←back to thread

221 points michaelcampbell | 1 comments | | HN request time: 0s | source
Show context
didgeoridoo ◴[] No.41830981[source]
This is particularly bananas as ACF is basically table stakes for doing anything beyond blogging. I’d assume most websites that make actual money are thoroughly dependent on it.

To twist the knife on a personal spat, Mullenweg just blew up uncountable businesses on a double-holiday weekend. At this point, seriously, fuck that guy.

replies(2): >>41831282 #>>41831633 #
sgdfhijfgsdfgds ◴[] No.41831633[source]
> This is particularly bananas as ACF is basically table stakes for doing anything beyond blogging.

Not sure about this.

I'd assume most Wordpress sites that make actual money are dependent on WooCommerce and Easy Digital Downloads, and maybe Gravity Forms/WP Forms for member subscriptions.

None of these are reliant on ACF, and there's any number of WP plugins like this that do the whole job of some website niche or other.

(I've been doing bespoke WP builds for at least a decade -- first one probably more like 14 years ago actually -- and I've not used ACF a single time. There has always been an alternative, and for a developer it's a bad choice.)

Either way: I don't think ACF's popularity is the major factor here. It's that it's an outright abuse.

The word "gaslighting" gets overused but it applies quite well to what ACF free plugin users are experiencing here.

As to "blew up": I am not sure how many money-making ACF users this has affected, because they tend to use ACF Pro, which is a separate download.

What appears to have been removed from ACF to make this shady SCF nonsense is the upsell marketing. Not sure what other breakage there would/could have been. I have seen people say things have broken but I suspect they are relatively minor issues caused by the actual ACF security patch which is also shipped here... because they haven't changed much.

Though if Secure Custom Fields is getting the blame for the breakage, that's kismet, karma, whatever you want to call it.

replies(4): >>41831892 #>>41833066 #>>41834032 #>>41836488 #
1. ryoshu ◴[] No.41836488[source]
There are plenty of uses for WordPress for marcom sites for Fortune 500 brands that don't use those sites for transactional revenue, but they serve millions of impressions a month that rely on ACF. This is a supply chain attack. The security discussions with client IT groups happening this week are going to be a much bigger deal than they were last week.

The erratic and bizarre behavior of the BDFL that runs WordPress and Automattic has proven himself untrustworthy and is causing massive damage to the WordPress ecosystem.