From the point of view of the user, Wordpress is incredibly simple and intuitive. Don't underestimate how important it is for the average user to never see a terminal, and rarely if ever see the source code, for the application to feel comfortable to people most familiar with Windows applications and web forms. Anything more technical than that is intimidating.
Most people who use Wordpress aren't programmers, don't want to be programmers, and don't want to hire programmers to get their site up and running. The simplicity of installing new plugins and themes is far more important than the quality of the code.
A few years ago, while searching for a development role, I was rejected by couple of people at a company with feedback that my code sample was not of good quality. Later I got the chuckle when I noticed the same people subscribed (paid) to my service that uses the provided code sample.
- huge and powerful
- vividly maintained and extended by lots of developers
- rarely features security issues which aren't fixed immediately
... the question arises whether the quality of its code base is in this case maybe rather an academic issue.
I tried to use WordPress once. I downloaded a theme from wordpress.org with the assumption that themes are reviewed before making there. Nevertheless, I did some basic pentesting before putting my app live, and I quickly found a XSS vulnerability in the search bar of the theme (their paid version featured the same vulnerability). Maybe my experience is not to be generalised to WordPress in general, but it put me off.
WordPress plug ins are - as far as I know - not reviewed. You're at the mercy of the respective developer.
>Currently there are 224 plugins in the review queue, 198 of which are awaiting their initial review.
Pretty much the truth of any product (software or otherwise) really.
- I am a programmer (at least that's part of what I do)
- My blog is 50% about programming
Still - I don't see any reason why I would want to spend even a minute longer on the layout or some backend processes.
And I even less understand why anybody using a blog would want to or even need to use a terminal for that purpose ...
But most modern frameworks and CMS platforms seem to take for granted that everyone moved on from FTP to git ages ago, which isn't the case.
I could possibly imagine someone writing blog posts in markdown or plaintext and pushing them somewhere, but that would be the edgiest of edge cases, and even then a native app or web form would be more intuitive.
If I were actively writing a blog, it would be administered in the shell as well.
Surely the point was that the shell is unimportant for the vast majority of users, despite some HN missing its power.
WordPress was my gateway in 2008-9 to web development. back when I was still a graphic design student. I started off hacking away at themes with my extremely limited HTML / CSS / PHP knowledge back then. Shit, my Google-fu was't really even halfway decent then.
Today, thanks to the large community of developers working on the core WordPress project every day, and the sheer number of bug fixes, security updates, and new features that get added with each release -- there's absolutely nothing to compare it to. It runs nearly a quarter of the entire internet.
And now, with the upcoming release of the JSON REST API as a part of core, developers will be able to take advantage of using WP as a data backend (read: users still control their content), while using the API to build applications with modern tech like React or Angular.
Just my two satoshis.
Edit: I'd also like to point out that several (not all) hacks come from popular themes and plugins that are created by 3rd party authors / sources. Some of these are not available on the wordpress.org theme and plugin repositories, and usually this is due to not following certain standards. I would blame most successful hacks on brute force attempts against sites with admins who leave their username as the default admin and have incredibly weak passwords. I would also venture to say most of these hacks come from through exploits in third party code or out of date code, which users often fail to update.
That's open to debate. I have 3 websites running on Wordpress, I don't have the intent to use anything else. It's simple and comes with batteries attached, especially for people who aren't hacking the code themselves. The plugins/themes are a big plus and so is the community. In what way is it terrible? Have you used it enough?
> CMS as a whole is bad
No. CMSes serve a purpose and serve it well. Btw, TechCrunch, Fortune.com run on Wordpress too.
> Why has no one built a better one?
There are a lot of other CMSes. Different names of course, Drupal, Joomla, Django-CMS. Different languages too.
> Why lack of traction?
There's enough traction... Updates to the core/themes/plugins are frequent. There are a lot of performance updates coming up, along with PHP7 and HHVM, which will speed things in general.
Also, WP plugins can be monstrosities of cosmic scales. An pure exercise in delegation.
It's not my main job, but regularly people are looking for people to work on WP codebase, so I had to come back to it a few times.
It was in 3.7 days IIRC, I remember an article saying v4 would be a departure from the old model but I can't find it again.
Not sure what you have against hooks per say. They are just a form of event callbacks that any such system would require.
Hooks are ok, too much hooks and too much global states made if hard for me to understand order of things.
2) Momentum, inertia, market position, "path dependence," installed base, and community. Also not a show-stopper for those wishing to improve on WP technically, but a huge hurdle to cross for anyone wishing to encourage investment in alternatives. Large user bases create virtuous cycles of investment and improvement that fix previously broken things. Sure, it may not always be pretty, but WP now how has WYSIWYG editors, versioning, increasingly automated updates, ever improving admin features, and many other things that were hopeless in previous versions.
3) LCD. WP works on virtually all platforms, and is a credible lowest common denominator in terms of technology used (PHP, MySQL) and breadth of support. There have been some attempts to ramp up alternatives, but they often require one to use Ruby on Rails, Python and Django, or other less-LCD tech.
4) Chicken and egg problem. I have no doubt that at some point another CMS/publishing platform will arise to supersede WP. It's the nature of tech things. It's unlikely we'll all be using WP in 2025 or 2045. But as a developer who definitely wants a more elegant, extensible CMS platform, and who has the tech skills to jump languages and environments, I've never found a better alternative to invest in/build on. There are frameworks like Rails, Flask, Django, Meteor, etc. we might use for custom apps. But a built-out, reasonably-supported, rich CMS / web publishing environment? I haven't found an alternative I can credibly present to customers, co-developers, and designers as an up-and-coming, likable, very-likely-to-succeed platform we should build on. Linux over historical Unix, nginx over Apache, or Go over C or C++? Sure. There is no general-purpose X I could broadly recommend over WordPress.
Strong framework, component based, lots of basic features, looks and operates a lot like WP. But, much harder to install than WP, less featured (esp. when common plugins are considered), vastly smaller community and supporting base of plugins and themes, yadda yadda.
Tens of thousands of plugins to do almost anything you could possibly ever need to do. When you're building websites for a client on a budget, the availability of plugins goes a long way.
1) It's "good enough". Sure it is slow. Sure it is kind of buggy. Sure it gets hacked a lot. But at the end of the day, it mostly works. Harder to disrupt something that mostly works.
2) Traction. It has 1000s of plugins and themes. To get big, someone else would need a lot of plugins and themes. But no one will make plugins and themes for someone that is not big.
3) ease of use. I know a lot of people that WP admin and make WP websites for a living. They are not technical in the programmer sense (although some can hack a little PHP). They don't really want to have a giant MVC architecture with DAOs and Angular and Node.js and blah blah blah. They just want to throw up a blog like website.
TL;DR : The sheer amount of work to get at least to the level expected by the users outweights most motivations. Maybe one day someone will come with a way better solution, one which Wordpress cannot cope with. And then, we will have another cycle. ;)
If you have a small business that needs a site, but your not savy to do it yourself, you ask a developer to build you a wordpress site. You know that even if said developer is gone in a few years, enough people know wordpress that it can be maintained..
A lot of alternatives do individual X, Y, or Z functions better than WP. None I've seen have achieved a reasonable fraction (say, >40-70%) of the extremely broad set of aggregate requirements the entire developer, designer, and user communities would need to commit to a WP replacement.
Unfortunately, the can of worms that opens up in Wordpress is one of the worst things about it. Every plugin and theme is essentially its own ad-hoc web application running with global privileges.
Even if they did manage to, they'd have a massive amount of momentum to overcome in the form of the theme and plugin communities; there is so much turnkey extensibility available (for better or worse) that it comes with an awful lot of end-user value baked in out of the box.
Wordpress is slow, and its plugin/theme architecture breeds security holes like nobody's business, but that doesn't matter to your average user who does 90 pageviews/month and doesn't care about security until they actually get attacked.
I also disagree that nobody is building a better WP: I recently started working with Webflow, which is very good, quite powerful, and writes very clean code (better than most developers could write themselves).
And, on a more wysiwyg level, there are plenty of new companies like Squarespace offering a service targeting the same user-base as WP.
People often confuse popularity with merit. All of the popular systems are technically obsolete. Mainly we are waiting for people to catch up.
And because WordPress isn't bad enough, none of the bloggers will learn.
Building a CMS is relatively easy.
Building a CMS that does everything WP does is difficult.
Building a CMS that does everything WP does whilst still remaining easy to use is incredibly difficult.
There are plenty of blog alternatives out there - but few that you can turn into virtually any other kind of system in just a few clicks. WP can be turned into a whole host of other 'types' of website and you don't need to know anything particularly technical in order to do it.
Even installing Wordpress itself is just a few clicks (depending on your hosting provider).
WP is terrible in lots of ways, but in the ways that most people care about, it does a reasonable-to-good job.
In the next few months that's going to change dramatically. Shoot me an email to vlad@webflow.com for a demo if you're curious.
PHP is not terrible, Wordpress is not terrible. It's just you, trying to be "different".
Wordpress as a blog platform is still OK (personally not my cup of tea) and as a simple CMS is "OK", but it tries to do too much.
Enterprise-level websites running on Wordpress with shopping carts, customized ordering systems, etc are hacky as hell.
If you can see why wordpress is terrible, you don't need it and can easily whip out your own replacement.
If you can't see why it's terrible, then it's the perfect product for you.
Everyone wins, because it gets the job done.
But OK. You don't like the source code. That matters more, I guess.
I can launch a full-functional website and manage all of the users and even have a shopping cart with checkout for under $200. Pretty much everything I ever want to add onto to it (SEO, optimization, etc) has already been written in the form of a plugin and is usually free.
I will admit, the internal code leaves a lot to be desired, but in terms of the ecosystem, I haven't found anything better.