• Resolved peopleinside

    (@peopleinside)


    Hi,
    today my security system Wordfence alert me about a malicious URL in your plugin. The bad URL seems to be the URL of your demo that is currently not working “Error establishing a database connection”. I cannot post here, in public the malicious URL but you should know it or tell me how send privately.

    Also I see other than your demo that is currently not working, looks bad also the domain where your demo is hosted. If I remove the first demo address before the domain and load only your domain, the home page say: “Hello There, Nothing Here!”

    When I saw this I through your website was hacked and associated this think to the malicious URL alert I get by Wordfence.

    I’m not happy to use a plugin that is reported as malicious and I dont like to find a website with a white page that say Hello There, Nothing Here!.

    I suggest to be always strong with security and to avoid this situations where:

    • Your demo site (subdomain) has error connecting to the database and let me think has been hacked
    • If I load the main domain a white page say “Hello There, Nothing Here!”, considering the demo is KO, a malware alert about your plugin has been received by me and a white page is loaded when I load your main domain of the demo let me think something of strange is there
    • Received an email from Wordfence that say found a malicious blocked URL in your plugin

    I’m not feeling safe now and I’m thinking to find an alternative plugin.
    I suggest to improve that situation and your security.

    • This topic was modified 3 years, 2 months ago by peopleinside.
    • This topic was modified 3 years, 2 months ago by peopleinside.
Viewing 4 replies - 1 through 4 (of 4 total)
  • Thread Starter peopleinside

    (@peopleinside)

    I want think this is a false positive, in any case you should resolve maybe the fact your URL is blacklisted and your website has maybe two different issues:

    • Demo is not working and the demo link is blacklisted as malware URL
    • If your main-domain is loaded, a sentence like what you have in a blank empty page can made someone think bad, especially as in this case, if your demo subdomain on that domain is broken and reported as malware URL.

    Hi @peopleinside

    We are sorry for the inconvenience. Our team was migrating the site from one server to another server. That’s is why the “Database connection” error was showing.

    Anyway, we’ve fixed everything related to the “Malware URL” issue and updated the plugin.

    Please update your plugin to the latest version and let us know.

    If you have any questions, please let us know.

    Thanks!

    Thread Starter peopleinside

    (@peopleinside)

    Thank you, for now I have removed the plugin but I’m glad to see you fixed the issue. Your demo seems working now.

    Thanks again.
    Wish you the best.

    Thanks for letting us know.

Viewing 4 replies - 1 through 4 (of 4 total)

The topic ‘Malware URL in the plugin found,’ is closed to new replies.