• Resolved Borderlain Estudio

    (@borderlain)


    Hi,

    I’m currently managing a WordPress site where the “Redirect 404 to Homepage” plugin (version 1.0) is installed.

    Wordfence is reporting the following file as modified:

    wp-content/plugins/404-to-homepage/404-to-homepage.php

    I checked the file manually and there does not appear to be anything suspicious in the code. I also compared it with another copy of the plugin and the code appears to be the same.

    I also found this older support topic where you mentioned that previous iterations of the plugin included minor code changes that did not require a version number change:
    https://wordpress.org/support/topic/please-update-the-version-number-on-updates/

    However, Wordfence still reports the file as modified.

    Interestingly, when I try to use Wordfence’s “Repair” option, it fails with:

    “WordFence API error: Unable to locate the requested file.”

    Could you confirm whether there are different legitimate versions/iterations of this file that were distributed under version 1.0?

    If so, is it possible that Wordfence is comparing the installed file against a different version of the plugin?

    I have encountered this situation on more than one WordPress site that I manage, so I wanted to check with you before treating the Wordfence warning as a security issue.

    Thanks!

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support Sean (pipdig)

    (@seanpipdig)

    Hi @borderlain,

    If you’ve checked the code of the plugin and it definitely isn’t modified, that seems like a bug with WordFence’s scanning system. It might be picking up an older version of the code even though it hasn’t changed much over the past few years.

    I’ll try pushing an update to version 1.1 now to see if that helps. You should see the update available in your websites within the next 24 hours. After updating, I’m assuming the message in WordFence will disappear. If not, I’d recommend contacting their support team or your host so they can check if there is any modified files that need to be checked, or if the bug in WordFence could be fixed at their end.

    Thread Starter Borderlain Estudio

    (@borderlain)

    Hi Sean,

    Thanks for looking into this! I updated the plugin to version 1.1 and ran another Wordfence scan. The false positive is gone and the scan is now clean.

    Really appreciate you taking the time to investigate and push the update.

    Best,
    Cristian

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.