WPIntell

Source evidence

I cannot configure the plugin

Secure XML-RPC · support · 2014-10-04T19:40:00+00:00

mixedsentiment
highseverity
0.94relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
apkulasinghe resolved
Hi, Thanks for making this plugin available. It will help many to get protected from hackers. I installed the plugin and went to profile and see the Remote Publishing Permissions but no applications are listed below but I use the jetpack I think it uses the xml-rpc use wptouch mobile converter plugin I think using the xml-rpc but I cannot see any of them listed under the Remote Publishing Permissions I only see link: Add a new application Generate application keys Do I have to manually generate keys from above link and then assign the application names for them accordingly I never use any other method to post or edit my content like mobile or live writer I’m only using jetpack and wptouch plugin and allinone security plugin. Please can you explain me how to configure the plugin Thank you Take care https://wordpress.org/plugins/secure-xml-rpc/ Actually, you can’t configure the plugin that way. It’s specifically a secured XML-RPC layer meant to be used with other systems that require a secured XML-RPC layer. Even if you set up new application keys for Jetpack and WPTouch, they’re using vanilla XML-RPC, not its secured counterpart. The plugin is hosted on WP.org to allow other developers to build on top of it – it won’t automatically secure new applications unless those application developers take the time to implement its more secure interfaces. Sorry for any confusion. Hi, Thanks for the quick explanation. I was confused on how to configure. Ok now I understand that the new plugin developers if they want to use XML_RPC feature they can use your plugin security layer to protect the plugin and the user website. It is a cool idea and would help many plugin developers to easily use the secured layer to communicate and thus will protect the user website. Anyway thanks for the clering the problem. Thank you Take care.

Comments

2 shown
Eric Mann 2014-10-07T04:34:00+00:00

Actually, you can’t configure the plugin that way. It’s specifically a secured XML-RPC layer meant to be used with other systems that require a secured XML-RPC layer. Even if you set up new application keys for Jetpack and WPTouch, they’re using vanilla XML-RPC, not its secured counterpart. The plugin is hosted on WP.org to allow other developers to build on top of it – it won’t automatically secure new applications unless those application developers take the time to implement its more secure interfaces. Sorry for any confusion.

apkulasinghe 2014-10-08T13:57:00+00:00

Hi, Thanks for the quick explanation. I was confused on how to configure. Ok now I understand that the new plugin developers if they want to use XML_RPC feature they can use your plugin security layer to protect the plugin and the user website. It is a cool idea and would help many plugin developers to easily use the secured layer to communicate and thus will protect the user website. Anyway thanks for the clering the problem. Thank you Take care.