Just frankly speaking, if vBulletin.org is going to call itself 'The Official vBulletin Modifications Site' it should do basic audits and take trivial responsibility for the modifications that it hosts and therefore distributes.
I know it sounds unreasonable. But you have to look at it from the eyes of an end user. This site labels itself as the OFFICIAL modifications site. The term 'official' carries a lot of weight.
You see, even though they shouldn't, people make a solid connection between the two sites. When something goes awry with a modification, people make an instant connection with vBulletin as a product and that's when poop hits the fan. Rumors fly and the grape vine grows. All of a sudden the flaws in a 3rd-party plugin become the 'flaws' of the core product.
To the best of my knowledge, forum softwares such as MyBB and Simple Machines do have basic security audits of plugins and modifications before they are allowed to be listed on the official websites. They are a free product, it's a community effort.
My point is, if vBulletin.org isn't going to make an effort to ensure the items that they distribute are safe, they should drop the 'Official' bit in the slogan. It's more trouble than it's worth, it makes vBulletin as a product look bad. Things like the CMS, Blog, and Mobile Suite are 'Official' modifications. Not the stuff here.
Just my .02
|