• Resolved gecko_guy

    (@gecko_guy)


    Hi,

    Looks like people are still downloading the plugin even though it hasn’t been updated in 2 years.

    Sometimes plugins don’t need to be updated because of their simplicity and robustness, but on the other hand there have been a load XSS breaches in WP plugins in recent times, so it’s always nice to get some reassurance.

    This plugin is still also being linked to from some very high profile theme developers such as Elegant Themes.

    If the plugin is still being supported and simply doesn’t need to be updated because it is robust and works, could you maybe just update the certification of compatibility for WP 4.5+ ?

    Thanks

    https://wordpress.org/plugins/ajaxize/

Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Author yoav.aner

    (@yoavaner)

    Hi gecko_guy,

    Thanks for reaching out. It’s a very valid concern indeed. The last thing you’d want is some stale software with a bug waiting to be exploited. At the same time, there’s no guarantee that a newly developed, or frequently updated plugin is free of bugs or security holes.

    I believe that this plugin is simple and small enough not to warrant too many updates. It does one thing, and I hope it does it well. For better or worse, it’s not something that you’ll add a ton of features to and get a lively community around. I did build it with security in mind, as you can hopefully see from the documentation and the code. However, I cannot possibly claim that it’s free of bugs or security holes. Just that I haven’t come across any that warranted an update.

    I would encourage you and anybody else to look into the code and let me know if there’s any problem worth fixing. It’s open-source and I would love not to be the only one who actively maintains it.

    You’re right that I should update and indicate its compatibility with latest versions of wordpress. I’m running it on the latest version just fine. It’s mostly out of lazyness (and slightly to blame svn and the wordpress plugin ecosystem which feels a bit clunky to work with for me).

    Hope this answers your questions and concern. If there’s anything else, let me know.

    Cheers,
    Yoav

    Thread Starter gecko_guy

    (@gecko_guy)

    Hi Yoav,

    Thanks for the very quick reply. I did browse the code in SVN and it all looks fine to me, but it would be nice just to see that it is certified compatible with 4.5+.

    If you manage to find a bit of time to get it verified that would be great, although with your reply I will give it a try now anyway.

    Best,

    Guy

    Plugin Author yoav.aner

    (@yoavaner)

    You’re welcome, Guy.

    I just pushed an update after testing it with 4.5.2 …

    Cheers,
    Yoav

    Plugin Author yoav.aner

    (@yoavaner)

    If you’d like to help, please test it and vote for its compatibility.

    Once you use it, and if you find it useful, would be great if you could also rate it 🙂

    Thread Starter gecko_guy

    (@gecko_guy)

    yes of course. happy to provide feedback and rating (and if I run into problems will open a support post before rating of course 🙂

Viewing 5 replies - 1 through 5 (of 5 total)
  • The topic ‘Is the plugin still current and secure?’ is closed to new replies.