• Resolved girdy74

    (@girdy74)


    No other platform is reporting this plugin with a security issue and I can’t seem to find any relative information for Sept 2025 (since the plugin has been updated). I see reports back in 2023/24 with version 2.9.# but not the new version 3.0.1. Is this a legit warning or is it a false/positive?

    Warning from Jetpack Protect plugin: The installed version of Countdown builder (3.0.1) has known security vulnerabilities.

    • This topic was modified 6 months, 1 week ago by girdy74.
    • This topic was modified 6 months, 1 week ago by girdy74.
Viewing 5 replies - 1 through 5 (of 5 total)
  • Plugin Support fujifika (a11n)

    (@fujifika)

    Hi @girdy74,

    Thanks for bringing this up. I checked the WPScan report for the plugin countdown-builder and didn’t see any vulnerabilities flagged there for version 3.0.1. Are you seeing this flagged in your Jetpack Scan dashboard (https://cloud.jetpack.com/scan/)?

    If you are, could you share the URL of your site where it’s flagged so we can investigate further? It might be a false positive, which we can escalate internally.

    If you’d rather keep things private, you’re welcome to contact us via this form: [Contact Form]

    Please include a link or reference to this forum thread when contacting us so we know what you’re referring to.

    Thanks!

    Thread Starter girdy74

    (@girdy74)

    Shoot, the plugin is no longer installed. The client didn’t think they were using it so they just decided to uninstall it.

    It was in the WordPress admin area of the website under the JetPack Protect area under “all threats”:

    Plugin Support fujifika (a11n)

    (@fujifika)

    Hi @girdy74,

    Thanks for sharing the screenshot, got it, and no worries at all. If your client doesn’t need the plugin, then removing it sounds like the right call.

    I went ahead and tested version 3.0.1 of the plugin on my own test site but wasn’t able to trigger the same vulnerability alert, so for now, it does look like this was a false positive. If your client ever decides to use the plugin again, and if it gets flagged, feel free to reach back out, and we’ll take another look while it’s still active on the site.

    Thanks again for sharing this, and let us know if you have any other questions! 🙂

    Thread Starter girdy74

    (@girdy74)

    Great! Thanks so much for help 🙂

    Plugin Support Stef (a11n)

    (@erania-pinnera)

    Hi there, @girdy74,

    You’re very welcome – hope we did help 🙂

    I’m going to mark this thread as solved. If you have any further questions or need more help, you’re welcome to open another thread here. Cheers!

Viewing 5 replies - 1 through 5 (of 5 total)

The topic ‘Countdown builder (3.0.1) has known security vulnerabilities’ is closed to new replies.