![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 | |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
![]() I mean as a platform for independent themes and plugins. You won't find any professional plugin or theme there anymore.
By professional themes and plugins I mean those that made from professional webmasters who want to somehow insert HTML, CSS, JavaScript and PHP code into their WordPress posts, sites (e.g. sidebar, footer, header) etc. This is officially forbidden now and I've got an official confirmation on that. You may say: "that couldn't be true, because there is a ton op plugins like PHP anywhere are freely hosted at wordpress.org". Yes, they are. But not for a long time, so make sure to download them while they are not removed or not castrated on their functionality. Here is a quote from the official email, that explains the new WordPress.org policy on 3rd-party themes and plugins: Quote:
__________________
Obey the Cowgod |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
So Fucking Banned
Industry Role:
Join Date: Nov 2008
Location: with your dream girl
Posts: 4,941
|
Time to fork WordPress?
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Pay It Forward
Industry Role:
Join Date: Sep 2005
Location: Yo Mama House
Posts: 76,927
|
nope
![]() ![]() ![]()
__________________
TRUMP 2025 KEKAW!!! - Support The Laken Riley Act!!! END DACA - SUPPORT AZ HCR 2060 52R - email: brassballz-at-techie.com |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#4 |
Making PHP work
Industry Role:
Join Date: Nov 2002
Location: 🌎🌅🌈🌇
Posts: 20,227
|
Seems reasonable to me; unless I'm missing something.
A post made by a random user should not contain any HTML/CSS/JS/PHP Security "101" it seems. ![]()
__________________
Make Money with Porn |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#5 |
Industry Role:
Join Date: Mar 2003
Location: San Diego
Posts: 32,174
|
__________________
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#7 | ||
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
Quote:
I have submitted this plugin: https://www.wpadinserter.com/ - read its documentation. It' just an ad inserting plugin (a quote): "The plugin works with all existing WordPress themes and supports all types of ads. Use any types of ads like including banners, popups, AdSense codes etc. Mix HTML, JavaScript and PHP in any manner." They said they don't accept those anymore, because some WP user may enter a wrong code, which will break his site or let other people to hack it. I asked how my ad plugin will work, if the site owner won't be able to use Google or Amazon ads that obviously contain HTML/CSS/JS? The answer I've got: Quote:
P.S. How visitors may add something to a 3rd-party site? Only in comments, IMHO. How it could be relate to a plugin? ... A WordPress user - a person that uses WordPress engine at his site. A visitor - a random person who visits that site.
__________________
Obey the Cowgod |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#8 | |
Confirmed User
Industry Role:
Join Date: Sep 2013
Location: The Netherlands
Posts: 805
|
Quote:
![]() But yeah, I agree, even "banning" stuff like custom css or plain html to be inserted through plugins doesn't make much sense. Seems like they really want to put the focus back on being "the" blogging CMS for the "non-technical" audience. And to be honest, I don't really understand why anyone with technical skills would pick Wordpress over a much more lightweight, custom code anyway. |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#9 |
Confirmed User
Industry Role:
Join Date: Sep 2013
Location: The Netherlands
Posts: 805
|
Also, those that are looking to install plugins such as "include PHP" or whatever, likely won't have any issues with manually downloading and uploading a zip file to their WP dashboard anyway.
In a way, I think it's just them saying - you can install plugins from a third party server but "use at your own risk". Now it's no longer their fault when some popular plugin turns out to have an exploit (which they already deemed "risky"). I think they just want to keep the Wordpress core as secure as possible for the average user and get rid of anything that may, even if it's slightly, could potentially cause some sort of risk. |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#10 |
Confirmed User
Industry Role:
Join Date: Mar 2022
Location: In the moment
Posts: 95
|
Are you sure you're reading that correctly? It didn't say that your plugin couldn't natively insert HTML/JS/etc. It says you can't enable your end user to insert their own custom HTML/JS/etc.
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#11 |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
My end user is a person who uses my plugin at his/her site. Why he can't insert HTML/JS/etc into his own site with my plugin?
__________________
Obey the Cowgod |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#12 |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
I have no problem with WordPress which is hands down a great product. I have a problem with wordpress.org and a bunch of arrogant hypocrites that moderate plugin submissions. They have no relation to the actual WordPress coders. I bet they hire 'em cheap somewhere in India...
__________________
Obey the Cowgod |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#13 | ||
Confirmed User
Industry Role:
Join Date: Sep 2013
Location: The Netherlands
Posts: 805
|
Quote:
Quote:
Then you can sanitize that ID, and safely insert the ID into the rest of the banner code. Perhaps I'm wrong but it looks as if they only disallow end-users to insert any code themselves (probably due to security risk when there's an exploit, as anyone would now be able to insert any evil javascript or PHP code he wants). However, when you only allow the user to insert his partner ID through a form, the plugin can first sanitize that input (the partner ID), before including it into the final code (non-editable) and finally embed the output on page, thus eliminating the risk of "evil code". For example, a form where users can submit: - an affiliate url - the link to media file (for the banner) I think, would be totally fine, because you can then sanitize and validate both user input, before including it into the final <a href='ÚSER INPUT 1'><img src='USER INPUT 2'></a> code, which then gets injected on page etc. Might not be what you were trying to build exactly, but I kinda get it from a security stand point. I mean, what if the user ends up using your plugin (allowing code to be inserted without sanitizing it) in combination with some sort of heavily outdated theme, full of XSS holes? |
||
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#14 | |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
Quote:
I don't want to release a useless nonsense. I want to release a quality product and it will be released. At my own site. For free.
__________________
Obey the Cowgod |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#15 |
So fuckin' bored
Industry Role:
Join Date: Jun 2003
Posts: 32,381
|
I ended up publishing my plugin here: https://www.wpadinserter.com/
Download it, try it and let me know if you'll find any bugs (they should be there ![]()
__________________
Obey the Cowgod |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#16 | |
Too lazy to set a custom title
Industry Role:
Join Date: Sep 2005
Location: Canada
Posts: 10,207
|
Quote:
From what I understand, Wordpress is trying to tighten security around themes and plugins by not allowing end-users the option to add their own code. I assume this is because it's the most common form of attack Wordpress experiences. I'm not saying it's a good move on their part. I don't agree with their decision. This is what I assume their intention is.
__________________
skype: lordofthecameltoe |
|
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() ![]() |
|||||||
|
|||||||
Bookmarks |