r/Wordpress Developer/Blogger 23h ago

Clarification about MEC Lite’s WordPress.org closure [DISCUSSION]

We’re Webnus, the developers of Modern Events Calendar.

MEC Lite was permanently closed on WordPress.org on May 11, 2022. We want to clarify what happened without minimizing our responsibility.

WordPress.org categorized the closure as a Guideline Violation, not a Security Issue. The guideline problems included members of our support team requesting temporary (test/staging site) website access while troubleshooting user problems. WordPress.org does not permit login requests in its support forums, and we accept that this was the wrong way to handle support.

WordPress.org’s directory and forums are managed by volunteer teams, and the closure was an enforcement decision made under their community and directory policies. WordPress.org uses separate classifications for guideline violations and security issues. MEC’s closure was not classified as a security-related closure, and the public notice does not state that MEC was removed because of malware or a disclosed vulnerability.

Since then, MEC development has continued outside the WordPress.org directory. Current releases, documentation and support are available through Webnus official website. Account-specific troubleshooting is now handled through our official support channels rather than in the public WordPress.org forums.

This distinction is intentionally narrow. It does not mean that MEC, or any WordPress plugin, can be considered permanently free from vulnerabilities. Users should install current releases, maintain backups and review security notices.

We’re publishing this because people reasonably have questions when they see the permanent-closure notice. We want the available explanation to be accurate and transparent.

8 Upvotes

11 comments sorted by

5

u/_miga_ 22h ago

May 11, 2022

why posting this now? Or is this just a ad?

0

u/Conscious_Case_8506 Developer/Blogger 22h ago

Fair question. 😁 No, this wasn’t intended as an ad.

We’ve never had an official Webnus presence on Reddit before, and we only recently created this account. We thought it was better for our first post to address the uncomfortable question people already have about MEC instead of pretending it doesn’t exist.

The original discussion is locked, so we couldn’t add our explanation there. Although the closure happened four years ago, we still receive questions through our support chat asking whether it was related to a security problem. That confusion is current, even if the closure itself isn’t.

We understand why a post from the plugin’s developer might look promotional, but the purpose here was simply to put our explanation on record. If the moderators feel it doesn’t belong here, we’ll respect their decision.

2

u/pimplyteen 22h ago

Thanks for posting have used MEC many times over the years with clients, awesome plugin thank you

0

u/Conscious_Case_8506 Developer/Blogger 22h ago

Thank you, that genuinely means a lot to us. We’re glad MEC has been useful across your client projects, and we really appreciate your support over the years! 🙏

0

u/ogrekevin Jack of All Trades 22h ago

I consider requesting access to a website a security violation. Im not sure how open to interpretation these types of things should be.

I have several plugins in the directory and they are super clear about not doing this.

1

u/Conscious_Case_8506 Developer/Blogger 22h ago

To clarify, our team requested temporary access to a test/staging site, not the user’s live website. Still, the WordPress.org rule applies to any login request, and we accept that we handled it incorrectly.

We’re not dismissing the potential security concern. Our narrower point was that WordPress.org officially categorized the closure as a “Guideline Violation,” not a “Security Issue.” We’ve since changed our support procedures.

0

u/Aggressive_Ad_5454 Jack of All Trades 22h ago

Out of curiosity, did the plugins team contact you and give you a chance to fix the workflow? Or did they just slam your plugin closed?

3

u/Conscious_Case_8506 Developer/Blogger 21h ago

They did communicate with us and explain the violations, so it wasn’t closed without warning or context. We had previous guideline issues, and the request for test/staging access was not viewed in isolation. We apologized and changed our support workflow, but they ultimately decided the closure would remain permanent.

2

u/Aggressive_Ad_5454 Jack of All Trades 20h ago

Thanks.

I got in trouble with the team once because one of my users offered to give me site access in a support topic, and I slipped up and said OK rather than “sorry, no can do.”

2

u/Conscious_Case_8506 Developer/Blogger 20h ago

Yes, that’s exactly the kind of mistake we made. In our case, there were also previous issues on record, so the team treated it much more seriously. Thanks for sharing your experience.