WPIntell

Source evidence

Is this plugin still maintained?

Minify HTML · support · 2023-02-21T19:51:00+00:00

mixedsentiment
highseverity
0.95relevance
6replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

7 / 35 rows with source links

20.0% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
markb resolved
Hello, just wanting to hear from the author whether this plugin is actively maintained. Cheers. Sure is. No updates because I don’t have any issues with it. Can you comment on this please – https://snipboard.io/tHW3Ph.jpg No clue, sounds like a false positive warning. Contact WP Toolkit and ask why the following code would trigger that error: https://plugins.trac.wordpress.org/browser/minify-html-markup/trunk/minify-html.php That link is the entire code for Minify HTML, and it doesn’t do anything with CSRF. My guess is WP Toolkit is overzealous and is looking for a string which happens to also be in the Minify HTML plugin. To be clear, this isn’t a problem with this Minify HTML, it’s a potential CSRF issue with WordPress and *any* plugin. I’ve updated Minify HTML to ( v2.1.1 ) to address the potential WordPress vulnerability issue. This should now be resolved. Hi Tim, I like your plugin but I’ve got an Wordfence alert : “Minify HTML” has a security vulnerability. Type: Plugin Vulnerable “ “ Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Minify HTML” until a patched version is available. “ “Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/ef7cf633-e907-4da1-bd96-0013e88defbb?source=plugin” ; Regards, S.L There’s an over-zealous group which is profiting on reporting plugins for trivial potential security “issues”. In any case, the plugins has been updated to address this issue. If you’re using the latest version of Minify HTML (v 2.1.8 ), the issue has been resolved. If it’s still reporting a problem, it’s a false-positive at this point as they haven’t updated their system yet that the latest release resolves the problem. You may be able to contact word fence and have them update their database. This reply was modified 3 years, 3 months ago by Tim Eckel .

Comments

6 shown
Tim Eckel 2023-02-22T02:58:00+00:00

Sure is. No updates because I don’t have any issues with it.

markb 2023-02-22T20:38:00+00:00

Can you comment on this please – https://snipboard.io/tHW3Ph.jpg

Tim Eckel 2023-02-22T21:13:00+00:00

No clue, sounds like a false positive warning. Contact WP Toolkit and ask why the following code would trigger that error: https://plugins.trac.wordpress.org/browser/minify-html-markup/trunk/minify-html.php That link is the entire code for Minify HTML, and it doesn’t do anything with CSRF. My guess is WP Toolkit is overzealous and is looking for a string which happens to also be in the Minify HTML plugin.

Tim Eckel 2023-02-24T21:14:00+00:00

To be clear, this isn’t a problem with this Minify HTML, it’s a potential CSRF issue with WordPress and *any* plugin. I’ve updated Minify HTML to ( v2.1.1 ) to address the potential WordPress vulnerability issue. This should now be resolved.

surflibre 2023-03-15T12:59:00+00:00

Hi Tim, I like your plugin but I’ve got an Wordfence alert : “Minify HTML” has a security vulnerability. Type: Plugin Vulnerable “ “ Details: To protect your site from this vulnerability, the safest option is to deactivate and completely remove “Minify HTML” until a patched version is available. “ “Vulnerability Information: https://www.wordfence.com/threat-intel/vulnerabilities/id/ef7cf633-e907-4da1-bd96-0013e88defbb?source=plugin” ; Regards, S.L

Tim Eckel 2023-03-15T15:54:00+00:00

There’s an over-zealous group which is profiting on reporting plugins for trivial potential security “issues”. In any case, the plugins has been updated to address this issue. If you’re using the latest version of Minify HTML (v 2.1.8 ), the issue has been resolved. If it’s still reporting a problem, it’s a false-positive at this point as they haven’t updated their system yet that the latest release resolves the problem. You may be able to contact word fence and have them update their database. This reply was modified 3 years, 3 months ago by Tim Eckel .