Forum Replies Created

Viewing 15 replies - 1 through 15 (of 273 total)
  • Hi @nosilver4u,

    unfortunately we have the same fatal error still in version 2.9.2 under certain circumstances:

    [20-Jul-2026 11:38:19 UTC] PHP Fatal error: Uncaught Error: Undefined constant “IMSANITY_DEFAULT_PNG_TO_JPG” in /wp-content/plugins/imsanity/imsanity.php:212
    Stack trace:
    0 /wp-includes/class-wp-hook.php(343): imsanity_handle_upload(Array)
    1 /wp-includes/plugin.php(205): WP_Hook->apply_filters(Array, Array)
    2 /wp-admin/includes/file.php(1068): apply_filters(‘wp_handle_uploa…’, Array, ‘sideload’)
    3 /wp-admin/includes/file.php(1130): _wp_handle_upload(Array, Array, ‘2026-07-20 13:3…’, ‘wp_handle_sidel…’)
    4 /wp-admin/includes/media.php(478): wp_handle_sideload(Array, Array, ‘2026-07-20 13:3…’)
    5 /wp-includes/class-wp-customize-manager.php(1400): media_handle_sideload(Array, 0, NULL, Array)
    6 /wp-includes/class-wp-hook.php(341): WP_Customize_Manager->import_theme_starter_content(Array)
    7 /wp-includes/class-wp-hook.php(365): WP_Hook->apply_filters(NULL, Array)
    8 /wp-includes/plugin.php(522): WP_Hook->do_action(Array)
    9 /wp-settings.php(749): do_action(‘after_setup_the…’)
    10 /wp-config.php(106): require_once(‘/www/htdocs/…’)
    11 /wp-load.php(50): require_once(‘/www/htdocs/…’)
    12 /wp-admin/admin.php(35): require_once(‘/www/htdocs/…’)
    13 /wp-admin/customize.php(13): require_once(‘/www/htdocs/…’)
    14 {main}
    thrown in /wp-content/plugins/imsanity/imsanity.php on line 212

    We downgraded to 2.9.1 – the error was there, too. Then we downgraded to 2.9.0 – the error was gone.

    Since we are an agency with 270 installations of your plugin it might be that we have a rare edge case here or something like that which isn’t covered with your fix in 2.9.2. We only see the problem in two of our installations so far.

    Every time we try to enter the customizer of the Astra theme in a fresh installation for example with the link https://www.domain.tld/wp-admin/customize.php?autofocus%5Bcontrol%5D=site_icon we get the fatal error above.

    But: We managed to “patch” the problem in your imsanity.php file in line 419. If we add “imsanity_init();” before your line “add_action( ‘init’, ‘imsanity_init’ );” then the problem is gone.

    It appears that your plugin currently assumes init has always run before wp_handle_upload, which is not the case during some Astra customizer loading procedures in some of our webs. To be precise: It happens only as long as we have a new/clean Astra installation. As soon as we imported some demo content into Astra, the problem ist gone.

    Because most of your users have ready set up installations of Astra this problem might not have emerged so far.

    Could you fix this problem?

    As always thank you for your work,
    -doffine

    Thread Starter doffine

    (@doffine)

    yes, that’s exactly the popup I’m referring to – the marker popup that opens when clicking on a map marker.

    I’ve attached a screenshot showing the element that WAVE flags as a contrast issue:
    https://i.postimg.cc/nVq6zKT1/ultimate-maps-contrast-issue.png

    You can find and reproduce it on: https://www.doffine.de/kontakt/

    Thread Starter doffine

    (@doffine)

    Hello @usamaazad99,

    thanks for coming back to us. We just rolled out the new stable update. But now we see, that the version updated to 3.6.0.1 – not 3.6.1 as you write it above and as it is shown here on wordpress.org as newest version number.

    In terms of rollback or not-rollback:
    For about 3 weeks our many customers had to suffer from the bug that led to so many spam getting through. Manually updating several hundrets of installations to a) a beta version that b) isn’t capable of auto updates is not a good choice.
    So if you need time to make a stable release (we understand that), an update simply reverting the changes that led to the bug would have been best. The reason for the heavy spam was not the old static honey pot field. That did work well until the update. It was a bug in the new version.
    So it is nice to have a dynamic honey pot field now. I see that this is more sophisticated than the old static one. But in the meantime the working old static approach without the bug would have been better – via a reverting update.
    Or to say it in one simple sentence: When an update causes massive problems and it will last several weeks to fix it, go back to the old working code until the new is ready.

    Thank you again for your work,
    -doffine

    Edit: I have to row back – the new version got updated to 3.6.1. In the backend plugins page “3.6.0.1” was shown, also when page was reloaded and updates were re-fetched. But after the update really took place, it was 3.6.1. Thanks again.

    • This reply was modified 1 month, 1 week ago by doffine. Reason: version finally was 3.6.1
    Thread Starter doffine

    (@doffine)

    Hello @usamaazad99,

    we surely don’t want to be impolite or thankless for your work and this free plugin. But we really can underline every single statement @shahmanish877 from above. We couldn’t have written it better than him. But first of all we want to praise that you do at least answer to this problem so quickly at all. There are other manufacturers that don’t even do this. So thanks for that.

    Meanwhile we have rebuilt the whole contact form system of more than a dozen (and counting) websites as Fluent Forms Pro with Turnstile because of uncertainty concerns.

    If you need so much time so verify this crucial system a not-updateable, just manually installable beta version is no solution overall.

    Why don’t you simply release a new version via this repository having your old anti spam technique? Everryone could easily “downgrade” this way and when you are ready with your tests everyone could easily upgrade. Agencies as ours have to do everything in maybe hundrets of websites. So this would be by far the most effective way. Since I’ve seen it often in plugin or theme changelogs that authors release a new version that does a rollback in certain things until the real solution is there, we really ask ourselves why you don’t do this after such a long time. This could buy you the time you need to fix the problem reliably.

    Greetings,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hey @usamaazad99,

    thank you for your detailed answer. So we’ll just wait for you letting us know we when can update our Betas back to the new repository version then.

    Have a nice weekend and thank you for your good work,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hi @usamaazad99,

    over the weekend we had your beta running. Honeypot and minimum-time-to-send feature both seem to work. Both did filter out spam messages. Nevertheless we got a single spam message, obviously by a bot that 1) doesn’t fill in the honeypot, that 2) didn’t send the form too fast and that 3) was able to answer our quiz question that we set up as a third security measure. We now changed the quiz question from an easy calculation task (1+5?) to a little more sophisticated question and will see what comes out.

    We have some more question:

    1. Will the beta version we installed be auto updated like regular versions, as soon as a new version will be available here in the wordpress.org repository?
    2. What did you change in the beta? Is it plausible that your changes did fix malfunctioning honeyport or time-measure functions?
    3. Are you still trying to improve something relevant for this topic at the moment for a second beta – and if yes, what is it?
    4. What else could we do to bot-protect our forms better than just using honeypot/time measure/quiz quesiton and without using external services like ReCaptcha, Turnstile & Co.?

    Thank you very much for your great work and support,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hi @usamaazad99 ,

    thank you for your feedback! We are currently testing the update and need the weekend to verify that everything works as expected. We will get back to you after the weekend with an update.

    In the meantime, we would like to provide some additional information and a screenshot that may help you troubleshoot the issue. We submitted the screenshot via your support form at https://objectsws.atlassian.net/servicedesk/customer/portals and included a link to this support thread in the request.

    Thread Starter doffine

    (@doffine)

    Hi @wfmargaret,

    ok thank you very much for letting us know. If such a more granular possibility of the settings is nothing you would implement in the UI, perhaps you can think about adding some filters that interested users could integrate into the functions.php file. You wouldn’t have to change your UI for everyone, but we could switch on and off notifications more granular then. We guess it cannot be too hard to implement such filters for single events to switch mail notifications on or off. But of course switches in the normal settings would be more comfortable.

    Thanks again,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hey @wfmargaret,

    thank you for coming back to us so quickly. When I look on the alerts list you provided above, I see…

    • under medium “An abandoned plugin is installed” and
    • under critical “A plugin removed from the wordpress.org repository is installed”.

    What is the exact difference between both of them? Is an “abandoned” plugin a plugin that still is to be found in the wordpress.org repository but didn’t receive any update for a specific amount of time?

    I can do without the rest of the “medium” alerts, but if there was an abandoned plugin (that didn’t get updates for long) I indeed would want to get notified about that.

    So it stays: As far as I could read, older versions of Wordfence had the possibility to switch off just those “update is available” mails. Now we would have to switch off way more. Every agency should have a working update process to keep all installations in view and up to date – and so do we. We don’t need another plugin telling us things via mail we already know. But we would not want to do without a Wordfence mail telling us that plugin XY hasn’t received any updates for 3 years or so.

    Greetings and thank you again,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hi @wpssupport,

    ok, we’ll do so. Please let us know how/where to do this. Keep in mind that we are using the free version of the plugin if that matters.

    Thank you a lot,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hello @wpssupport,

    it’s us again. We discussed this problem in our team and still see a problem. The following is the problem:

    1. We have a website that uses relative links as hyperlinks.
    2. We export that page with your plugin to a PDF and save it to disc. Then we open it with Acrobat Reader.
    3. All relative links – let’s say /impressum/ – are shown as file://impressum/ in a current Acrobat reader and thus don’t work.

    We would expect that relative links in a website should be auto-converted to absolute links https://www.domain.tld/impressum/ when they are put in a standalone PDF file that doesn’t know anything about the domain of origin.

    The way it is now, every relative link in a PDF file generated by your plugin has broken links. Can you again help us with this?

    Many greetings and thanks for your work,
    -doffine

    Thread Starter doffine

    (@doffine)

    Thank you for this tip! I looked at this again and found out that it was the official Adobe Acrobat Extension in my browser that handles relative links incorrectly. If I deactivate the extension, the relative links are handled as absolute links!

    Thanks again for clarifying!

    Thread Starter doffine

    (@doffine)

    Hi @jarnovos,

    please allow us a further question:
    When you publish the update, will it also fix all .htaccess files that are broken at this moment? Or do we have to manually re-save all permalinks after your update to make sure everything is ok in every of our 250+ websites?

    Greetings,
    -doffine

    Thread Starter doffine

    (@doffine)

    Hello @jarnovos,

    we just sent you the mail with the information you asked for.

    As said our agency maintains 250+ WordPress installations all having your plugin. Even after 9.5.0.1 we continuously have websites down (all subpages but not the front page) because of the missing WordPress-part in the .htaccess that still erratically gets auto-deleted by your plugin. That is a situation that may not persist. It is a severe problem we think you should urgently fix considering your huge installations base. Your plugin might be responsible for thousands of websites going down. If you cannot fix this asap please consider an update of your plugin reverting your changes that led to this huge problem until you find the issue.

    We are waiting for your reply – of course, thank you for your work!
    -doffine

    Thread Starter doffine

    (@doffine)

    Hi @protibimbok,

    thank you, I just sent you the link.

    Greetings,
    -doffine

Viewing 15 replies - 1 through 15 (of 273 total)