<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WPblogger &#187; WordPress News</title>
	<atom:link href="http://wpblogger.com/category/wordpress-news/feed" rel="self" type="application/rss+xml" />
	<link>http://wpblogger.com</link>
	<description>All things WordPress</description>
	<lastBuildDate>Sun, 15 Jan 2012 23:39:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>PressRow: Casualty of Automattic&#8217;s Jihad</title>
		<link>http://wpblogger.com/pressrow-automattic-casualty.php</link>
		<comments>http://wpblogger.com/pressrow-automattic-casualty.php#comments</comments>
		<pubDate>Thu, 18 Nov 2010 22:45:09 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=799</guid>
		<description><![CDATA[In their continuing jihad/crusade against all things Chris Pearson, Automattic is removing yet another extremely popular theme from WordPress.com.

The theme on the chopping block this time is PressRow. ]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/pressrow-automattic-casualty.php" title="Permanent link to PressRow: Casualty of Automattic&#8217;s Jihad"><img class="post_image alignnone" src="http://wpblogger.com/wp-content/uploads/2010/11/lego-crusader.jpg" width="500" height="375" alt="Automattic's Crusade Against it's Users" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fpressrow-automattic-casualty.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fpressrow-automattic-casualty.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In their continuing jihad/crusade against all things Chris Pearson, Automattic is removing yet another extremely popular theme from WordPress.com.</p>
<p>The theme on the chopping block this time <a target="_blank" href="http://en.forums.wordpress.com/topic/details-on-pressrow-replacement-pilcrow" target="_blank">is PressRow</a>. This despite the fact Matt Mullenweg <a target="_blank" href="http://en.blog.wordpress.com/2006/09/09/new-theme-pressrow/" target="_blank">once labeled</a> the theme one &#8220;of the best ones [themes]&#8221; submitted for inclusion, and significant outcry from users of the theme.</p>
<p>The message, as always from Automattic: we care more about our injured ego and vendetta than we do about our users.</p>
<p>The argument&#8217;s been made that users of PressRow should have seen the writing on the wall when Cutline was removed with little warning, and <a target="_blank" href="http://en.forums.wordpress.com/topic/you-changed-my-theme-without-my-knowledge" target="_blank">disastrous impact on it&#8217;s users</a>. However, most WordPress.com users probably don&#8217;t keep up with all the egotistical politics that have been driving Automattic&#8217;s decisions lately.</p>
<p>Naturally, many PressRow <a target="_blank" href="http://en.forums.wordpress.com/topic/details-on-pressrow-replacement-pilcrow#post-526343" target="_blank">users are upset</a> about the impending change. And given the kinds of <a target="_blank" href="http://en.forums.wordpress.com/topic/details-on-pressrow-replacement-pilcrow/page/7" target="_blank">comments being left by folks who have opted to already make the switch</a>, the number of angry users will only increase over the next two weeks.</p>
<p>If you&#8217;d like to urge WordPress.com to NOT remove the theme theme of your choice over a personal grudge that has nothing to do with you or your site, I&#8217;ve made the badge below available for embedding:</p>
<p style="text-align: center;"><a href="http://wpblogger.com/pressrow-automattic-casualty.php" target="_blank"><img class="size-full wp-image-800 aligncenter" style="margin-top: 2px; margin-bottom: 2px;" title="Save my Theme - PressRow!" src="http://wpblogger.com/wp-content/uploads/2010/11/dinomatt-small.jpg" alt="Save my Theme - PressRow!" width="250" height="125" /></a></p>
<p style="text-align: center;">To embed the image, copy and paste the code below:</p>
<p style="text-align: center;">&lt;a href=&#8221;http://wpblogger.com/pressrow-automattic-casualty.php&#8221; target=&#8221;_blank&#8221;&gt;&lt;img style=&#8221;margin-top: 2px; margin-bottom: 2px;&#8221; title=&#8221;Save my Theme &#8211; PressRow!&#8221; src=&#8221;http://wpblogger.com/wp-content/uploads/2010/11/dinomatt-small.jpg&#8221; alt=&#8221;Save my Theme &#8211; PressRow!&#8221; width=&#8221;250&#8243; height=&#8221;125&#8243; /&gt;&lt;/a&gt;</p>
<p style="text-align: left;">While I think it is important to raise awareness of this issue, I would urge PressRow users to have a backup option in place. Automattic&#8217;s recent track record (capital P dangit issue, Cutline, etc) suggests they couldn&#8217;t care less what users want, or if their actions break users&#8217; sites.</p>
<p style="text-align: left;">If you&#8217;re one of the unlucky PressRow users, there is a bit of good news. Chris Pearson  has announced he&#8217;ll be releasing Cutline and PressRow as skins for the  Thesis theme for free, to all Thesis customers. Also, Grant Griffiths of Headway announced that they&#8217;ll be offering a discount to all former PressRow users if you&#8217;d like to move to a self hosted version of WordPress.</p>
<p style="text-align: left;">If nothing else, this whole episode can serve as an important reminder of the importance of owning your web property, and maximizing your control over your site.</p>
<h6 style="text-align: left;">image source: <a target="_blank" href="http://www.flickr.com/photos/zjmac/3819026218/" target="_blank">http://www.flickr.com/photos/zjmac/3819026218/</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/pressrow-automattic-casualty.php/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Happy Birthday WordPress &amp; Thanks for All the Work!</title>
		<link>http://wpblogger.com/happy-birthday-wordpress.php</link>
		<comments>http://wpblogger.com/happy-birthday-wordpress.php#comments</comments>
		<pubDate>Thu, 27 May 2010 20:12:49 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=647</guid>
		<description><![CDATA[Seven years ago today, WordPress was turned loose on the world. The platform has come quite a way in that time, boasting an impressive 9.4 million downloads of WordPress 2.9. With WordPress 3.0 looming which will include multi-site support, it&#8217;s clear the &#8220;blogging&#8221; platform has become much much more. Built on the back of countless [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/happy-birthday-wordpress.php" title="Permanent link to Happy Birthday WordPress &#038; Thanks for All the Work!"><img class="post_image alignnone" src="http://wpblogger.com/wp-content/uploads/2010/05/wordpress-birthday.jpg" width="500" height="314" alt="WordPress' 7th Birthday" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fhappy-birthday-wordpress.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fhappy-birthday-wordpress.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Seven years ago today, <a target="_blank" href="http://wordpress.org/development/2003/05/wordpress-now-available/" target="_blank">WordPress was turned loose</a> on the world.</p>
<p>The platform has come quite a way in that time, boasting an impressive <a target="_blank" href="http://wordpress.org/download/counter/" target="_blank">9.4 million downloads</a> of WordPress 2.9.</p>
<p>With WordPress 3.0 looming which will include multi-site support, it&#8217;s clear the &#8220;blogging&#8221; platform has become much much more. Built on the back of countless hours of volunteer work, WordPress is now a full CMS solution that can power even the most complicated sites.</p>
<p>While I&#8217;ve been a <a href="http://wpblogger.com/matt-should-resign.php" target="_blank">vocal critic of Matt Mullenweg</a> and Automattic&#8217;s leadership of the WordPress project, the fact remains that without their efforts, the platform wouldn&#8217;t be what it is today. Whatever your thoughts are on the politics surrounding WordPress, it would be foolish to deny the incredible progress that has been made under their guidance in just seven years.</p>
<p>And, since I&#8217;ve personally benefited tremendously from all the tireless work that has gone into the project, I&#8217;d like to mark the date by congratulating and thanking everyone that has contributed in any form to the WordPress platform.</p>
<p>WordPress truly has revolutionized the way content is published online and I&#8217;m excited to see what the next seven years bring.</p>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/happy-birthday-wordpress.php/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Why Matt Should Resign</title>
		<link>http://wpblogger.com/matt-should-resign.php</link>
		<comments>http://wpblogger.com/matt-should-resign.php#comments</comments>
		<pubDate>Fri, 21 May 2010 15:03:21 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=636</guid>
		<description><![CDATA[Neither WordPress nor Automattic would be where they are today without the tireless efforts of Matt Mullenweg. I have personally benefited from his work and for that I&#8217;m truly thankful. That said, it&#8217;s time for Matt to resign from either the WordPress Foundation or Automattic. The reason is fairly simple, there&#8217;s a glaring conflict of [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/matt-should-resign.php" title="Permanent link to Why Matt Should Resign"><img class="post_image alignnone" src="http://wpblogger.com/wp-content/uploads/2010/05/conflict-of-interest.jpg" width="500" height="333" alt="Matt's dual responsibilities will eventually conflict" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fmatt-should-resign.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fmatt-should-resign.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Neither WordPress nor Automattic would be where they are today without the tireless efforts of Matt Mullenweg. I have personally benefited from his work and for that I&#8217;m truly thankful.</p>
<p>That said, it&#8217;s time for Matt to resign from either the WordPress Foundation or Automattic.</p>
<p>The reason is fairly simple, there&#8217;s a glaring conflict of interest.</p>
<h3>Automattic</h3>
<p>Automattic is the for profit company Matt co-founded which provides several WordPress related services such as premium WordPress hosting, Akismet and VaultPress, a security and backup service for WordPress blogs.</p>
<p>The company has raised over $30 million from investors and, as co-founder, Matt is ultimately responsible to make sure Automattic earns a profit for  those investors.</p>
<p>Simply put, Automattic, like every other business, has  to make money and it&#8217;s Matts job to make that happen.</p>
<h3>WordPress Foundation</h3>
<p>The WordPress Foundation, on the other hand, is a non-profit organization intended to  &#8220;further the mission of the WordPress&#8221; and &#8220;be responsible for  protecting the WordPress &#8230; related  trademarks.&#8221;</p>
<p>As Matt has admitted on several occasions it is not intended to fix the  &#8220;Matt runs everything&#8221; issue.</p>
<p>However, the fact that even Matt acknowledges there is such an issue  should invoke memories of the &#8220;Danger, Will Robinson!&#8221; robot.</p>
<p>While it might seem like a minor thing, controlling the trademark of several WordPress related terms makes the foundation a very powerful entity.</p>
<p>Imagine if a company offering WordPress related services were prevented from using the phrase WordPress!</p>
<h3>The Conflict</h3>
<p>Automattic has enjoyed a long run as a monopoly in several service  areas, but challengers are springing up all over as the number of WordPress users  continues to grow.</p>
<p>Companies like Page.ly, for example, are now competing with WordPress.com in the premium WordPress hosting market.</p>
<p>The BackupBuddy plugin by PluginBuddy offers many of the same features Automattic&#8217;s newest service, VaultPress offers.</p>
<p>Matt owes it to Automattic&#8217;s investors to ensure new competitors like Page.ly don&#8217;t cut into their profit margins. On the other hand, Page.ly is perfectly GPL compliant and a valuable resource to the community the WordPress Foundation is supposed to serve.</p>
<p>Should Matt protect his investors and prevent Page.ly from using the  WordPress trademark or should the WordPress Foundation help promote the  valuable service Page.ly provides to the community?</p>
<p>I don&#8217;t know about you, but I certainly wouldn&#8217;t want to have to make that decision.</p>
<p>Jane Wells, an Automattic employee caused an uproar earlier this week by declaring all &#8220;non-GPL-compliant people&#8221; ineligible to sponsor, organize, or speak at WordCamp events.</p>
<p>Since WordCamp is one of the trademarks owned by the WordPress Foundation, they can pretty much set any rule they want about who can and can&#8217;t participate.</p>
<p>Keeping only Automattic&#8217;s goals in mind, it would be foolish to allow a competitor to gain publicity by organizing, speaking at, or sponsoring a WordCamp event.</p>
<p>By contrast, it would an enormous disservice to the community if Matt used the WordPress Foundation&#8217;s trademarks to prevent Automattic competitors from participating.</p>
<p>Unfortunately for Matt, there are countless more perfectly plausible situations where Automattic and the WordPress Foundation&#8217;s interests would conflict.</p>
<h3>Solution: Remove the Conflict</h3>
<p>In government there are rules and regulations to prevent conflicts of interest like  this from arising. When people write the rules for the industries and companies they’re  financially invested in, we tend to wind up paying $30,000 for a toilet seat.</p>
<p>I should note that Matt seems to have tip-toed across this ethical tight-rope  successfully – so far. But, as the old saying goes, absolute power corrupts absolutely and no one is perfect.</p>
<p>Eventually Matt will find himself faced with a decision that will hurt either the community or his company’s bottom line. I have no idea  which side he’ll come down on but I do know one thing…</p>
<p>He shouldn&#8217;t be put in that position in the first place.</p>
<p>It&#8217;s time for Matt to do the right thing and remove himself from this obvious and dangerous conflict of interest.</p>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/matt-should-resign.php/feed</wfw:commentRss>
		<slash:comments>29</slash:comments>
		</item>
		<item>
		<title>Google Cloaking Hack Targeting WordPress &amp; How to Fix It</title>
		<link>http://wpblogger.com/google-cloacking-wordpress-hack.php</link>
		<comments>http://wpblogger.com/google-cloacking-wordpress-hack.php#comments</comments>
		<pubDate>Thu, 15 Apr 2010 20:00:02 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=551</guid>
		<description><![CDATA[<blockquote><strong><span style="color: #ff0000;">Update  III:</span> </strong>Chris Pearson has published a g<a href="http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php" target="_blank">uide on how to diagnose and fix this hack</a>. If you've been hit by this thing, this is how to get your site back. However, the vulnerability that allowed the hackers in is still unknown. It has hit multiple sites across all sorts of web hosts and servers.</blockquote>]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/google-cloacking-wordpress-hack.php" title="Permanent link to Google Cloaking Hack Targeting WordPress &#038; How to Fix It"><img class="post_image aligncenter" src="http://wpblogger.com/wp-content/uploads/2010/04/cloaking-device.jpg" width="500" height="375" alt="Google Cloaking WordPress Hack" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fgoogle-cloacking-wordpress-hack.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fgoogle-cloacking-wordpress-hack.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<blockquote><p><strong><span style="color: #ff0000;">Update   IV:</span> </strong>If your WordPress installation has been hacked and you need help fixing it, I would highly recommend talking to  Michael VanDeMar. He&#8217;s written a great <a target="_blank" href="http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/" target="_blank">guide to cleaning up WordPress hacks</a> and offers a cleaning service if you&#8217;d rather not do the work yourself.  <a target="_blank" href="http://smackdown.blogsblogsblogs.com/contact-michael-vandemar/" target="_blank">Contact him here</a> for more details.</p>
<p><strong><span style="color: #ff0000;">Update  III:</span> </strong>Chris Pearson has published a g<a target="_blank" href="http://www.pearsonified.com/2010/04/wordpress-pharma-hack.php" target="_blank">uide on how to diagnose and fix this hack</a>. If you&#8217;ve been hit by this thing, this is how to get your site back. However, the vulnerability that allowed the hackers in is <strong>still unknown</strong>. It has hit multiple sites across all sorts of web hosts and servers.</p>
<p><span style="color: #ff0000;"><strong>Update II:</strong></span> The RSS file seems to have been the culprit for several other sites as well. <a target="_blank" href="http://www.christopherspenn.com/2010/04/07/find-the-latest-wordpress-hack/">Christopher Penn</a> (it seems this hacker picked the wrong Christophers to mess with) has a tip on how to fix it.</p>
<p>&#8220;Log into your MySQL database (most hosts have this via PHPmyAdmin)  and execute this query:<strong><em>SELECT *FROM `wp_options` where option_name like ‘rss%’  ORDER BY `wp_options`.`option_name` ASC</em></strong></p>
<p>What you’re looking for is an entry that starts with  rss_ and then some random numbers. The text of the entry is encoded  javascript, which looks like this:</p>
<p><strong><em>FFPJ1JpnyfUnpDzz3h9tfaI92uDvyD/Of+r4XyJ2f2Uev6U539WDM39kP10QFLP53+Y5BaX3+0/a03rZ0<br />
0nKX5Na27hXdOSw17TGuO7pDWt/+Na0+lVHHdrWrScqzVqdysqybmiWvILqqXzn5L+ehyvSzriIZHsf<br />
oIiUKwlJvcjvH69FR7SHB4UNXyXOaZw+ivT8dhjkZ6rtGj+PPJRMlCW5ePEZVlLOj8YkgL80/26Luefq<br />
VXgStMY/Afw/</em></strong></p>
<p>Delete this entry.&#8221;</p>
<p>You&#8217;ll want to be sure to back up your site before making any changes, and after making the fix, change your passwords for your WordPress installation, the FTP password, and even the database password.</p>
<p>There&#8217;s still no word as of yet on HOW the hackers gain access to the sites, but this should at least remove the issue and hopefully prevent it from recurring.</p>
<p><strong><span style="color: #ff0000;">Update:</span> </strong>Chris Pearson seems to have found the offending code, at least in his case. The injection point seems to have been an RSS magpie widget, however that&#8217;s not necessarily the point of vulnerability. He recommends looking &#8220;in your  wp_options table for the following option name:  rss_f541b3abd05e7962fcab37737f40fad8.&#8221; Please note this is ONLY a single case and from what I understand it&#8217;s quite common for hackers to use multiple or varying file names. If you&#8217;ve been hacked, I would again urge you to contact security@wordpress.org so we can find a fix for this issue as soon as possible. Thanks!</p></blockquote>
<p>There&#8217;s an incredibly nasty hack hitting WordPress sites right now, even sites that are running the latest most up to date version (2.9.2).</p>
<p>What makes this hack so mean is that it is only viewable to search engine spiders AND it apparently has a high rate of recurrence. Detecting the hack is fairly simple, just do a site:yourdomain.com search in Google for your site. If you see title tags involving all sorts of pharmaceuticals, you&#8217;ve been hit. I don&#8217;t have an answer for you on how to fix it. I wish I did, but hopefully this post will help lead to a resolution.</p>
<p>Several prominent sites including the WPquestions.com blog, Chis Pearson&#8217;s (creator of the Thesis theme) personal blog, and dozens if not hundreds of others have been hit. Plus, the <a target="_blank" href="http://www.themelab.com/2010/03/01/dirty-wordpress-hack-going-around-cloaked-to-search-engines/">hack was covered on ThemeLab.com</a>, discussed in a WPtavern thread, and apparently submitted a couple of times to the WordPress support forums.</p>
<p>Despite the well documented security issues WordPress has had over the last year, the resounding sentiment seemed to be &#8220;It&#8217;s not my problem until you can prove it&#8217;s my problem.&#8221; In the WPtavern thread, members were quick to argue that it wasn&#8217;t necessarily a WordPress issue and basically argued that if it were a WordPress issue, more sites would have been hacked by now. In the WordPress.org forum, it appears the thread received an even cooler reception, being deleted all together.</p>
<p>Don&#8217;t get me wrong, I have no doubt everyone on the WordPress team wants the platform to be as secure as possible. But the reaction we&#8217;re seeing to this significant problem is baffling to me. Whether WordPress is the source of the vulnerability or not, the hack is obviously targeting WordPress sites and making life difficult for a LOT of WP users.</p>
<p><img class="aligncenter size-full wp-image-556" title="mark-jaquith-tweet" src="http://wpblogger.com/wp-content/uploads/2010/04/mark-jaquith-tweet.jpg" alt="WordPress Developer Mark Jaquith" width="500" height="76" />As WP developer, Mark Jaquith pointed out via Twitter, they receive hack reports on a daily basis and try to track down all actionable security information. While I&#8217;m sure that&#8217;s the case, this specific hack is very easy to miss if you&#8217;re not actively checking out your search engine listings. A vast majority of these site owners probably have no idea their site&#8217;s been hit, and that&#8217;s going to make it tough for them to raise the issue to the WordPress team directly.</p>
<p>Even though I&#8217;ve been lucky enough to not have any of my sites affected (knock on wood), I was able to find and point Mark to <a target="_blank" href="http://www.google.com/search?hl=en&amp;client=firefox-a&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;q=%22we+always+offer+lowest+prices%22&amp;btnG=Search&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=">thousands</a> of <a target="_blank" href="http://www.google.com/search?hl=en&amp;client=firefox-a&amp;hs=Yq3&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;q=%22we+always+have+special+offers%22&amp;btnG=Search&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=">examples</a> the WordPress team can take a look at to find any possible patterns.</p>
<p>Looking at a hacked site from the outside in, however, isn&#8217;t nearly as helpful as having access to the behind the scenes info. Providing things like:</p>
<ul>
<li> a list of what plugins you&#8217;re running</li>
<li>what version of WP you&#8217;re running</li>
<li>what theme you&#8217;re using</li>
<li>who your hosting provider is</li>
<li>and a list of any other applications installed on your account</li>
</ul>
<p>would GREATLY increase the WordPress team&#8217;s ability to narrow down the list of possible culprits.</p>
<p>If you&#8217;re site has been hacked (again you can find out by going to Google and typing site: before your url) please send those details in an email to security@wordpress.org and feel free to post them in the comment sections below.</p>
<p>This issue is a particularly nasty one and the sooner we can nail down the vulnerability, the sooner it can be eliminated!</p>
<blockquote><p><span style="color: #ff0000;"><strong>Note:</strong></span> If your WordPress installation has been hacked and you need help fixing  it, I would highly recommend talking to  Michael VanDeMar. He&#8217;s written a  great <a target="_blank" href="http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/" target="_blank">guide to cleaning up WordPress hacks</a> and offers a  cleaning service if you&#8217;d rather not do the work yourself.  <a target="_blank" href="http://smackdown.blogsblogsblogs.com/contact-michael-vandemar/" target="_blank">Contact him here</a> for more details.</p></blockquote>
<h6>Image source: <a target="_blank" href="http://icanhascheezburger.com/2007/10/13/cloaking-device-operational/">ICanHasCheezburger.com</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/google-cloacking-wordpress-hack.php/feed</wfw:commentRss>
		<slash:comments>50</slash:comments>
		</item>
		<item>
		<title>Hacks are ALWAYS a WordPress Issue</title>
		<link>http://wpblogger.com/wordpress-hack-problems.php</link>
		<comments>http://wpblogger.com/wordpress-hack-problems.php#comments</comments>
		<pubDate>Wed, 14 Apr 2010 19:01:56 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>
		<category><![CDATA[WordPress Security]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=577</guid>
		<description><![CDATA[Any time a WordPress site is hacked, it becomes a WordPress problem. Now don&#8217;t get me wrong, hacks happen. Unfortunately that&#8217;s just a fact of life in our online world. When a platform becomes popular enough, the ne&#8217;er-do-wells will eventually attack it. WordPress is no exception. It&#8217;s been the target of countless attacks and hacks [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/wordpress-hack-problems.php" title="Permanent link to Hacks are ALWAYS a WordPress Issue"><img class="post_image aligncenter" src="http://wpblogger.com/wp-content/uploads/2010/04/wordpress-security.jpg" width="500" height="375" alt="WordPress Security Issues" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-hack-problems.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-hack-problems.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Any time a WordPress site is hacked, it becomes a WordPress problem.</p>
<p>Now don&#8217;t get me wrong, hacks happen.</p>
<p>Unfortunately that&#8217;s just a fact of life in our online world. When a platform becomes popular enough, the ne&#8217;er-do-wells will eventually attack it.</p>
<p>WordPress is no exception.</p>
<p style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/rSdHE122UdM&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/rSdHE122UdM&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>It&#8217;s been the target of countless attacks and hacks over the years; some because of vulnerabilities in its code, but <strong>most</strong> due to vulnerabilities in plugins, servers, or outdated versions.</p>
<p>I recently reported on a nasty attack that&#8217;s been targeting <a target="_blank" href="http://wpblogger.com/google-cloacking-wordpress-hack.php" target="_blank">WordPress sites with Google cloaked pharmaceutical spam</a>. Just days later, a <a href="http://blog.sucuri.net/2010/04/details-on-network-solutions-wordpress.html" target="_blank">different hack hit the WordPress installs of many Network Solutions customers</a>.</p>
<blockquote><p><span style="color: #ff0000;"><strong>Disclaimer: </strong></span> I&#8217;m the SEO Manager for Network Solutions. I had no involvement in the recent WordPress episode on a professional level. Also, this blog does not, and never has spoken for NetSol. I&#8217;m not an  official rep for the company or anything like that. I&#8217;m simply a big fan  of the WordPress platform.</p>
<p>In reading Network Solutions&#8217; blog posts, it seems the WordPress community was very helpful in this situation. However, the sentiments expressed following these hacks, and readily apparent in Matt&#8217;s recent post, are what I&#8217;m calling into question.</p></blockquote>
<p>There was so much press about WordPress hacks going around that Matt Mullenweg felt the need to <a target="_blank" href="http://wordpress.org/development/2010/04/file-permissions/trackback/" target="_blank">address the issue in a blog post published yesterday</a>. While he was talking specifically about the NetSol attack, the impression I got from that post is &#8220;if the vulnerability isn&#8217;t in the core code of WordPress, it&#8217;s not our problem.&#8221;</p>
<h3>Not My Problem</h3>
<p>When reporting the &#8220;pharma hack&#8221; in the WordPress support forum as well as the <a target="_blank" href="http://www.wptavern.com/forum/general-wordpress/1371-0-day-wordpress-vulnerability-results-many-media-temple.html" target="_blank">WPtavern forum</a> there were several replies that seemed to be reprimanding the poster for suggesting it could be a WordPress issue and that a smoking gun would be needed before it would be taken seriously.</p>
<p>It was in fact that sentiment, and the lack of coverage about the ongoing pharma hack, that prompted me to cover the attack again, despite it having already been mentioned months ago on several different sites!</p>
<p>Again, let me be clear. I&#8217;m by no means suggesting that all hacks are due to faults in the WordPress code. In fact the large majority aren&#8217;t.</p>
<p>However, they ALL impact the community, the platform&#8217;s brand, and should be dealt with swiftly and aggressively. In short, they&#8217;re ALL WordPress&#8217; problems to deal with.</p>
<p>Thousands of WordPress users are being hit with the &#8220;pharma hack&#8221; (Google has just under <a target="_blank" href="http://www.google.com/search?hl=en&amp;client=firefox-a&amp;hs=Yq3&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;q=%22we+always+have+special+offers%22&amp;btnG=Search&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=" target="_blank">2 million results </a>for title tags that <a target="_blank" href="http://www.google.com/search?hl=en&amp;client=firefox-a&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;q=%22we+always+offer+lowest+prices%22&amp;btnG=Search&amp;aq=f&amp;aqi=&amp;aql=&amp;oq=&amp;gs_rfai=" target="_blank">match the hacked pattern</a>) and WordPress hasn&#8217;t said a word about it.</p>
<p>Mark Jaquith has reached out privately to a few people and there&#8217;s finally a thread on the support forums that didn&#8217;t get deleted but we still don&#8217;t have the vulnerability pinned down months into this attack.  Chris Pearson has been tweeting about it, in an attempt to solve the issue, but that only earned him a lecture from Matt!</p>
<p><img class="aligncenter size-full wp-image-578" title="matt-mullenweg-security-tweet" src="http://wpblogger.com/wp-content/uploads/2010/04/matt-mullenweg-security-tweet.jpg" alt="" width="410" height="74" /></p>
<p>Whether WordPress is the source of this problem or not, if no solution is found, what option will these blogs have other than to stop using WordPress? Sure it might not be WordPress&#8217; fault, but if another platform isn&#8217;t being exploited in this way, it won&#8217;t much matter.</p>
<h3>Brand Damage</h3>
<p>WordPress has earned a well deserved reputation as a great CMS. However the frequent updates, many of them security related, have also earned it a reputation of being insecure.</p>
<p>Users who don&#8217;t update to the latest version are obviously posing significant security risks, but every time they get hacked, it&#8217;s one more person that has a WordPress hack story to tell. Every hack that targets a WordPress plugin is another Do Matt and others within the community really not care whether WordPress&#8217; reputation is damaged in this fashion?</p>
<h3>Defensiveness</h3>
<p>The root of this &#8220;not my problem&#8221; attitude is likely defensiveness. No one wants to be at fault when a hack happens. And, WordPress get&#8217;s more than it&#8217;s fair share of accusations. Since WordPress is developed by a team of volunteers, it&#8217;s easy to see why they would take offense to these accusations.</p>
<p>However, with as many security releases as WordPress has put out in the last year or so, it&#8217;s certainly not unreasonable to suspect the platform could be the source of a vulnerability. Yes, security releases mean that a threat is being dealt with, but it  also means that exploits were there in the first place.</p>
<p>As I said, hacks happen. The WordPress dev team has very limited resources. Unfortunately there are probably thousands of hackers out there right now trying to figure out how to exploit the platform.</p>
<p>The fact of the matter is it&#8217;s only a matter of time until the next one is found. That doesn&#8217;t mean the WordPress team is made up of horrible people. It just means they&#8217;re out-manned.</p>
<h3>What would you have us do?</h3>
<p>Thankfully, there are several actions the WordPress community (myself included) can take to improve this situation. They include:</p>
<ul>
<li><strong>Be more vocal in praising the WordPress developers for improvements and successes. </strong><br />
Sure there&#8217;s more motivation to comment or blog when you&#8217;re upset. But if the team deserves criticism, then they also deserve credit when they succeed (which happens much more frequently than the slip-ups). I&#8217;m one of the chief perpetrators of this and resolve to do better in the future.</li>
<li><strong>Volunteer to beta-test new releases.</strong><br />
The WordPress dev team is always looking for more testers. The more people looking at the beta releases, the better chance problems will be found before the full release, thus preventing more of the updates we all love to hate.</li>
<li><strong>Don&#8217;t take criticism personally.</strong><br />
This one isn&#8217;t easy but just because someone suggests there could be an issue with your theme, plugin, or even platform, doesn&#8217;t mean they hate you. Mistakes happen. Let&#8217;s figure out how to fix the problem and move on.</li>
<li><strong>Discuss hacks openly</strong>.<br />
One of the biggest mistakes I see being made right now is that information about hacks and vulnerabilities is often treated like a state secret. While I certainly can see the merit in keeping information about how to perpetrate a hack private, in today&#8217;s Twitter world, everyone is going to know when an attack happens.You&#8217;re not going to keep the discussions from happening, so you might as well bring the conversation onto your own turf. When something surfaces that&#8217;s affecting thousands of WordPress users, you need to address it.</li>
<li><strong>Face the facts.</strong><br />
Whether it&#8217;s earned or not, WordPress has a reputation as being a   security problem. The very fact that WordPress get&#8217;s so many hack   reports proves that people are naturally inclined to blame the platform.  Realizing and accepting that will make it easier to go about fixing it.</li>
<li><strong>Hire more security experts.</strong><br />
One of the biggest ways to change the security reputation would be to hire more security experts. It&#8217;s obvious the team will never be able to compete with the number of would-be hackers out there. However, by publicly hiring security experts, you&#8217;ll not only be making a good PR move, you&#8217;d improve the product as well.More folks focusing on security would allow more thorough review of plugins and themes that are submitted, as well as more active pursuit of active hacks or attacks.</li>
</ul>
<h3>Your Suggestions</h3>
<p>Thankfully, the WordPress community is full of people a lot smarter than me. I&#8217;m by no means a security expert (as I&#8217;m sure you&#8217;ve seen over the course of the last few posts) but there are plenty of you out there. What kinds of suggestions do you have? How can WordPress improve the security situation, or are things fine the way they are?</p>
<h6>image source: <a target="_blank" href="http://www.flickr.com/photos/pong/288491653/" target="_blank">rpongsaj</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/wordpress-hack-problems.php/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>WordPress 2.9 Auto-Upgrade Problems Fixed by 2.9.1</title>
		<link>http://wpblogger.com/wordpress-2-9-upgrade-problems.php</link>
		<comments>http://wpblogger.com/wordpress-2-9-upgrade-problems.php#comments</comments>
		<pubDate>Tue, 29 Dec 2009 03:49:25 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=386</guid>
		<description><![CDATA[<blockquote><strong>Update:</strong> WordPress 2.9.1 has been <a href="http://wordpress.org/development/2010/01/wordpress-2-9-1/trackback/" target="_blank">officially released</a> and it seems to have addressed the variety of issues that occurred when upgrading, as well as a problem people had with scheduled posts. I gave it a shot on the two sites that choked on 2.9 and it worked seamlessly so I think it's safe to upgrade at this point.</blockquote>]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/wordpress-2-9-upgrade-problems.php" title="Permanent link to WordPress 2.9 Auto-Upgrade Problems Fixed by 2.9.1"><img class="post_image aligncenter" src="http://wpblogger.com/wp-content/uploads/2009/12/failing-street.jpg" width="500" height="452" alt="WordPress 2.9 Upgrade Issues" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-2-9-upgrade-problems.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-2-9-upgrade-problems.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<blockquote><p><strong>Update:</strong> WordPress 2.9.1 has been <a target="_blank" href="http://wordpress.org/development/2010/01/wordpress-2-9-1/trackback/" target="_blank">officially released</a> and it seems to have addressed the variety of issues that occurred when upgrading, as well as a problem people had with scheduled posts. I gave it a shot on the two sites that choked on 2.9 and it worked seamlessly so I think it&#8217;s safe to upgrade at this point.</p></blockquote>
<p>WordPress released version 2.9 over a week ago but the automatic upgrade has been causing several people problems.</p>
<p>It seems the process will occasionally hang mid-upgrade, often causing database problems with your site.</p>
<p>Sugarrae upgraded her <a target="_blank" href="http://www.sugarrae.com/" target="_blank">afiliate marketing / internet marketing website</a> (a must read if you&#8217;re not already subscribed) and had <a target="_blank" href="http://twitter.com/sugarrae/status/7137107981" target="_blank">disasterous</a> results.</p>
<p>I tried updating one of my own installations tonight but the automatic upgrade didn&#8217;t finish, resulting in every page on my site throwing an error.  Thankfully, I had the site content backed up and I needed to move the blog over to Hostgator anyway.</p>
<p>After tweeting my experiences, fellow <a target="_blank" href="http://www.brooksvillepc.com/pro-blog/" target="_blank">SEO</a>, Dave Curtis mentioned he had just had similar problems.</p>
<p>I&#8217;m willing to chalk one or even two failures up to coincidence but three in a relatively short period of time is enough for a pattern in my mind.</p>
<h3>What Can I Do?</h3>
<p>The first and most important step is to <a href="http://wpblogger.com/how-to-backup-wordpress.php" target="_blank">back up your WordPress installation</a> before attempting an upgrade. That way if anything should go wrong you can reinstall WordPress or your database if it should come down to that.</p>
<p>At this point you can either roll the dice &amp; hope you don&#8217;t have to use those backups you just created, or if you want to be 100% safe, you can always upgrade using the old-fashioned manual method.</p>
<p>I&#8217;ve heard the problems blamed on everything from plugins, to themes, to different versions of PHP. My failed upgrade seemed to be caused by a slow or unresponsive server but I haven&#8217;t been able to verify that. If anyone else has more details on the problem feel free to share them in the comments below.</p>
<p>WordPress 2.9.1 beta has also been released and reportedly fixes some of the bugs that may be causing the upgrade issues but of course, that upgrade has to be done manually as well which can be a bit of a pain for those of us with dozens of installs.</p>
<p>It wouldn&#8217;t surprise me at all for 2.9.1 to be officially released shortly and since 2.9 didn&#8217;t contain security patches this might be a rare instance where not upgrading is the best course of action.</p>
<p><img class="aligncenter size-full wp-image-390" title="upgrade-fail" src="http://wpblogger.com/wp-content/uploads/2009/12/upgrade-fail.jpg" alt="WordPress Upgrade Failure" width="498" height="17" /></p>
<p><strong>Update:</strong> It appears that at least for my failed upgrade, WordPress recognized the failed upgrade and is allowing me to reinstall the upgrade. I know others haven&#8217;t been as lucky but at least some of the failures don&#8217;t appear to cause permanent damage.</p>
<h6>image source: <a target="_blank" href="http://www.flickr.com/photos/cjdaniel/3312922051/" target="_blank">Chris Daniel</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/wordpress-2-9-upgrade-problems.php/feed</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>Brute Force Attack Hitting WordPress</title>
		<link>http://wpblogger.com/wordpress-brute-force-attack.php</link>
		<comments>http://wpblogger.com/wordpress-brute-force-attack.php#comments</comments>
		<pubDate>Mon, 30 Nov 2009 19:51:01 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>
		<category><![CDATA[WordPress Plugin Reviews]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=375</guid>
		<description><![CDATA[Word on the street is that some WordPress blogs are being hit with a brute force attack that is essentially a script that continuously tries to guess the admin&#8217;s password. Dennis Fisher has all the details over on Threatpost summing up the threat with the following: The wp_brute_attempt() function takes 3 parameters, $ch which is [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/wordpress-brute-force-attack.php" title="Permanent link to Brute Force Attack Hitting WordPress"><img class="post_image aligncenter" src="http://wpblogger.com/wp-content/uploads/2009/11/brute-force.JPG" width="500" height="362" alt="Brute Force Attack on WordPress" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-brute-force-attack.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-brute-force-attack.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Word on the street is that some WordPress blogs are being hit with a brute force attack that is essentially a script that continuously tries to guess the admin&#8217;s password.</p>
<p>Dennis Fisher has all the details <a target="_blank" href="http://threatpost.com/en_us/blogs/wordpress-installations-under-brute-force-attack-113009" target="_blank">over on Threatpost</a> summing up the threat with the following:</p>
<blockquote><p>The wp_brute_attempt() function takes 3 parameters, $ch which is cURL&#8217;s structure (cURL is a command line tools that can be used to perform HTTP requests). The other two parameters define the site and the password that will be tried. If the script logged in successfully, the page that gets returned by the server will contain the phrase &#8220;Log Out&#8221;, and the function will return a true value.</p></blockquote>
<p>So how can you protect yourself from this kind of attack?</p>
<p>It&#8217;s actually fairly easy. Change the default administrator&#8217;s login name from admin to something unique and use strong passwords with numbers, capitalized letters, etc.</p>
<p>There&#8217;s also a plugin designed specifically to prevent this sort of brute force attack, called <a target="_blank" href="http://www.bad-neighborhood.com/login-lockdown.html" target="_blank">Login Lockdown</a>.</p>
<blockquote><p>The plugin &#8220;records the IP address and timestamp of every failed WordPress login attempt. If more than a  certain number of attempts are detected within a short period of time from the same IP range, then the login function is disabled for all requests from that range.&#8221;</p></blockquote>
<p>And last but not least, as a last line of defense you should always make sure to regularly <a href="http://wpblogger.com/how-to-backup-wordpress.php" target="_blank">backup your WordPress</a> installation in multiple locations.</p>
<p>I know posts like this seem like nagging or a waste of time but the first time your blog is hacked you&#8217;ll be kicking yourself for not taking action.</p>
<h6>Image Source: <a target="_blank" rel="cc:attributionURL" href="http://www.flickr.com/photos/kadath/">kadath</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/wordpress-brute-force-attack.php/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Dear Matt, Put Up or Shut Up About the GPL</title>
		<link>http://wpblogger.com/put-up-shut-up-gpl.php</link>
		<comments>http://wpblogger.com/put-up-shut-up-gpl.php#comments</comments>
		<pubDate>Fri, 16 Oct 2009 20:55:57 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>
		<category><![CDATA[GPL]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=334</guid>
		<description><![CDATA[In the WordPress world there&#8217;s no quicker and easier way to start a passionate debate than to bring up the issue of the GPL. For those of you new to the discussion, the GPL is the license under which WordPress is distributed. It states, in part, that you&#8217;re free to modify and build on the [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/put-up-shut-up-gpl.php" title="Permanent link to Dear Matt, Put Up or Shut Up About the GPL"><img class="post_image alignnone" src="http://wpblogger.com/wp-content/uploads/2009/10/shut-up.jpg" width="499" height="382" alt="Matt Mullenweg, Put Up or Shut Up About the GPL" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fput-up-shut-up-gpl.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fput-up-shut-up-gpl.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>In the WordPress world there&#8217;s no quicker and easier way to start a passionate debate than to bring up the issue of the GPL.</p>
<p>For those of you new to the discussion, the <a target="_blank" href="http://www.gnu.org/licenses/gpl-2.0.html" target="_blank">GPL</a> is the license under which WordPress is distributed. It states, in part, that you&#8217;re free to modify and build on the code of WordPress, and distribute it in any manner you wish.</p>
<h3>Premium Theme Controversy</h3>
<p>Where the controversy comes in is that the license stipulates that your derivative work inherits the GPL licensing as well.</p>
<p>Where this has become a hot topic for discussion is in regards to &#8220;premium&#8221; plugins and themes.</p>
<p>Several of the most prominent premium themes such as <a href="http://wpblogger.com/thesis-theme-review.php" target="_blank">Thesis</a> or <a href="http://wpblogger.com/headway-theme-review.php" target="_blank">Headway</a> contend their themes do NOT inherit the GPL licensing and have restricted use of their themes accordingly.</p>
<p>Other theme creators such as <a target="_blank" href="http://wpblogger.com/woothemes-review.php" target="_blank">WooThemes</a>, StudioPress, and <a href="http://wordpress.org/extend/themes/commercial/" target="_blank">others</a> have publicly embraced the GPL and structured their business models accordingly.</p>
<p>The most recent entry into the premium theme market, Rocket Theme, states in their FAQ that they adhere to the standards of the GPL and yet price their themes in a manner which directly contradicts the license, a much more deceptive practice than flat out rejecting the license all together.</p>
<p>In short, the WordPress community tends to be all over the map when it comes to the implications of GPL licensing.</p>
<h3>Matt Weighs In</h3>
<p>WordPress creator, Matt Mullenweg, has weighed in on this issue several times, going so far in fact to <a target="_blank" href="http://wordpress.org/development/2009/07/themes-are-gpl-too/" target="_blank">ask a lawyer about the topic</a>.</p>
<p>His position, which is supported by the lawyer and I happen to agree with, is that the PHP of WordPress plugins and themes that are distributed do in fact inherit the GPL licensing regardless of the developers&#8217; wishes. Images and CSS files however, do not necessarily inherit the same licensing.</p>
<p>The problem of course is that some of the framework themes use the PHP to generate the CSS files and use very few if any images. And, as WordPress themes progress, that seems to be the direction more and more themes are heading.</p>
<p>In short, this issue isn&#8217;t going away any time soon.</p>
<h3>Where the Rubber Meets the Road</h3>
<p>The reason this is such a contentious and potentially far-reaching issue is simple&#8230;</p>
<p><strong>Money.</strong></p>
<p>If Matt&#8217;s interpretation of the GPL is accurate, users would be well within their rights to distribute premium themes at a lower price or even for free if they chose to do so.</p>
<p>Naturally some premium theme developers have been very vocal about their opposition to this interpretation of the GPL. In fact, Thesis developer Chris Pearson and Matt Mullenweg have previously feuded over the issue with the threat of legal action being thrown into the mix.</p>
<p>Just last week Matt published the video embedded below in which he says around the 8 minute mark that premium themes that place limits on users&#8217; rights such as number of installations or footer links are &#8220;evil.&#8221;</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="400" height="224" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="src" value="http://v.wordpress.com/ABaVkvrA" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="400" height="224" src="http://v.wordpress.com/ABaVkvrA" allowfullscreen="true"></embed></object></p>
<h3>Put Up or Shut Up</h3>
<p>Now I don&#8217;t know about you, but calling a company evil seems like a pretty strong statement to me. If nothing else it&#8217;s evident that Matt feels strongly about the issue.</p>
<p>Unfortunately, he hasn&#8217;t bothered to actually DO anything about it.</p>
<p>Instead he&#8217;s left users like you and I in the middle to try and interpret the legal language, debate it amongst each other, and contend with the thread of a lawsuit should we decide to embrace the rights he claims we have under the GPL.</p>
<p>So my request to Matt and the rest of the Automattic team is simple. If you honestly believe that WordPress themes inherit the GPL licensing, put your money where your mouth is.</p>
<p>Either distribute the GPL portions of premium themes for all WordPress users to enjoy or file a lawsuit against premium theme companies that don&#8217;t adhere to the GPL.</p>
<p>Automattic certainly has deep enough pockets to be able to afford the legal battle that&#8217;s likely to ensue. And as the creators of several WordPress based businesses, you have a vested financial interest in seeing the case through.</p>
<p>If you&#8217;re unwilling to take either of those steps, then I respectfully ask you to SHUT UP about the issue.</p>
<p>Don&#8217;t sit back and take pot shots at &#8220;evil&#8221; premium theme companies during an interview if you&#8217;re not willing to back your statements up with action.</p>
<p>I happen to agree with your stance on the GPL but I find myself unable to defend your attitude of superiority &amp; intimidation towards non-GPL theme developers.</p>
<p>Either put up, or shut up.</p>
<p>It&#8217;s that simple.</p>
<h6>image source: <a target="_blank" href="http://www.flickr.com/photos/pedpaula/946704784/" target="_blank">pedpaula</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/put-up-shut-up-gpl.php/feed</wfw:commentRss>
		<slash:comments>31</slash:comments>
		</item>
		<item>
		<title>Premium WordPress Themes are Dead</title>
		<link>http://wpblogger.com/premium-wordpress-themes-dead.php</link>
		<comments>http://wpblogger.com/premium-wordpress-themes-dead.php#comments</comments>
		<pubDate>Wed, 26 Aug 2009 23:33:32 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=273</guid>
		<description><![CDATA[After reading iThemes' <a href="http://ithemes.com/growing-better-that%E2%80%99s-what%E2%80%99s-happening/" target="_blank">most recent blog post</a> I came to a startling but suddenly obvious realization... Premium WordPress themes are dead.

I realize that may seem like a foolish statement given the constantly increasing number of premium themes on the market, but its true.

Over the last year, the premium theme that has garnered the most attention has undoubtedly been the Thesis theme.

In recent weeks, the Headway theme has exploded onto the scene and quickly emerged as Thesis' main competitor.

So in light of the still growing popularity of these two themes, why would I proclaim that premium themes are dead?]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/premium-wordpress-themes-dead.php" title="Permanent link to Premium WordPress Themes are Dead"><img class="post_image aligncenter" src="http://wpblogger.com/wp-content/uploads/2009/08/cemetary.jpg" width="500" height="292" alt="Post image for Premium WordPress Themes are Dead" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fpremium-wordpress-themes-dead.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fpremium-wordpress-themes-dead.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>After reading iThemes&#8217; <a target="_blank" href="http://ithemes.com/growing-better-that%E2%80%99s-what%E2%80%99s-happening/" target="_blank">most recent blog post</a> I came to a startling but suddenly obvious realization&#8230; Premium WordPress themes are dead.</p>
<p>I realize that may seem like a foolish statement given the constantly increasing number of premium themes on the market, but its true.</p>
<p>Over the last year, the premium theme that has garnered the most attention has undoubtedly been the Thesis theme.</p>
<p>In recent weeks, the Headway theme has exploded onto the scene and quickly emerged as Thesis&#8217; main competitor.</p>
<p>So in light of the still growing popularity of these two themes, why would I proclaim that premium themes are dead?</p>
<h3>Because.. They&#8217;re Not Themes</h3>
<p>Oh sure they label themselves as themes, contain many of the same files as themes &amp; are installed in the same way as themes, but they&#8217;re not themes.</p>
<p>They&#8217;re <a target="_blank" href="http://www.wolf-howl.com/blogging/thesis-framework-seo/">frameworks</a>.</p>
<p>If you read my <a href="http://wpblogger.com/thesis-theme-review.php" target="_blank">Thesis review</a>, or our guest submitted Headway review, you may have noticed that the thing we liked best about these two &#8220;themes&#8221; was their flexibility.</p>
<p>You can create virtually endless different site designs, all while working within the framework of the Thesis or Headway theme.</p>
<p>And that my friends, is exactly why premium themes are dead.</p>
<h3>Flexibility Killed the Premium Theme</h3>
<p>Sure it&#8217;s nice that companies like iThemes keep turning out new themes, but they&#8217;re fighting a losing battle.</p>
<p>People don&#8217;t want to purchase a different theme for every new site they create or every time they want to redesign their site. We want a framework that allows us to make a vast array of design changes as quickly and easily as possible.</p>
<p>Unless premium theme companies release frameworks of their own, and do it soon before Thesis and Headway gain an even stronger strangle-hold on the market, they&#8217;ll be reduced to even more posts like the one we saw today.</p>
<p>As Monty Python taught us, it you can go around screaming &#8220;I&#8217;m not dead yet&#8221; as much as you want, but you&#8217;ll get carted off just the same.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/grbSQ6O6kbs&amp;hl=en&amp;fs=1&amp;start=50" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/grbSQ6O6kbs&amp;hl=en&amp;fs=1&amp;start=50" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<h6>Image Source: <a target="_blank" rel="cc:attributionURL" href="http://www.flickr.com/photos/paparutzi/">http://www.flickr.com/photos/paparutzi/</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/premium-wordpress-themes-dead.php/feed</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>Dear WordPress, Get it Right the First Time (2.8.3 released)</title>
		<link>http://wpblogger.com/wordpress-2-8-3-security.php</link>
		<comments>http://wpblogger.com/wordpress-2-8-3-security.php#comments</comments>
		<pubDate>Mon, 03 Aug 2009 15:59:34 +0000</pubDate>
		<dc:creator>Ben Cook</dc:creator>
				<category><![CDATA[WordPress News]]></category>

		<guid isPermaLink="false">http://wpblogger.com/?p=216</guid>
		<description><![CDATA[While WordPress 2.8.2 is just two weeks old, WordPress 2.8.3 was released today containing, you guessed it, another security patch. Two weeks ago, I defeneded WordPress&#8217; quick update arguing that it involved a new exploit that obviously needed to be closed. However, the holes that 2.8.3 closes should have been closed two weeks ago. In [...]]]></description>
			<content:encoded><![CDATA[<p><a class="post_image_link" href="http://wpblogger.com/wordpress-2-8-3-security.php" title="Permanent link to Dear WordPress, Get it Right the First Time (2.8.3 released)"><img class="post_image aligncenter" src="http://wpblogger.com/wp-content/uploads/2009/08/3564244382_cb57a92511.jpg" width="500" height="458" alt="Post image for Dear WordPress, Get it Right the First Time (2.8.3 released)" /></a>
</p><div class="tweetmeme_button" style="float: left; margin-right: 10px;">
			<a target="_blank" href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-2-8-3-security.php"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwpblogger.com%2Fwordpress-2-8-3-security.php&amp;source=wpblogger&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>While WordPress 2.8.2 is just two weeks old, <a target="_blank" href="http://wordpress.org/development/2009/08/wordpress-2-8-3-security-release/trackback/" target="_blank">WordPress 2.8.3 was released today</a> containing, you guessed it, another security patch.</p>
<p><a href="http://wpblogger.com/wordpress-xss-vulnerability.php" target="_blank">Two weeks ago</a>, I defeneded WordPress&#8217; quick update arguing that it involved a new exploit that obviously needed to be closed. However, the holes that 2.8.3 closes should have been closed two weeks ago. In fact, the announcement from WordPress admits as much saying:</p>
<blockquote><p>Unfortunately, I missed some places when fixing the privilege escalation issues for 2.8.1.</p></blockquote>
<p>Now I get it, people make mistakes. And yes, WordPress is free to use.</p>
<p>But being free is not a license to suck.</p>
<p>And besides, Automattic, the company behind the WordPress software is a business and believe it or not they do make money as a result of WordPress. The fact that they&#8217;ve been required to release 3 updates in less than a month&#8217;s due to sloppy coding &amp; testing on their part is simply inexcusable.</p>
<blockquote><p><strong>Edit:</strong> As was correctly pointed out to me by an Automattic employee, Automattic is not technically &#8220;behind&#8221; WordPress. There are several other generous souls who contribute to the open source platform. However, 3 of the 5 lead developers of WordPress are Automattic employees, including Ryan Boren who published the post admitting he &#8220;missed some places&#8221; in the 2.8.2 release. Splitting hairs? I think so, but hey at least this post is now accurate.</p></blockquote>
<p>No I&#8217;m not saying WordPress shouldn&#8217;t be releasing this new version. And I&#8217;m not saying that I expect WordPress to be ahead of every conceivable new hack or vulnerability people discover.</p>
<p>But I am saying next time I&#8217;d like a little bit more time spent on security &amp; double checking that ALL the holes are closed.</p>
<p>Maybe instead of developing some of these extra <a target="_blank" href="http://wordpress.org/development/2009/07/2-9-vote-results/" target="_blank">features for 2.9</a>, you can focus on not requiring me to update every single blog I have every two weeks. That&#8217;d save me a lot more time than a feature for people who are too lazy to edit their images in a separate program.</p>
<p>Now if you&#8217;ll excuse me, I&#8217;m off to close several dozen security holes on my server&#8230; again.</p>
<h6>image source: <a target="_blank" href="http://www.flickr.com/photos/almaz73/3564244382/" target="_blank">AlmazUK</a></h6>
]]></content:encoded>
			<wfw:commentRss>http://wpblogger.com/wordpress-2-8-3-security.php/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

