Here:
</div><div class="inside">
<div class="health-check-title-section site-health-progress-wrapper loading hide-if-no-js">
<div class="site-health-progress">
<svg role="img" aria-hidden="true" focusable="false" width="100%" height="100%" viewBox="0 0 200 200" version="1.1" xmlns="https://www.w3.org/2000/svg">
Any reason why that is happening?
Thanks.
]]>but I found this in the code – which links directly to the theme as the culprit:
<script type=”text/javascript” src=”https://lendorphoglacour.com/wp-includes/js/wp-embed.min.js?ver=5.4.2″></script>
not https and there are several of those.
so it seems my potential readers are denied access because of this.
]]>Every transaction was fraudulent, donations in the mount of $1.24, $1.20, 2.70, 2.43 etc. Obviously the hacker had stolen credit multiple credit cards and was randomly targeting wordpress sites with this plugin.
Didn’t think about it because we had a give $1 $2 campaign going on at the time, encouraging donors every little bit helped.
The day Stripe started contacting us, threatening to close the account, and the disputes rising, and fraudulent flagged transactions, I reached out to support, only to get the blame game on Stripe Api keys.
The only way they can read those secret keys is through a security hole in the plugin, and to confirm, I did not change the Api Keys I changed the plugin, I tried 5 other plugins, all stopped these fraudulent transactions, and I decided to go with another plugin. Since then no more fraudulent transactions.
Now the problem is every transaction, is being disputed and the banks are charging $15.xx fees to each transaction, I have hundreds of them, if only 200 of them are disputed and won, I will lose $3000.00 and go bankrupt
The author is not taking any responsibility. I have alerted Stripe of the problem, so they can remove this plugin from their recommendation. Also reporting to wordpress. Please do not even try this plugin. If anyone wants proof, I can send you screenshots of everything.
]]>We have SSL certificate and our site is set to HTTPS that is why we don’t get why the message showing up. Please help us and please also check if the button is working on Desktop using Firefox. Thank you
Rodel Hufana
]]>