• Congratulations, guys. This is the first site I’ve ever had defaced. Obviously you’re not paying attention to developing with security in mind. Shame on me for using your software. I cannot ever in good conscience use or recommend your work to anyone ever again. I’ll be recommending that WordPress remove you from the plugin repos until you can demonstrate a solid grasp on developing php/wp code securely.

    • This topic was modified 5 years, 12 months ago by tommadrid.
Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Contributor Christine

    (@cdegraff1)

    The Social Warfare plugin was the target of a zero-day exploit on March 21, 2019. We notified all paid customers via email as soon as it was discovered and issued a patch/fix to the WordPress repository within a few hours. Please accept our deepest apologies for any inconvenience this has caused.

    Fortunately, there were few points of entry, and the type of code attackers could execute is limited to simple JavaScript (such as redirects) or simple PHP (to print information). Further, _if_ malicious code made its way into your database from our plugin, then it is _only_ in the wp_options table within our social_warfare_settings field. Therefore, no login credentials, no customer or personal data, no sensitive data – nothing should have been compromised.

    We notified all paid customers via email as soon as it was discovered and issued a patch/fix to the WordPress repository within a few hours.

    As a paid customer, I did not receive any email about this. I check my emails very frequently. If I did receive any notification from you, my visitors wouldn’t have suffered 12 hours of malware before I realized what happened.

    Also, I requested a refund last week and gave you my Paypal email address. I have still not received any response or money.

    Plugin Contributor Christine

    (@cdegraff1)

    If you previously unsubscribed, you would not have received it. Have you received your refund yet?

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Do not use or buy this plugin’ is closed to new replies.