• Resolved Shadician

    (@shadician)


    Hi,

    The security plugin WP Fingerprint keeps flagging Pretty Links as being hacked. I imagine it’s a false positive, but it makes me nervous about using the plugin and no doubt others would uninstall it when they see this.

    It’s very rare the WP Fingerprint has a problem with any plugin, in the past when it has it’s been a serious issue.

    This is what WP Fingerprint says about false positives and why they can occur:

    “There is a small chance that the result is a false positive. A false positive means that there’s a mistake in the scanning and notification. This means that while the checksums don’t match, there’s a valid reason for the mismatch:

    – You have made direct changes to the plugin files.
    – A plugin author has changed the content of the file, but hasn’t changed the version number. This might show as being the latest version locally, but in
    reality a newer version is available.
    – If checking against a local wpfingerprint.json file (so source says local) – and you have made changes to file, but not regenerated the local file.
    – The plugin is missing version information, meaning its impossible to identify what version should be checked. This will flag all files as potentially malicious. ”

    (source: https://wpfingerprint.com/dealing-with-hacked-wordpress-plugins/ )

    Can this be looked into?

    Thank you

  • The topic ‘PrettyLinks flagged as hacked’ is closed to new replies.