WordPress owners replaced the ACF plugin with their fork, which has 2 million installations.

The conflict that started in September between Automattic and WP Engine took an unexpected turn — Automattic, overseeing the development of the WordPress platform and the official WordPress.org plugin directory, announced the creation of a fork of one of the most popular plugins — ACF (Advanced Custom Fields), developed by WP Engine, which has over 2 million installations and is distributed under the GPLv2 license. Developers were outraged that the owners of WordPress.org not only created a separate fork called 'Secure Custom Fields' but also replaced the main ACF plugin page on WordPress.org, thereby initiating the transition of users to the fork.

This action was explained by concerns for security and the necessity to provide users with a fix for a vulnerability that had remained unaddressed in the ACF version distributed through the WordPress.org directory. The announcement of the fork creation also mentioned that the ACF developers stated they would switch to delivering plugin updates from their own website instead of through WordPress.org, but representatives of WordPress.org do not recommend that users switch to the ACF developers’ own update system until they resolve the vulnerability in the plugin. It is claimed that the plugin replacement is an exceptional situation, backed by legal attacks from WP Engine, which develops the ACF plugin. In addition to fixing the vulnerability, the fork also underwent a cleanup of any ties to WP Engine services.

The absurdity of the situation is that just a few weeks before this, Automattic had blocked ACF developers' access to WordPress.org, so the ACF maintainers were unable to publish an update with the vulnerability fix on WordPress.org, while they posted the fix on their own site and recommended installing it manually or through WP Engine's alternative directory. The update addressing the vulnerability in ACF was prepared 5 days before Automattic announced the creation of the fork.

The acquisition of the user base and the ACF page on WordPress.org has become a continuation of the conflict between WP Engine and Matt Mullenweg, the founder of the WordPress platform and owner of Automattic. Since 2011, Matt Mullenweg has been an investor in WP Engine, but he exited as an investor in 2018 after WP Engine caught the interest of the investment firm Silver Lake. In addition to developing the ACF plugin, WP Engine is also expanding its hosting platform. for hosting projects on the WordPress engine, competing with WordPress.com.

The conflict escalated after the WordPress Foundation filed an application in June to register the trademarks "Managed WordPress" and "Hosted WordPress," which were used on the WP Engine site. On September 20, Matt Mullenweg spoke at the WordComp conference criticizing WP Engine's activities and published an article explaining that WP Engine has no relation to the official WordPress project, despite WP Engine's rhetoric and marketing attempting to convince users otherwise.

There was also dissatisfaction expressed regarding WP Engine's low involvement in development — with a revenue of $500 million, the company reportedly invests about 40 hours a week into the development of the WordPress platform, whereas Automattic’s contribution is estimated at 3,915 hours per week. In the article, WP Engine was compared to a cancerous tumor and it was mentioned that WP Engine will now require a trademark license for the continued operation of its business. A link to the article appeared in the news widget in the admin panel across all WordPress installations, including those on hosting WP Engine.

On September 23, WP Engine sent Automattic an official cease and desist notice demanding to stop false, misleading, and defamatory statements. In response, Automattic demanded that WP Engine cease using the WordPress trademark and amended trademark usage guidelines to mention "WP Engine" as an example of misleading users due to its stylization similar to the official WordPress engine.

On September 25, access to resources distributed through the WordPress.org site was blocked for WP Engine, including access to updates with vulnerability fixes, plugins, and themes. On the same day, accounts of WP Engine staff were blocked in the WordPress.org directory, preventing them from publishing updates for the ACF plugin. On September 27, the blockage of WP Engine's access to resources was partially lifted, but then resumed again on October 1.

On October 2, WP Engine filed a lawsuit against Automattic and Matt Mullenweg. In response, Automattic denied all allegations. Joseph Haden, the executive director of Automattic, and 158 other employees (out of approximately 1700) resigned in disagreement with the stance regarding WP Engine. On October 5, Automattic publicly disclosed information about a vulnerability in the ACF plugin in violation of the code of conduct, and on October 8, changed the login page on WordPress.org, necessitating confirmation of a lack of connection with WP Engine. On October 7, WP Engine prepared an ACF update to fix the vulnerability, and on October 12, Automattic announced the creation of a fork and replaced the ACF plugin page in the WordPress.org directory with it.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster