← Back to context

Comment by earthlingdavey

4 hours ago

The permissions/sandboxing (and Clef review) IS the reason you can have a reasonable confidence in trusting a random plugin publisher.

samtp - I think you're looking for the answer to two or more problems here.

  - Can I trust that a plugin is (relatively) secure?  
  - Can I trust that the plugin will be maintained?  
  - Can I trust that the plugin will be good quality and work as described?

So far EmDash has an answer to what I think is the most important question (IMO). Can I trust that a plugin is (relatively) secure? Yes.

That's something WordPress haven't been able to do - so I'd say well done to the EmDash team! And, if I wasn't building my own CMS (with a very similar permission model) then I would probably be trialling it right now :)

Don't get me wrong, I would love for another CMS to overtake WordPress and the features EmDash has launched with around plugin security is great.

I've spent a lot of time browsing and using plugin/extension marketplaces. One of the main questions that you have when deciding on a plugin is your last one question - specifically the quality of the plugin and if does what it says it will do. But when I look at the EmDash marketplace, there is almost no way to judge the quality of the plugin (especially the UI/UX without screenshots) or if it actually does what it says it will do. And that is usually the first question you ask before going into the security and maintenance. Because if it looks terrible, slows down your site, and doesn't really work - who cares if it's maintained and secure?