False Positives on Site Health page with Debian servers
-
Ever since the Site Health feature was added to core, all my sites have displayed a warning: “critical issue: There are 23 curl vulnearabilities.” I contacted my previous host as the instructions advise, and was told that the warning is an error, so I’ve been ignoring it ever since.
I have just moved to a new VPS that I am certain has had all available updates applied – the critical error warning is still there!
According to Gemini, this is because the site health function does not really find vunerabilities – it just checks the curl version numbers to see if they are current. Apparently the WordPress devs didn’t understand (or care) that on Debian servers security updates are backported to stable versions of curl without changing the version number.
I hope I am not stumbling into some ancient religious war here, but this is not a good situation.
It makes WordPress look bad to anyone who discovers that every brand new install has “critical errors”.
It makes anyone using WordPress professionally look bad because they can’t hand over a new site with the site health green circle.
But worse, it trains users that the appropriate response to “critical errors” is to ignore them.Is there a way to disable this faulty test? Or can the error message be suppressed?
You must be logged in to reply to this topic.