Main page shows naked PHP
-
With the Gauntlet Security plugin 1.1.1, when I first visit /wp-admin/admin.php?page=gauntlet-security, I see some bare PHP:
Files
message): ?> class=’toggle has_icon_lg’> message): ?> Make sure your server is not vulnerable to the Shellshock Bash bug message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Set correct file and directory permissions message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Turn off directory indexing message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Prevent code execution in the uploads directory message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Block files in the includes directory message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Rename or move the content directory message): ?>PHP
message): ?> class=’toggle has_icon_lg’> message): ?> Disable dangerous PHP functions message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Disable allow_url_include and allow_url_fopen PHP flags message): ?>Database
message): ?> class=’toggle has_icon_lg’> message): ?> Use a strong database password message): ?>
message): ?> class=’toggle has_icon_lg’> message): ?> Change the default database table prefix message): ?>… and so forth.
When I click “Scan Now”, these are replaced with the correctly-styled text (red, yellow, or green).
- The topic ‘Main page shows naked PHP’ is closed to new replies.