Title: Walf's Replies | WordPress.org

---

# Walf

  [  ](https://wordpress.org/support/users/wallfur/)

 *   [Profile](https://wordpress.org/support/users/wallfur/)
 *   [Topics Started](https://wordpress.org/support/users/wallfur/topics/)
 *   [Replies Created](https://wordpress.org/support/users/wallfur/replies/)
 *   [Reviews Written](https://wordpress.org/support/users/wallfur/reviews/)
 *   [Topics Replied To](https://wordpress.org/support/users/wallfur/replied-to/)
 *   [Engagements](https://wordpress.org/support/users/wallfur/engagements/)
 *   [Favorites](https://wordpress.org/support/users/wallfur/favorites/)

 Search replies:

## Forum Replies Created

Viewing 12 replies - 1 through 12 (of 12 total)

 *   Forum: [Reviews](https://wordpress.org/support/forum/reviews/)
    In reply to:
   [[ReCaptcha v2 for Contact Form 7] Contact Form 7 no longer supports reCAPTCHA V2](https://wordpress.org/support/topic/contact-form-7-no-longer-supports-recaptcha-v2/)
 *  [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/contact-form-7-no-longer-supports-recaptcha-v2/#post-16750522)
 * You don’t need any extra plugin if you want V3, the latter just works (once you’ve
   entered a correct key+secret pair). The whole point of a V2 plugin is to disable
   CF7’s built-in V3 support, so a V2 checkbox can be shown.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Elementor Website Builder - more than just a page builder] Have first item of Toggle open by default](https://wordpress.org/support/topic/have-first-item-of-toggle-open-by-default/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 4 months ago](https://wordpress.org/support/topic/have-first-item-of-toggle-open-by-default/#post-16717222)
 * And another canned response. Failed to notice this was labelled as **not a support
   question**, did we?
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Elementor Website Builder - more than just a page builder] Have first item of Toggle open by default](https://wordpress.org/support/topic/have-first-item-of-toggle-open-by-default/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 5 months ago](https://wordpress.org/support/topic/have-first-item-of-toggle-open-by-default/#post-16705762)
 * I find such canned responses insulting. The linked thread explains very clearly
   what the issue is, in which your team already stated that it’s expected behaviour
   for the widget.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Gmail SMTP] Please amend “from address” info and test send data](https://wordpress.org/support/topic/please-amned-from-address-info-and-test-send-data/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 6 months ago](https://wordpress.org/support/topic/please-amned-from-address-info-and-test-send-data/#post-16620135)
 * Better, but you’re still using `sanitize_text_field` instead of `sanitize_textarea_field`
   for the message body. It was more that when installing and testing your plugin,
   my first impression was that it broke breaking user input, which probably doesn’t
   instil trust for your average user.
 * Super prompt response, thanks.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Meta pixel for WordPress] Daily php errors on WP plugin](https://wordpress.org/support/topic/daily-php-errors-on-wp-plugin/)
 *  [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 7 months ago](https://wordpress.org/support/topic/daily-php-errors-on-wp-plugin/#post-16464053)
 * Seeing the same. Fix your stuff, [@facebook](https://wordpress.org/support/users/facebook/).
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Manager - WP Adminer] Limit access to some table/DB](https://wordpress.org/support/topic/limit-access-to-some-table-db/)
 *  [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 10 months ago](https://wordpress.org/support/topic/limit-access-to-some-table-db/#post-16179285)
 * [@maipiusenza](https://wordpress.org/support/users/maipiusenza/) I’m still of
   the opinion that a separate user is better, because then MySQL automatically 
   limits what is available to the user (and thus in Adminer) without any program
   code to change the behaviour of Adminer or a plugin. As long as you’re aware 
   of that, then do whatever works for you.
 * [@pexlechris](https://wordpress.org/support/users/pexlechris/) That’s just another
   band-aid. Raw SQL is also allowed in the Select, Insert and Update pages. Whilst
   your advice may work in this particular instance, they are the only person reading
   this, so it’s best not to spread false information about basic database access
   control.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Manager - WP Adminer] Limit access to some table/DB](https://wordpress.org/support/topic/limit-access-to-some-table-db/)
 *  [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [3 years, 11 months ago](https://wordpress.org/support/topic/limit-access-to-some-table-db/#post-16112695)
 * [@maipiusenza](https://wordpress.org/support/users/maipiusenza/) The only way
   to limit user access to specific tables and databases is with MySQL’s/MariaDB’s
   own permission system. Trying to block Adminer URLs containing table names is
   no substitute because there are many ways to read and modify data within Adminer,
   the most obvious being the _SQL command_ page. You might need a stand-alone copy
   of Adminer to do what you want, but this could invite brute-force attacks so 
   use **very** strong passwords.
 * [@pexlechris](https://wordpress.org/support/users/pexlechris/) I don’t know why
   you’re telling your users it’s possible.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Access with Adminer] Could not read credentials](https://wordpress.org/support/topic/could-not-read-credentials/)
 *  [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [4 years, 1 month ago](https://wordpress.org/support/topic/could-not-read-credentials/#post-15961875)
 * New version is better.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Manager - WP Adminer] Reveals database username and password](https://wordpress.org/support/topic/reveals-database-username-and-password/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [4 years, 1 month ago](https://wordpress.org/support/topic/reveals-database-username-and-password/#post-15900053)
 * Well done on plugging the security hole, but I’ll stick with the other one. Yours
   loads Adminer inside WordPress, which I think is asking for trouble given they
   are stand-alone applications, not written to share a global namespace or environment
   with anything else.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Manager - WP Adminer] Reveals database username and password](https://wordpress.org/support/topic/reveals-database-username-and-password/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [4 years, 2 months ago](https://wordpress.org/support/topic/reveals-database-username-and-password/#post-15865621)
 * I don’t have time to help you fix your plugin.
 * I like Adminer, generally, and the previous plugin I used (ARI Adminer) got closed
   for security issues. I figured I should check how yours works before putting 
   another compromised plugin on clients’ sites. Yours works but I’m not comfortable
   with _how_. I’m using [the other Adminer plugin](https://wordpress.org/plugins/db-access-adminer/)
   because it does security right as far as I can tell.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Manager - WP Adminer] Reveals database username and password](https://wordpress.org/support/topic/reveals-database-username-and-password/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [4 years, 2 months ago](https://wordpress.org/support/topic/reveals-database-username-and-password/#post-15862026)
 * [@pexlechris](https://wordpress.org/support/users/pexlechris/) If you’re not 
   going to address the issue, that’s up to you, but don’t mark the topic as resolved
   when your response is equivalent to “I don’t care that my plugin transmits the
   database credentials back and forth in plain text.” Allow your users to make 
   an informed decision.
 *   Forum: [Plugins](https://wordpress.org/support/forum/plugins-and-hacks/)
    In
   reply to: [[Database Manager - WP Adminer] Reveals database username and password](https://wordpress.org/support/topic/reveals-database-username-and-password/)
 *  Thread Starter [Walf](https://wordpress.org/support/users/wallfur/)
 * (@wallfur)
 * [4 years, 2 months ago](https://wordpress.org/support/topic/reveals-database-username-and-password/#post-15840649)
 * Just pick one of the permissions from [https://wordpress.org/support/article/roles-and-capabilities/#capability-vs-role-table](https://wordpress.org/support/article/roles-and-capabilities/#capability-vs-role-table)
   that only super-admins or single site admins have, e.g. `update_core`.
 * That still doesn’t change the fact that you’re echoing the raw db credentials
   out in the HTML. You’ve created a target for XSS by doing do. All an exploit 
   has to do is fetch that page and send it somewhere else.

Viewing 12 replies - 1 through 12 (of 12 total)