WordPress.org

Ready to get started?Download WordPress

Forums

iThemes Security (formerly Better WP Security)
[Plugin: Better WP Security] Dozens of blank file change warning emails a day (8 posts)

  1. Yaron Guez
    Member
    Posted 1 year ago #

    I have been getting close to a dozen file change warning emails a day from almost all of my sites that have this plugin installed. The emails are almost completely blank:

    A file (or files) on your site at http://trestian.com have been changed. Please review the report below to verify changes are not the result of a compromise.

    Followed by...nothing. The rest of the email is totally blank. These emails all come at once as well. They don't trickle over the day. I just wake up to 10 or so emails sent at the exact same time with the exact same empty content. Any help would be appreciated, thanks!

    http://wordpress.org/extend/plugins/better-wp-security/

  2. dukejames27
    Member
    Posted 1 year ago #

    I must admit that I receive these e-mails very often as well. I use a security scanner to analyze my WordPress site and inform me of any vulnerabilities. Take a look at BWPS logs to determine if there were file changes or 404 errors. If it helps, clear the log so you can start fresh and analyze from there.

    For me, there were no file changes. I haven't made any changes to the site and BWPS logs does not indicate that there were any. It does however state that there were 404 errors found. Therefore, the e-mail should adapt or be tuned to the 404's, not file changes.

    "Please review the report below to verify changes are not the result of a comprimise."

    I don't think this message should be within the e-mail because there is no details within the e-mail or even an attachment.

    Lastly, I think it would be very helpful if IP addresses were logged so that I can research where the file changes or 404's came from. I plan on making this suggestion on the "Suggestion" thread.

  3. dukejames27
    Member
    Posted 1 year ago #

    Oh yes, I'd like to know why there are so many alerts rather than just one. Are e-mails meant to be sent once a day or each time a detection is made?

  4. It should only be sending daily although I can see how certain caching situations might result in more emails. I'll see if I can't rework the scheduler for some better reliability.

  5. Yaron Guez
    Member
    Posted 1 year ago #

    Thanks! I appreciate the effort. I am on the verge of disabling the feature all together and using File Change Monitor instead. I literally get 5 BLANK emails a day from every one of my sites. Most of the sites use W3 Total Cache but not all and the problem affects them all.

  6. @yguez. Thanks. I understand with that feature. Have you tried turning off only the emails for it?

  7. Yaron Guez
    Member
    Posted 1 year ago #

    I need the emails to notify me. I have this plugin installed on over a dozen sites so I can't log into each daily to see if any files have changed. It would be great if this notification system could be cleaned up to remove all the false positives (for example from updating a plugin) and blank emails. Thanks!

  8. grahman
    Member
    Posted 1 year ago #

    I started a new post that may be related to this post. I have a solution to the problem I was experiencing there (blank file-change notifications).

    It may be helpful to others who land on this support topic.

    http://wordpress.org/support/topic/blank-file-change-notifications

Topic Closed

This topic has been closed to new replies.

About this Plugin

About this Topic