Add to Allowlist
-
(Free Version)
We use WhatConverts to track users. One of the pieces of code provided by WhatConverts to instert the tracking into the <head> is being deleted by Wordfence. It contains the address ‘s.ksrndkehqnwntyxlhgto.com’ which is where the WC code comes from. How do I add this to the Allowlist? If I paste this in , it will not allow me to save?
Thanks!
-
Hi @jonahall59, thanks for reaching out.
It sounds to me like you’re logged in as an admin and trying to update a code snippet using a custom header/footer editor plugin (or similar feature). It is still possible to get false-positives when Wordfence thinks something being added is harmful, but you should be able to override it if you’re satisfied the code is actually something safe.
Take a look here: https://www.wordfence.com/help/firewall/learning-mode/#what-to-do-if-a-page-is-blocked-after-learning-mode-is-complete
Let us know how you get on,
Peter.Thanks – unfortunately, that didn’t work (the line of WhatConverts code was still removed).
Yes, I am logging in as an admin. We are using Themify Ultra as our theme. We have (for years) been using the Themify ‘Hook Content’ option to put tracking code onto specific pages – this has worked fine. Unfortunately, for some reason Wordfence seems to be disallowing that and has actively deleted that line of code on every website (!) which means the tracking doesn’t work any more.
This is the line of code <script src=”//s.ksrndkehqnwntyxlhgto.com/XXXXX.js”></script> (XXXXX is a five digit number) that gets removed. It does not bring up any sort of popup to allow us to confirm that this is a safe link when adding it to the Hook Content area. Turning the Firewall back into Learning mode makes no difference – it is still removed.
If I use a plugin (WP Code Lite), I can add the line of code to the whole site : it brings up the WF message allowing me to confirm this is a safe link and that saves and works OK, it is not removed. But unfortunately we need to add different code (with different numbers) to different pages. Is there any way of manually specifying that URL as safe either in the site backend or can you do it in your backend? I suspect this will affect quite a few people as WhatConverts is widely used.
Thanks very much
Hi @jonahall59, thank-you for the extra information.
As WP Code Lite added the code site-wide without being blocked for you, I also tried the WhatConverts plugin which doesn’t result in a block either. I appreciate those don’t change the code per-page as you want, but wanted to ensure WhatConverts’ scripts and the
ksrndkehqnwntyxlhgto.comdomain aren’t the things being blocked by Wordfence. We also don’t have Themify or its Hook Content feature in our list of known conflicts.I’m sorry to hear Learning Mode doesn’t seem to solve the attempts to save the code snippets. If Wordfence is the cause of the block, you should be able to see the full reasoning in your Live Traffic page immediately afterwards. Wordfence logs all blocks it makes here and you can filter by “Blocked” if you like, too.
You may find a specific firewall rule or Wordfence setting stated as the reason. The block reason itself is shown in red text. Feel free to paste that reason here so we can look at why it’s not being added to the allowlist.
Thanks again,
Peter.A bit of an update.
We used WP Code lite (as above) to add the code to the sites. It popped up a notice and we accepted it as being safe. That worked – three days later and the code (<script src=”//s.ksrndkehqnwntyxlhgto.com/XXXXX.js”></script>) has been deleted from the WP Code area! Thus causing the sites to fail again. This time I enabled Learning Mode on the Firewall and readded the same code. It did not pop up with the WF message about it not being safe this time. That seems to infer that the address has been whitelisted. If I tried to add the same code to the Themify Hook Content (in Learning Mode or not) it just deletes it very quickly. So if it has been whitelisted then it doesn’t work in the Hook Content block? Is that possible?
The problem is that the code (despite being apparently whitelisted) disappeared after three (or maybe 4) days. So now we are a bit stuck. We cannot check all of the numerous sites we look after every few days and then re-add the code again, not knowing how long it will ‘stick’. We are a bit desperate – the WhatConverts tracking is pretty central to what we do. So any ideas would be welcome.
Hi @jonahall59, thanks for the update.
I am starting to suspect that another product on your server may be flagging the code snippet as unsafe and auto-removing it. CDNs, other server firewalls/antivirus, or products like ModSecurity could be contenders. The reason I say that is because once allowlisted by Wordfence, it’d either re-check if you wanted to allowlist it when saving the Hook Content block again, or be flagged as part of a scan – but not removed silently.
I am open to Wordfence being the cause if you’re able to see any activity in Live Traffic around the time you believe it was removed and can paste the block reason or firewall rule that was involved. We can certainly work towards a solution if that’s the case.
Thanks again,
Peter.I am starting to think you are right – I have the sever support looking at it this very moment.
Thank you for the patient help and advice. If the solution is server-related, I will post it here so that anyone else having the problem will know what to look for!
Thank-you. I don’t like suggesting other products, but the behavior seems different to what I’d expect. You may be able to find the answer sooner if your system administrator or hosting support know something on your server considers WhatConverts to be an issue.
Peter.
You must be logged in to reply to this topic.