You can now fork Cumulus 2.0 on Github

When I decided to no longer maintain my WP-Cumulus plugin a while ago, one of the reasons was that the project was in disarray. I wanted to improve so many things at once, that I ended up finishing none. One of the plugin’s parts however, the actual Flash movie, was 99% done. That’s why I’ve decided to put it on Github.

Note that this is “Cumulus”, without the “WP-”. It’s a new version of the movie, that uses a different, more generic XML format, and supports new things like unicode and device fonts. It’s not a WordPress plugin. If you’re looking to revive WP-Cumulus or incorporate the effect into other projects, it’s the ideal start. It’s the best incarnation of the effect, and I invite you to write stuff around it.

https://github.com/roytanck/cumulus

APPY Geek Honeycomb app is all about tags

Mobiles Republic recently launched a new iOS and Android app that allows you to keep track of the latest geek news. It displays articles from over 70 sources, and uses a clever tagging scheme to navigate between them. Mobiles Republic’s Rudy Viard explains:
More APPY Geek Honeycomb app is all about tags

Roy | August 16, 2011 | English,Software | Comments (1)
Tags: , , , , ,

About the ‘hidden’ links in WP-Cumulus

Recently, I came across discussions on Twitter, and a blog post about ‘hidden links’ in my WP-Cumulus WordPress plugin. Quite frankly, I’m a little embarrassed by this, and I’d like to explain how the situation came to be, and what I plan to change in upcoming versions.
More About the ‘hidden’ links in WP-Cumulus

WP-Cumulus 2.0 is finally in development (again)

I’ve been promising a new version of WP-Cumulus for a long time. I’ve tried working with more experienced PHP developers, but it’s been hard to find a really good one who’s able to devote time to the project. I still think a plugin like this should be a team effort, but for now I’m going to kick things back into motion again myself.

What’s ready at this point is a much cleaner rewrite of the plugin files, with the display logic in a neat little class that port authors will hopefully be able to reuse. I’ve also got a Flash movie that uses a user-defined system font, as a result is much smaller, and supports unicode tags.
More WP-Cumulus 2.0 is finally in development (again)

Closing the comments on WP-Cumulus posts

I hate having to do this, but I’m going to be closing the comments on most of the WP-Cumulus related posts on this blog. Because some have several hundred comments, they’ve become impossible to read and I find that the same questions keep getting asked over and over again. I’ve tried to patiently answer all of them, but I’m no longer able to keep up. Blog comments just aren’t a very good support mechanism.

If your question is about WP-Cumulus, the original WordPress plugin, not one of its ports or variations, please post it in the WordPress forums. This allows others to find the answers, and chances are your question has been discussed already. The forums are an invaluable resource, and offer a much better platform for WP-Cumulus support. If you add the “wp-cumulus” tag to your thread, I’ll almost certainly see it.

I’ll also try to update the FAQ more often. It’s a little out of date, but definitely still a good place to start. Oh, and for more info, see my support page.

BB-Cumulus takes your forum tags for a spin

bbpress logoWP-Cumulus has been ported to quite a few other platforms. I keep bumping into it, often on sites not running WordPress. I’ve given up trying to post about all of these spin-off projects, but this one feels a little special. Gautam Gupta has created a bbPress version. As far as I’m aware this is the first port to another Automattic project (I’m still waiting for a wordpress.com ‘port’, come on Matt ;) ).

So, if you want your forum tags to fly like your blog tags, head over to http://bbpress.org/plugins/topic/bb-cumulus/ for the download.

Help me test WP-Cumulus unicode support

The one feature I’ve always wanted to add to WP-Cumulus is true unicode support. Flash player 9 made this impossible because it needed to have the font characters embedded into the movie, and unicode fonts are simply too big for that. But with Flash 10, Adobe has introduced new ways of handling text, and those now allow for non-embedded text to be animated quite smoothly. There’s also no longer any need to specify an exact font name, you can simply tell the player to get a sans-serif font. Flash player 10 is on over 93% of computers now, so it starts to make sense to use it to finally add this long-awaited feature to WP-Cumulus.
More Help me test WP-Cumulus unicode support

WP-Cumulus updated to address yet another security issue

danger signA few weeks ago I rushed out an update to fix a potentially dangerous Cross-Site Scripting (XSS) vulnerability in WP-Cumulus. With the PHP part of the plugin shielded from ‘outside use’, I was hoping no more issues would pop up. Still, I’m glad MustLive alerted me to another issue that uses the Flash movie itself. The exploit worked by calling the SWF file directly, and supplying link with javascript. I’m not quite sure how dangerous this is, but I’ve modified the movie so it only executes regular links.

Please update your copy of WP-Cumulus to 1.23 asap. For most users it should only take two clicks.

The should not affect how WP-Cumulus works on WordPress blogs. But there have been a number of ports and other projects that use the Flash movie. I urge the authors of those projects to examine the new Flash movie, and see if it still works in/with their product. The exploit is not unique to WordPress, and they may need to modify the security check to fit their project.

WP-Cumulus is now a team effort

team effort tshirtOver the last few months, I’ve not been able to dedicate as much time to the WP-Cumulus project as I’d hoped to. Freelance work has been keeping me pretty busy, and I’ve had to deal with acute issues rather than be able to focus on new features. That’s why I decided to look for help. Just around that time, Luke Morton launched a spin-off version of the plugin that implemented something I’d been meaning to work on too. I contacted Luke and I’m very happy he’s agreed to help develop WP-Cumulus from now on.

Some of the things we’ll be working on are pretty major. We’ll finally move to SWFObject 2.x, look into internationalization (both for the plugin and the Flash movie) and make improvements to the admin screen. We hope to be able to release a true 2.0 version sometime this year.

WP-Cumulus 1.22 fixes a security hole, please upgrade!

danger signYesterday, Thomas Scholz alerted me to a security weakness in WP-Cumulus. He noticed XSS hacking attempts targeted at wp-cumulus.php that could, in rare cases allow malicious code to be executed. This issue has been fixed in version 1.22, and I strongly recommend you upgrade straight away. It’s better to be safe than sorry, and the attack has already been seen ‘in the wild’.

WP-Cumulus can be downloaded here, but chances are your blog will notify you of the new version and allow you to upgrade automatically.