I've been maintaining the matrix_api module on Drupal.org since 2016, nearly a decade of it doing one thing well: posting Drupal events into a Matrix room. This year that changed.
I've been maintaining the matrix_api module on Drupal.org since 2016, nearly a decade of it doing one thing well: posting Drupal events into a Matrix room. This year that changed.
Last month, a critical WordPress vulnerability triggered emergency patching across the web — and reignited a familiar argument: if WordPress keeps having security problems, why not let AI build something new instead?
It’s a reasonable question.
AI has made software dramatically cheaper and faster to create. But somebody still has to understand it, patch it, test it, and keep it running eighteen months from now.
That’s the part of the “AI instead of WordPress” pitch we think is getting overlooked.
Gabor asked in Slack about how people contributing to Drupal manage multiple different Drupal versions, and different contributed module branches, when using AI agents:
On July 17, WordPress shipped an emergency security release for a vulnerability chain now being called wp2shell.
While your site is running, things change. A content editor tweaks a configuration setting. A security vulnerability surfaces in a dependency. A production fix gets applied directly instead of going through the normal release process.