The recent travails of WordPress have caused consternation among the web community that relies on the platform, which powers more than four in ten websites online today. Now, a coalition of prominent WordPress contributors and the Linux Foundation is unveiling a federated update and plugin-distribution network aimed at eliminating what they describe as a critical “supply chain security” vulnerability at the core of the world’s most widely used website system.

The FAIR Package Manager project, to be announced at a conference in Switzerland later today, enables web-hosting companies and large organizations to run their own mirrors of WordPress’s core update, plugin, theme, and translation servers. This setup would replace reliance on WordPress.org—a domain controlled by Automattic CEO Matt

See Full Page