WPIntell

Source evidence

Backdoor

Showdown · support · 2016-03-06T15:35:00+00:00

mixedsentiment
highseverity
0.83relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

4 / 28 rows with source links

14.3% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

24 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
woofdriver resolved
Our site was hacked, and our email server was passing third party spam. Our ISP identified it as a pass through from WordPress coming from a form/forum plugin. We installed Anti-Malware from GOTMLS.NET. It found code identified as a backdoor threat installed in your plugin. We currently have version 1.5.5 of your plugin. Are you aware of this issue? Is there a newer version of our plugin that addresses it? https://wordpress.org/plugins/showdown/ Hi Woofdriver, Just ran the scan against our dev site and not seeing any issue with our plugin. Can you send us a screenshot of what you are seeing? I’m not too sure that the Anti-Malware plugin from GOTMLS.NET is reliable, as it is pointing at a number of WordPress files and claiming that they are ‘Potentional Threats’. I would expect that it would know if WordPress include files are dangerous or not. If I can recommend a different security plugin, I make extensive use of Wordfence which I believe is the best security plugin available at the moment ( https://wordpress.org/plugins/wordfence/ ). Can I recommend you use this to prevent your site being hacked. Regards Owen

Comments

1 shown
owencutajar 2016-03-26T13:35:00+00:00

Hi Woofdriver, Just ran the scan against our dev site and not seeing any issue with our plugin. Can you send us a screenshot of what you are seeing? I’m not too sure that the Anti-Malware plugin from GOTMLS.NET is reliable, as it is pointing at a number of WordPress files and claiming that they are ‘Potentional Threats’. I would expect that it would know if WordPress include files are dangerous or not. If I can recommend a different security plugin, I make extensive use of Wordfence which I believe is the best security plugin available at the moment ( https://wordpress.org/plugins/wordfence/ ). Can I recommend you use this to prevent your site being hacked. Regards Owen