WPIntell

Source evidence

Please improve plugin security

Activity Log – Monitor & Record User Changes · support · 2025-05-30T10:05:00+00:00

mixedsentiment
highseverity
0.83relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 32 rows with source links

18.8% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

26 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Alexandru Negoita resolved
Hei, I just tested the plugin through WordPress standards and it seems that there are issues that needs to be fixed. There are unescaped values in the plugin which can pose a threat to the site security, even when the plugin is only used in admin interface. For example: $where[] .= ‘`object_type = \'' . $type . '\''; Combined with _roles values, which can also have allot of various data, it could potentially lead to escalated privileges. Hi @kulsite , Thank you for researching our plugin! To better serve the researcher community, we’re running a managed public Bug Bounty program on Patchstack: https://patchstack.com/database/wordpress/plugin/aryo-activity-log Please open a Patchstack account if you don’t already have one, join our program and submit your findings. The program contains all the information you’ll need in order to submit a report. Best regards,

Comments

1 shown
ArielK 2025-05-30T11:36:00+00:00

Hi @kulsite , Thank you for researching our plugin! To better serve the researcher community, we’re running a managed public Bug Bounty program on Patchstack: https://patchstack.com/database/wordpress/plugin/aryo-activity-log Please open a Patchstack account if you don’t already have one, join our program and submit your findings. The program contains all the information you’ll need in order to submit a report. Best regards,