WPIntell

Source evidence

Potential Security Issues

Plugin Notes · support · 2016-11-09T17:52:00+00:00

mixedsentiment
highseverity
0.88relevance
2replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

3 / 31 rows with source links

9.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

28 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
e4girl resolved
Hello! We recently had an audit done to look for potential security issues with plugins we use for our university website. The audit revealed several unsanitized post variables. Is this something you are aware of? If so, is it on the roadmap to be fixed? If not, are you amendable to making the changes? Thank you! There’s quite a lot more I’d like to improve aside from that, but time is limited. I wouldn’t worry about the issue you mention too much as – if I remember correctly – the user authorisations are checked, so it would have to be a malicious admin to do any harm and even then, the harm which could be done is *very* limited as the plugin code is effectively only loaded on the plugins page in the back-end. Patches are very welcome though, please send in a PR on GitHub: https://github.com/mjangda/plugin-notes Thank you for the quick response. I’ll check with my team on a patch and get it to you. 🙂

Comments

2 shown
Juliette Reinders Folmer 2016-11-09T20:05:00+00:00

There’s quite a lot more I’d like to improve aside from that, but time is limited. I wouldn’t worry about the issue you mention too much as – if I remember correctly – the user authorisations are checked, so it would have to be a malicious admin to do any harm and even then, the harm which could be done is *very* limited as the plugin code is effectively only loaded on the plugins page in the back-end. Patches are very welcome though, please send in a PR on GitHub: https://github.com/mjangda/plugin-notes

e4girl 2016-11-09T21:16:00+00:00

Thank you for the quick response. I’ll check with my team on a patch and get it to you. 🙂