That is a pretty serious claim to make without any supporting evidence. We took a look over the plugin and we did not see anything in the plugin that looks like it could allow that to happen. If you have some evidence to support the claim then you should provide that to the Plugin Directory so that they can work to resolve the issue.
Moderator
Jan Dembowski
(@jdembowski)
Forum Moderator and Brute Squad
@runtman How did you come to the conclusion that your site was compromised due to this plugin? It’s a very important question I am asking.
Using a new installation of wordpress with only this plugin and it had URL injections all over the place. I will try to pull out the logs for you.
Moderator
Jan Dembowski
(@jdembowski)
Forum Moderator and Brute Squad