19 points ascorbic 3 hours ago 7 comments

samtp 2 hours ago | parent

Unless I'm missing something, the current plugin registry [0] is pretty useless compared to WordPress or even Envato without stats for number of installs, ratings, and reviews/comments.

[0] https://plugins.emdashcms.com/

ascorbic 2 hours ago | parent

We launched the plugin registry last week, and our focus has been on safe, decentralised plugin distribution and discovery. Stats, ratings etc are valuable, but they need careful design to prevent abuse. We will definitely add them later.

samtp 1 hour ago | parent

Appreciate the context. But my larger point is that all of the sandboxing and plugin permission security features falls flat until you can easily evaluate the plugins themselves from social signals and even looking at the code on Github. It's one of the main aspects the people overlook when trying to replace WordPress is the developer network, reviews, ratings, etc.

Otherwise you just have to trust the random plugin publisher and the permissions/sandboxing doesn't really matter.

nkohari 59 minutes ago | parent

What you're actually saying is that network effects are strong. Those network effects are the only reason Wordpress is still so commonly-used.

But, that has very little to do with the work described in the OP. Maybe EmDash will fail to gain sufficient traction to have their own network effects, but in the meantime, doing moderation on plugins in their marketplace is still important work. Automated moderation to prevent abuse and malware is useful, and is orthogonal to the social proof you're talking about.

samtp 47 minutes ago | parent

Thats not what I'm saying at all. I really like a lot about EmDash and would love for a different default CMS to overtake WordPress.

What I am saying is that there are different levels of types trust when it comes to incorporating outside code into your project (in the form of packages/plugins/extensions):

1. Being able to quickly understand what the code does and what effect it will have (screenshots are pretty big here for CMS plugins)

2. Being able to examine the code before installation

3. Seeing feedback from others on the quality of the code and how well it meets the objectives

4 Limiting what the code can do once you install it

Right now the EmDash plugin catalog really only does #4. I don't see any screenshots of the UI of these plugins, there is no link to the repo, there is no indication if a plugin is used by 100 people or no one, and there is no feedback from anyone who has used it.

The bottom line is that there are several layers of trust that outside code has to pass before you even install it and consider what permissions to grant it. Ignoring that makes it very difficult for someone to start trying out different plugins. And it also makes me hesitant to develop a plugin, because it seems like it has very little chance of standing out from all the rest, even if it becomes popular.

earthlingdavey 52 minutes ago | parent

The permissions/sandboxing (and Clef review) IS the reason you can have a reasonable confidence in trusting a random plugin publisher.

samtp - I think you're looking for the answer to two or more problems here.

  - Can I trust that a plugin is (relatively) secure?  
  - Can I trust that the plugin will be maintained?  
  - Can I trust that the plugin will be good quality and work as described?
So far EmDash has an answer to what I think is the most important question (IMO). Can I trust that a plugin is (relatively) secure? Yes.

That's something WordPress haven't been able to do - so I'd say well done to the EmDash team! And, if I wasn't building my own CMS (with a very similar permission model) then I would probably be trialling it right now :)

samtp 40 minutes ago | parent

Don't get me wrong, I would love for another CMS to overtake WordPress and the features EmDash has launched with around plugin security is great.

I've spent a lot of time browsing and using plugin/extension marketplaces. One of the main questions that you have when deciding on a plugin is your last one question - specifically the quality of the plugin and if does what it says it will do. But when I look at the EmDash marketplace, there is almost no way to judge the quality of the plugin (especially the UI/UX without screenshots) or if it actually does what it says it will do. And that is usually the first question you ask before going into the security and maintenance. Because if it looks terrible, slows down your site, and doesn't really work - who cares if it's maintained and secure?