Forum Replies Created

Viewing 15 replies - 61 through 75 (of 127 total)
  • Hi @otto42

    And it’s appreciated. But you have to understand that not everyone has the Wordfence security plugin (I do, and recommend in the course, to my students and even configuration of email alerts).

    But if now that you just closed 4 post, you put a post posted on the top… sure you save more post replies.

    Because the questions that I ask myself and more people are…
    1º. What will happen to this plugin? And the author? I mean… will not there be more new versions?
    2º. Alternatives to this plugin? I only see this as the most similar:
    Math Captcha‘ (By dFactory) although it has not been updated for 1 year… it works in WP 4.9.1

    Greetings from Spain & Goodnight! 🙂
    Pd.: I did read the article until the end, and that’s why I put it in all the other post, so that people would not have any doubt with the source where it is said.

    • This reply was modified 8 years, 8 months ago by Joan Morci. Reason: I did read the article until the end

    Sorry @otto42 for repeating answer quoting that part of the source that nobody talked about it (the final part).

    To maintain order, the best would have been to put a post posted at the top, warning of this complicity on the part of those responsible for the WordPress repository, and Wordfence. And this multitude of messages would have been avoided.

    I’ve been on forums since 2002 and it’s a regular thing (important to put post at the top), but I do not know why you did not have the idea to do it here. No mood to bother.

    I have a course in Udemy (16h) and I recommend my students to take plugins and themes from the WordPress repository because in theory it has security controls.

    Greetings!

    From Wordfence…

    What We’ve Done So Far

    As of this writing, we’ve created three firewall rules in total to protect our users’ sites from the backdoor installation. Premium customers received the first two rules on December 8th and the third one on the 14th. These rules also protect against the backdoor itself executing in Captcha as well as in the five other plugins available for download on simplywordpress.net. Free users will receive these rules 30 days from the original publish date via the community version of the Threat Defense Feed.

    We have also been working with the WordPress.org plugins team to get out a patched version of Captcha (4.4.5) that is backdoor-free. The plugins team has used the automatic update to upgrade all backdoored versions (4.3.6 – 4.4.4) up to the new 4.4.5 version. Over the course of the weekend over 100,000 sites running versions 4.3.6 – 4.4.4 were upgraded to 4.4.5. They have also blocked the author from publishing updates to the plugin without their review.

    Our Recommendations

    We recommend that you uninstall the Captcha plugin immediately from your site. Based on the public data we’ve gathered, this developer does not have user safety in mind and is very likely a criminal actor attempting yet another supply chain attack. You should also ensure that you’ve enabled automatic updates within WordPress – that’s still one of the best ways to keep your site secure before disclosures like this take place. We also recommend using the Premium version of Wordfence, to proactively defend your site against threats like this one.

    The most viable alternative seems: ‘Really Simple CAPTCHA‘ (By Takayuki Miyoshi, creator of ‘Contact Form 7’ and compatible with it)

    Greetings!

    From Wordfence…

    What We’ve Done So Far

    As of this writing, we’ve created three firewall rules in total to protect our users’ sites from the backdoor installation. Premium customers received the first two rules on December 8th and the third one on the 14th. These rules also protect against the backdoor itself executing in Captcha as well as in the five other plugins available for download on simplywordpress.net. Free users will receive these rules 30 days from the original publish date via the community version of the Threat Defense Feed.

    We have also been working with the WordPress.org plugins team to get out a patched version of Captcha (4.4.5) that is backdoor-free. The plugins team has used the automatic update to upgrade all backdoored versions (4.3.6 – 4.4.4) up to the new 4.4.5 version. Over the course of the weekend over 100,000 sites running versions 4.3.6 – 4.4.4 were upgraded to 4.4.5. They have also blocked the author from publishing updates to the plugin without their review.

    Our Recommendations

    We recommend that you uninstall the Captcha plugin immediately from your site. Based on the public data we’ve gathered, this developer does not have user safety in mind and is very likely a criminal actor attempting yet another supply chain attack. You should also ensure that you’ve enabled automatic updates within WordPress – that’s still one of the best ways to keep your site secure before disclosures like this take place. We also recommend using the Premium version of Wordfence, to proactively defend your site against threats like this one.

    The most viable alternative seems: ‘Really Simple CAPTCHA‘ (By Takayuki Miyoshi, creator of ‘Contact Form 7’ and compatible with it)

    Greetings!

    From Wordfence…

    What We’ve Done So Far

    As of this writing, we’ve created three firewall rules in total to protect our users’ sites from the backdoor installation. Premium customers received the first two rules on December 8th and the third one on the 14th. These rules also protect against the backdoor itself executing in Captcha as well as in the five other plugins available for download on simplywordpress.net. Free users will receive these rules 30 days from the original publish date via the community version of the Threat Defense Feed.

    We have also been working with the WordPress.org plugins team to get out a patched version of Captcha (4.4.5) that is backdoor-free. The plugins team has used the automatic update to upgrade all backdoored versions (4.3.6 – 4.4.4) up to the new 4.4.5 version. Over the course of the weekend over 100,000 sites running versions 4.3.6 – 4.4.4 were upgraded to 4.4.5. They have also blocked the author from publishing updates to the plugin without their review.

    Our Recommendations

    We recommend that you uninstall the Captcha plugin immediately from your site. Based on the public data we’ve gathered, this developer does not have user safety in mind and is very likely a criminal actor attempting yet another supply chain attack. You should also ensure that you’ve enabled automatic updates within WordPress – that’s still one of the best ways to keep your site secure before disclosures like this take place. We also recommend using the Premium version of Wordfence, to proactively defend your site against threats like this one.

    The most viable alternative seems: ‘Really Simple CAPTCHA‘ (By Takayuki Miyoshi, creator of ‘Contact Form 7’ and compatible with it)

    Greetings!

    Forum: Plugins
    In reply to: [Captcha] Backdoor?

    With Adam’s permission I will complete the info with link to the original source

    From Wordfence…

    What We’ve Done So Far

    As of this writing, we’ve created three firewall rules in total to protect our users’ sites from the backdoor installation. Premium customers received the first two rules on December 8th and the third one on the 14th. These rules also protect against the backdoor itself executing in Captcha as well as in the five other plugins available for download on simplywordpress.net. Free users will receive these rules 30 days from the original publish date via the community version of the Threat Defense Feed.

    We have also been working with the WordPress.org plugins team to get out a patched version of Captcha (4.4.5) that is backdoor-free. The plugins team has used the automatic update to upgrade all backdoored versions (4.3.6 – 4.4.4) up to the new 4.4.5 version. Over the course of the weekend over 100,000 sites running versions 4.3.6 – 4.4.4 were upgraded to 4.4.5. They have also blocked the author from publishing updates to the plugin without their review.

    Our Recommendations

    We recommend that you uninstall the Captcha plugin immediately from your site. Based on the public data we’ve gathered, this developer does not have user safety in mind and is very likely a criminal actor attempting yet another supply chain attack. You should also ensure that you’ve enabled automatic updates within WordPress – that’s still one of the best ways to keep your site secure before disclosures like this take place. We also recommend using the Premium version of Wordfence, to proactively defend your site against threats like this one.

    The most viable alternative seems: ‘Really Simple CAPTCHA‘ (By Takayuki Miyoshi, creator of ‘Contact Form 7’ and compatible with it)

    Greetings!

    Thread Starter Joan Morci

    (@joanmor)

    Hi @epicurum!

    This is not a problem with the plugin, but the author of your predesigned theme.

    Recently I saw an update for my predesigned theme, Primer (GoDaddy), and thanks to another plugin (WP Theme Changelogs) I was able to check what changes had been made (something you can´t do natively from WordPress).

    Among the changes of the new version, 1.8.1, were these:

    • Fix: Prevent customizer title & tagline colors from updating when they are hidden. -evanherman
    • Fix: Update translation files so translate load correctly. -evanherman
    • Fix: Remove HTML markup in search results / author archive page titles. -evanherman

    If you look at the last change (fix), it refers to what I asked in this same post

    This means that you must contact the author of the predesigned theme and tell him to solve this same action.

    Greetings from Spain! 🙂

    • This reply was modified 8 years, 8 months ago by Joan Morci. Reason: fix list
    • This reply was modified 8 years, 8 months ago by Joan Morci.
    Thread Starter Joan Morci

    (@joanmor)

    Hello Vinod,

    Sorry for not answering sooner.

    So if I use this code to change the color… would I have a problem?:

    svg.search-icon path {
    fill: #fff;
    }

    I have used this code for the moment because with the code you are commenting, it still does not change color. I suppose that in the future if I had another svg image, it could come into conflict.

    At the moment I have the website with a coming soon plugin, since I indicated to the author of it that the text was not totally responsive.

    So when that person updates the plugin to solve that (said soon), I will show the new website open again, to resolve other details of other plugin authors, including yours in this regard.

    Greetings Vinod! 🙂

    Hi @wpshopmart

    I’m sorry to say that the partner is right.

    I would have already given a 5 star note, because the plugin really deserves it. It is beautiful and very useful. I am using it on a website, but I have observed as an ugly detail that the text is not responsive. Do not you use FitText?

    I show you capture to prove it. Here you will see that ‘Headline’ by default it is possible to change size in ‘px’. But I changed it to ’em'(Custom CSS) because it fits a bit better, not totally.

    It is a defect for long words. Also words separated by slashes but attached to it.

    And also link to my website, where I change the values of the ‘Headline’.

    Custom CSS (Headline)

    .color {
        font-size: 0.8em;
    }

    It also has the error of the white strip when downloading scroll on mobile. It’s a minor problem, but it really messes up the great work done in the plugin, maxime when it also claims to be responsive.

    However, for the great work done and everything it offers I did a video tutorial in Spanish.

    Will you solve this matter?

    • This reply was modified 8 years, 8 months ago by Joan Morci. Reason: Detail the problem of the white strip when scrolling down in mobile version, and link to the tutorial in Spanish video of the plugin
    Thread Starter Joan Morci

    (@joanmor)

    Hello @epicurum,

    The truth is that when I asked was out of curiosity. But those headings of title, own of the theme, do not contribute any value neither to the user nor to the SEO.

    I have a course for Udemy, to learn how to design a website (from your Personal Brand). So I choose to eliminate those theme title header, by CSS. And put title header with page builder SiteOrigin (although you can do it with the one you use), and in this way it was a better choice, it fixed the problem that the author of this plugin did not correct here… and with the new title header, gave value to each page.

    You can see that info, in the minute that I link you to my promotional video on YouTube.

    Greetings! 🙂

    Thread Starter Joan Morci

    (@joanmor)

    Hi Vinod!

    About the box (in my case, now, of light blue color) that appears on the right side, which when clicking brings me to the compilation of all articles and pages.

    Online website where you can see that behavior.

    To see here (new link): https://imgur.com/a/xReky

    Is there no way to eliminate it? Or is that a function wanted by author plugin?

    Greetings!
    Pd.: Sorry for taking so long to upload online to check error.

    Thread Starter Joan Morci

    (@joanmor)

    Hello Vinod!

    I want to tell you that I am about to launch the last part of my first course at Udemy (I hope to update course before Black Friday, on the 16th) … and I found the code you gave up to stop working for the color of the magnifying glass. Then I looked around and saw that it worked with this code:

    svg.search-icon path {
    fill: #fff;
    }

    It’s curious because the previous code worked on localhost, but no longer when I uploaded the web to a remote server. By the way, yes, I already have the web online, this is, if you want to check something.

    • This reply was modified 8 years, 9 months ago by Joan Morci. Reason: If... no, Yes
    Thread Starter Joan Morci

    (@joanmor)

    Hi Andrew!

    Ok no problem. It’s been proven a while ago and I found it curious.

    Normally I always advise only to layout the pages (because they are smaller than post). The only solution is ‘revert to editor’ on each page.

    And I want to share another curiosity to know about it, ‘revert to editor’ returns you to the native WordPress editor and when we go back to the ‘Page Builder’ tab (without saving) the layout disappears. Ok, I knew this about Page Builder by SiteOrigin. But … for example the page builder Unyson (framework that does not have its own theme but works with third-party theme), I do the same process as in SiteOrigin, and it recovers the layout again. It is a thing that you can observe when you want, although without demand it is unnecessary to improve, I suppose.

    Greetings! 🙂

    • This reply was modified 8 years, 9 months ago by Joan Morci. Reason: OK no, Ok yes :)
    Thread Starter Joan Morci

    (@joanmor)

    Fixed in the video of the course Udemy 🙂

    Thread Starter Joan Morci

    (@joanmor)

    Seeing that it is a feature that no longer exists due to the “great Apple”, I end this post, because although it was not the expected solution, at least, I remove the doubt to continue working.

Viewing 15 replies - 61 through 75 (of 127 total)