[wp-hackers] WordPress plugin update bugs

Travis Snoozy ai2097 at users.sourceforge.net
Sun Sep 30 12:08:51 GMT 2007


Hey folks,

  I've been having some trouble with getting the plugin upgrade feature
to work for my plugin[1]. I poked around and inferred a bit about how
the update system backend works[2]. Unfortunately, I also found a few
less-than-ideal behaviors, two of which stem from the assumption that
all plugins are hosted with WordPress:

http://trac.wordpress.org/ticket/5115
http://trac.wordpress.org/ticket/5116
http://trac.wordpress.org/ticket/5117

I'm pretty concerned about 5115 and 5117 security-wise, since the user
can get the impression that all his/her plugins are up-to-date when
they're not. Any extra eyes on this feature or comments on the bugs
would be appreciated.


Thanks,

-- 
Travis 

In Series maintainer
Random coder & quality guy
<http://remstate.com/>

[1]
http://comox.textdrive.com/pipermail/wp-hackers/2007-September/thread.html#14874
[2] http://remstate.com/2007/09/30/plugin-updates-and-wordpress-23/


More information about the wp-hackers mailing list