idea" of WordPress (The software).
I guess there probably are that many alternatives, I'm just shocked the WP branding has been enough to keep it relevant despite its disadvantages, bad security reputation, and insecure architecture.