After they saturated the market for lifetime buyers, they started launching new features not included for lifetime buyers. Annoying.
Then they started pushing advertising for upgrading. Very annoying.
Then they started taking away features lifetime plan users had already. Infuriating.
Then they made it so that support was only available for users on a subscription plan. My complaints weren’t even answered. Unforgivable.
[1]https://dayoneapp.com/blog/the-next-chapter-of-day-one-at-au...
[2] https://medium.com/day-one/day-one-goes-premium-424492fd0a5b
Either they kept introducing even worse policies, or they allowed them
I'd love the diversity of everybody being able to build the sites they want, though. Perhaps we'll see more static HTML/CSS/JS pages.
Update: I love the irony that I just saw the sibling post arguing in the exact opposite direction, that the diversity might make it harder to exploit web sites at scale. Which is also a good point.
Just saying, there are plenty of good CMSs out there now.
WordPress is junky AF, and the spat with WP Engine over... of all things... how they store backups... it was all so cringe. Felt like it boiled down to WP Engines saying, "We don't need to keep backups on the live server..." And WP saying, "Oh hell yeah you do, you can't have your own way to do rollbacks!" It was literally insane for them to fight about that.
This should probably say self appointed advocate. He really hasn't advocated for much beyond collecting payments to Automattic.
Like him or hate him, he grew WordPress to be one of the most popular open source projects of all time. It seems fair to call him a key advocate.
WordPress is still GPL licensed.
Only because it's forced to be because it in turn was a fork of a previous GPL license.
It should be noted that Mullenweg has regularly weaponized the GPL license in the past - using it to take out other companies in the ecosystem like in their fight against Thesis.
As someone who has contributed to WordPress: WordPress grew on the back of volunteers.
It would be unfair to most non-Automattic "volunteers" if he was attributed all/most credit for what it had become, especially pre-Gutenberg.
It's felt somewhat unique to WP for sure, though maybe there are other examples where swaths of communities get big mad when people suggest distributing GPL software for free. I found it a little repellent, but lots of folks scraped together micro-scale businesses selling plugins and themes.
I believe I made a lot better living building stuff for clients and then not caring about what they did with the software, but hey, I'm not the boss of folks trying to make a living supporting a $10 lifetime membership to an image size selecting plugin.
Anyhow, my point is that there is at least a little nuance to be found when thinking about WP and open source software.
The only reason Wordpress is open source in the first place is because it's a just a fork of b2/cafelog and the original GNU license means derivative works have to be open source as well. (Lost in his moral crusade against WP Engine is the fact that he never really contributed to b2 besides just taking their code).
Not sure if it makes me autistic though, I mean, companies use wrong spellings all the time to differentiate, so often that I don't give much thought to it any more.
> One person speculated that the timing may have something to do with Mullenweg’s annual trip to the Burning Man festival, after which he tends to return “with ideas.”
(eg, page 24 of https://storage.courtlistener.com/recap/gov.uscourts.cand.43... )
Of course usually hand-picked boards don't go against their benefactor, and they're not keeping their seats.
That they did in this case says something about just how bad the situation must be.
Depending on the company rules it is possible they might not be easily replaced during their term in which case they could do a coup in the short term.
Travis, Altman, they’re egotistical but ultimately respect corporate theatre, they know that circumventing it is a bad idea, that one must participate in the grand performance, as Altman did. Matt doesn’t care, he’ll do as he pleases regardless of the consequences.
If Matt was a rationale shareholder he would know that what he has done here is a death sentence for Automattic but alas he does not care. Matt will watch Automattic burn before he lets anyone usurp him. The irony is that as a supposed open source advocate, he’s harming open source, he’s showing how dangerous it is for investors to invest in the corporate arm of an open source project when the founder has absolute control over the project.
Either that or he somehow has control over IT and is just shit posting and controlling Slack.
> As of yet, no one at Automattic has heard a confirmation from the board. Mark Davies’ Slack account was also deactivated, sources said.
mhm, ok.
Davies perhaps explained to Matt how financially precarious Automattic’s position is but it seems very unlikely for a CFO to advocate for a batshit extortion plot that had no hope of success. Where did you hear that Davies was responsible for the extortion scheme? I haven’t seen that reported anywhere.
VCs typically include clauses to be able to sack CEO and retain board control under specific circumstances. I've seen this happen in a small company I was at, to a CEO that didn't meet rather ambitious financial targets. AFAIK it is all very carefully designed and the power is extremely important to VCs, plus the legalities are well tested (since most losing CEOs will fight it in courtroom).
https://www.dwell.com/article/mirene-tugboat-stewart-brand-r...
This could not be a more clear case of projection - you are being the exact monster you tell people your enemies are being.
Give this up and seek help. You're not the amazingly self-actualized person you think you are.
When the rights were transferred to the WPF, Matt didn't disclose that the Foundation was essentially just him, and the two other nominal members were effectively absent.
When the rights were transferred, and a big deal was made of this, "It now belongs to the WPF, which ensures that no commercial entity or interest can affect what should be a community project", there was no mention of how, on that same day the WPF silently granted a "irrevocable, non-expiring, exclusive universal commercial licence" to Automattic.
Throughout all of this Matt has conflated Automattic, himself, WP.com, WP.org, the WPF to whatever is most convenient to himself.
Matt says himself "I am WordPress.org. It's not a part of the Foundation", but you'd be forgiven for thinking so, given that the website resides on the Foundations AS network...
Matt doesn't want WPE's "revenue-sharing" license agreement to go to the community, the project, or the Foundation, though, he wants it to go to himself, via his private, for profit competitor.
Matt's claim, "My mom is confused and thinks that WPEngine is part of the open source project", is a deflection, and laughable coming from the man who runs wordpress.org as a "independent website" (that just happens to be running on the Foundation's IP addresses) and wordpress.com as a for-profit business. That seems just a little more confusing.
I remember this:
https://news.ycombinator.com/item?id=41789765
According to the legal counsel's LinkedIn, he left two months after.
Red Hat most memorably has tried it with "technically you are legally permitted to distribute these things we are giving you under contract but we will terminate your contract if you do."
Wordpress might technically be GPL, but the code itself routes most of the key features of Wordpress through Automattic.
If you have a massive technical moat around the ecosystem, it would make sense to be against erecting walls.
Claude can reproduce Wordpress with enough tokens. Claude cannot reproduce the community of maintainers, plug-in authors, users reporting bugs, etc. that is what any real user of Wordpress actually wants (if they don't want buggy, out of date software with security risks).
It is much easier to prompt a relatively tight slop doing the same that WP plus dozens of plugins does. Particularly if you know what you’re doing.
WordPress and a nice page builder with MCP is actually a joy to use, and the absolutely enormous catalog of plugins that are easily extensible and endlessly modifiable makes it so easy to work with when building via agent.
Having worked with WordPress for over a decade, I find it hilarious that WooCommerce (the bane of my existence that has inexplicably paid my rent for a gigantic chunk of my adult life) is easier to use and better positioned for building with AI than Shopify.
The future is actually pretty bright for WordPress I think.
As someone who made a number of bespoke backends, WordPress wins on turnkey host-support, ease of content-authorship, familiarity (when handing over or taking over a backend), and breadth and depth of plugins. A lot of people would be well-served by static-site generators, and those were on the rise for a bit. WordPress stays winning because of the user-friendliness of its publishing workflows (vs SSGs), and self-reinforcing ecosystem.
Those who have ever delivered actual WP sites know the pain of it. Typical WP setups grow very fast growing towards completely entangled mess of plugins and template hacks as the project matures.
The security issues with WordPress aren’t fake, but they are not nearly as bad as the reputation is. The main reason WordPress gets a bad rap is companies like Patchstack have a financial incentive to abuse CVEs and scare people into buying their products.
For example, we have had numerous CVEs from them stating that they found an RCE in our plugins (!). Oh no! CVE filed. Reproduction steps:
1. Log in as a site admin with full access to the database and file system of the site. 2. Scroll past an input field in our plugin where you can type in arbitrary PHP and have it executed. 3. Do some magical incantation to fire some useless hook.
——
Hello Toyota, I found a security problem- the center console inside the car can be opened by unauthorized users. As some vehicle owners may place valuables there, it exposes them to the possibility of theft.
Steps to reproduce:
1. Unlock the car door and enter the vehicle using your key.
2. Open the center console.
Proposed security fix: Require the vehicle’s key, an RSA fob, and iris scan to open the center console. You have 15 days to recall all vehicles in your fleet that have an unsecured center console. Here are several blog posts that will be going live after the deadline:
• All Toyota Cars Insecure And Anything You Put Inside Can Be Stolen By Anyone Unless You Give Us $50/mo
• Toyota Car Alternatives Because of Vulnerability
• How To Secure Toyota Cars
• Safe Toyota Cars Near Me
• Toyota Car Discount Code Security
——
Their whole business model is to file CVEs, get to them to rank on Google, and then blast out press releases scaring people into paying for their garbage plugin.
There have been real issues, like the Bricks thing, where actual sites did get hacked. But this is a fact of life, if you expose your server/data to the internet at some point it very well may get compromised. I’m sure a few people had a bad day, but if you have a WordPress site and care about security literally all you need to do is put it on a half decent host and they will use a WAF and won’t have to worry about anything.
There are plenty of household names running WordPress at scale like Rolling Stone, Time, the White House, Techcrunch, etc. They aren’t doing much different from what a $5/mo blog on GoDaddy gets in terms of security, and they certainly aren’t running Patchstack (I really hope someone doesn't sniff their sites or tell me they are providing a WAF for them etc and prove me wrong lol).
“Their whole business model is to sign CVEs” - please don’t make up random stuff. We were invited to the CVE program and therefore have an obligation to assign CVEs.
“Get to rank them on Google” - what?
Also, we don’t send press releases about vulnerabilities. There are cases where publications reach out to us and ask for comments when there are severe issues disclosed - but that’s very much different from the picture you’re trying to paint here.
Also, your “get a half decent host with a WAF” argument shows how disconnected you’re from the reality. There are web hosts that say they offer secure hosting when promoting free SSL. We’ve tested the web hosts with independent reviewers and what you’re claiming is a widespread myth that has been debunked: https://patchstack.com/articles/myth-of-secure-hosting-only-...
Wasn't there a 6 month severance on offer?
I'm sure there are people who are stuck and have a house payment, but it was pretty obvious the shenanigans were only going to get worse.
Also, if you're just there for a paycheck, you're probably not that upset at distractions.
Not true, I've worked jobs where I was there for the paycheck, I'd still prefer that it be a stable working and environment and still wanted to do good work.
I'm happier when work doesn't expect me to be "part of the vision" or "part of the family", treat me with respect, I'll treat you with respect and do good work - that's all it needs to be.
My feelings are not "boy I wish I could get back at that grindstone". It's "this is the ride I signed up for"
I'm assuming there should be an "off" after "laid"...
The software job market, especially for those of us outside the major tech hubs has been severely biased in favor of employers for the last 3 years, with constant layoffs and rising inflation.
If I was working for Automattic I can definitely see electing to stay there until the job market improves.