• I know that an update is good for a plugin. But, seriously? Updating the plugin everyday? So, I am starting to think if the plugin is still secured or if the codes are properly configured. May I ask what’s the intention to update the plugin everyday? Do you just add colon then save – update 1.0 then add another semi-colon becomes update 1.1?

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author Daan van den Bergh

    (@daanvandenbergh)

    Well, duh. I release an update after every character I type. I always do. 😛

    Am I working too hard? Haha, I had no idea that releasing many updates would raise suspicion somewhere in the world.

    Anyway, to explain the recent peak in updates. Sometimes when you add a new feature, like I did recently, new bugs are introduced. So two days ago I fixed one bug, because someone was waiting for it. And yesterday I fixed the other, because someone else was waiting for it. Oh, and I did some severe performance improvements. And I’ll be releasing another update soon, with some more performance improvement.

    If you want to know if a plugin contains any risky code, you can use coderisk. It’s a couple versions behind on CAOS, but when you look at the graph, you’ll see that CAOS has always been secure: https://coderisk.com/wp/plugin/host-analyticsjs-local

    Also, use WordFence or an equivalent on your site. It scans plugin code with every update, and deactivates any plugin that suddenly went rogue.

    Hope this helps.

    Plugin Author Daan van den Bergh

    (@daanvandenbergh)

    Oh, and another thing:

    Perhaps it’s good to have an understanding of what it means to maintain a freeware, open source plugin.

    It’s freeware, in other words: I do this in my spare time.

    Lately I have some spare time on my hands, so whenever I’m done with an assignment, I release it. Because it might just be that I won’t have any spare time the coming weeks or even months. What if in the meantime my laptop crashes or gets stolen? I lose my work.

    Corporate companies can/have to keep to a release schedule, because it helps them organise. I can’t do this, because I can only maintain this plugin in my spare time. And I have a really busy life.

    Hope this helped you gain some understanding.

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Is the plugin secured?’ is closed to new replies.