[wp-hackers] Somehow critical wp.org/extend/plugins issue

Matt Martz matt at sivel.net
Fri Aug 28 13:01:52 UTC 2009


On Fri, Aug 28, 2009 at 8:56 AM, Simon
Wheatley<simon at sweetinteraction.com> wrote:
> Presumably that means you have commit rights to remove your name as
> contributor in the readme.txt? (Is that where the data is read from?)
>
> S
>
>
> On Fri, Aug 28, 2009 at 1:54 PM, Ozh<ozh at planetozh.com> wrote:
>> Peeps,
>>
>> Just checked my profile on wp.org/extend/plugins
>> <http://wordpress.org/extend/plugins/profile/ozh> and noticed that a
>> plugin I don't know appears in the list. It turns out I'm listed as a
>> contributor, which I am not (AdSense Immediately!)
>>
>> The problem with this plugin is that is contains several hardcoded
>> base64_decode() shits with author's adsense code and not sure what
>> else (didn't extensively check)
>>
>> I have the feeling I'm listed as a contributor to add authority to the
>> plugin, but I definitely don't want to be associated with it. Other
>> plugin authors might want to check their profile listing for any
>> similar finding.
>>
>> As a bonus, there is no valid contact info on this plugin, I have no
>> clue who the dummy is...
>>
>> --
>> http://planetOzh.com ~ Blog and WordPress Stuff
>> http://FrenchFragFactory.net ~ Daily Quake News
>> _______________________________________________
>> wp-hackers mailing list
>> wp-hackers at lists.automattic.com
>> http://lists.automattic.com/mailman/listinfo/wp-hackers
>>
>

All that is required is that a user put your wp.org username in their
readme.txt file.  It doesn't mean you have to have commit access to
the plugin.  It is just a way to list contributors and unfortunately
makes their plugin show in your profile too.  Sometimes users will do
this if they have taken code from your plugin.  Not sure, but it is
conceivable that a user could do this to get better rankings/downloads
of their plugins.

Perhaps verifying this against the list of users with commit access to
that plugin should be done.  Dunno, but I have at least one plugin
that I don't have commit access to that I do contribute code to and am
listed as a contributor in readme.txt and on wp.org.

-- 
Matt Martz
matt at sivel.net
http://sivel.net/


More information about the wp-hackers mailing list