• Hi Gioni,

    Just updated to 7.0 on a couple of websites and decided to give security scanner a try. Please, have a look – https://imgur.com/a/UrESFI3

    The thing goes insane and barks on nearly every file of many plugins. I gather you’re using some kind of database that contains integrity checksums of free plugins or something like that? I assume this because it looks like the scanner is going crazy only on non-free plugins (e.g. Quform, WPJM Field Editor, Yoast Premium, etc).
    If that’s how it works – there’ll be tons of such false positives until you’re able to gather integrity checksums of paid plugins (which I guess is nearly impossible).

Viewing 6 replies - 1 through 6 (of 6 total)
  • Plugin Author gioni

    (@gioni)

    Hi Nazar!

    It’s possible and is already implemented though. 🙂

    The scanner supports commercial plugins and themes. Just click a “Resolve issue” link. You need to do it once for each plugin on a site.

    Next time when you install a theme or a plugin (including any update) the scanner will take a snapshot of all files in the plugin or theme ZIP archive and use it for integrity checking.

    Thread Starter Nazar Hotsa

    (@bugnumber9)

    Hmm, that’s quite a bit of work considering the fact that some websites I manage have 5-8 commercial plugins and all have paid or custom-built themes…

    What happens if I install/update plugins and themes manually (via FTP)? That’s how I usually do it with paid plugins and themes. I guess the scanner will bark every time and I’ll have to repeat the resolve step manually in those cases, right?

    On a separate note, do you have any idea if https://mainwp.com/extension/favorites/ will help? I’m sometimes using it to install and update plugins and themes, including paid ones. I guess I’ll have to test 🙂

    Plugin Author gioni

    (@gioni)

    Yes, using FTP for updating themes and plugins is the case when no reliable and convenient solution is possible. But in any other case when a standard WordPress update API is being used, the Cerber snapshots algorithm will work fine because it relies on it. Anyway, you need to test it out. Let me know how it goes.

    Nat

    (@brindecocagne)

    Hi there,

    I uptaded your great plugin to 7.0 yesterday. After the analize, the scanner is barking, as well as Nazar showed in the screenshot (only for non free plugins or themes).

    Sorry but I don’t understand what I have to do after I clicked on “Resolve issue” link….

    Plugin Author gioni

    (@gioni)

    Hi Nath! You need to upload a ZIP archive from which you’ve installed a particular plugin or a particular theme. Alternatively you can just install a newer version of the plugin or the theme.

    @brindecocagne

    Nat

    (@brindecocagne)

    Hi Gioni,

    Thanks for your reply! I was not sure it was the good way, I’ll try to do it as soon as I’ll got some time. 🙂

Viewing 6 replies - 1 through 6 (of 6 total)

The topic ‘Security scanner going insane’ is closed to new replies.