Publishing and distributing first-party packages for WordPress
Yesterday, the WordPress.org team started a long-term supply chain attack against Advanced Custom Fields. This involved effectively forking the project, repackaging it as Secure Custom Fields, and deploying it under the original slug which led to thousands of users updating to SCF without notification or the ability to select whether they wanted SCF. This is an unfortunate abuse of authority and only continues to highlight the significant vulnerability that the community faces with WordPress.org being… continue reading.