Over on the root of my main website I’ve been trying to set up a newsletter and stone me it’s been more difficult than you would have thought.
There are a number of newsletter/mailing list plugins and I think I’ve tried five of them. For the most part they were simple to install, medium to hard complexity to configure, and all but one of them allowed some super-weird user behaviour which I won’t permit.
After running various tests, I’ve binned them all off except for The Newsletter Plugin, and even this one doesn’t come without its issues.
So, the big story is that (with the exception of The Newsletter Plugin) when a user signs up to a newsletter, they all create that signer-up as a user on the website. This may be a good thing but read on. Spammers/hoaxers and other con artists have bots flying around the Internet looking for these newsletter plugins and – when they find these plugins – they create fake users on your website. The ‘top’ two plugins (in terms of popularity) created approximately 1,000 fake website users per hour. And I’m not happy with that.
Yes, there are mitigating actions you can take. The obvious one is to install a Captcha of some kind, but that should be your fallback – it shouldn’t be the first thing you do after you’ve installed one of these plugins. Having to get yourself a Google Captcha is a symptom of something that’s very wrong. You are, effectively, putting a third-party patch over someone else’s sloppy coding.
Unacceptable? Well, I think so.
Anyway, The Newsletter Plugin seems to be doing what I need it to be doing, but I’m still in Beta test, so I’ll keep my full-throated support muted for now.