← Back to context

Comment by earthlingdavey

1 day ago

The permissions/sandboxing (and Clef review) IS the reason you can have a reasonable confidence in trusting a random plugin publisher.

samtp - I think you're looking for the answer to two or more problems here.

  - Can I trust that a plugin is (relatively) secure?  
  - Can I trust that the plugin will be maintained?  
  - Can I trust that the plugin will be good quality and work as described?

So far EmDash has an answer to what I think is the most important question (IMO). Can I trust that a plugin is (relatively) secure? Yes.

That's something WordPress haven't been able to do - so I'd say well done to the EmDash team! And, if I wasn't building my own CMS (with a very similar permission model) then I would probably be trialling it right now :)

Don't get me wrong, I would love for another CMS to overtake WordPress and the features EmDash has launched with around plugin security is great.

I've spent a lot of time browsing and using plugin/extension marketplaces. One of the main questions that you have when deciding on a plugin is your last one question - specifically the quality of the plugin and if does what it says it will do. But when I look at the EmDash marketplace, there is almost no way to judge the quality of the plugin (especially the UI/UX without screenshots) or if it actually does what it says it will do. And that is usually the first question you ask before going into the security and maintenance. Because if it looks terrible, slows down your site, and doesn't really work - who cares if it's maintained and secure?

  • All of the plugins I looked at have a "view source" button that takes me to a github repo (though the payments plugin link is broken). Presumably you could install the plugin from source as well... would that not be a better signal than number of users?

    At this point you could probably just run it through an LLM yourself and ask it if it does what it claims, if the code is straightforward, or if there are any seemingly obfuscated bits. If something is on a safety-critical path, you should probably do the review yourself.

    • Ah that is my mistake because must have clicked a few that didn't have that button.

      But still social signals from others and especially screenshots are 1000x more important to me than an AI summary of the code base.

  • This is a valuable insight - and you are probably in the majority. Thanks for taking the time to explain, this is probably valuable user research for the EmDash folks :)