Review Severe Security Vulnerabilities
-
I’m a long time user of Rank Math and am trying to install it on a major news site. Our developers are on-board with the value of the plugin vs. Yoast, but they have serious concerns about a number of security issues that have come up in their linting process and they are advising against deployment. Here are just a few of the severe issues that came up in linting:
WordPress.Security.EscapeOutput.OutputNotEscaped WordPress.Security.NonceVerification.Recommended WordPress.Security.ValidatedSanitizedInput.InputNotValidated WordPress.Security.SafeRedirect.wp_redirect_wp_redirect WordPress.Security.ValidatedSanitizedInput.InputNotSanitized WordPress.Security.ValidatedSanitizedInput.InputNotValidated WordPress.DB.DirectDatabaseQuery.NoCaching WordPress.DB.DirectDatabaseQuery.DirectQuery WordPress.DB.PreparedSQL.InterpolatedNotPrepared WordPress.DB.DirectDatabaseQuery.SchemaChange WordPress.DB.SlowDBQuery.slow_db_query_tax_query WordPress.DB.SlowDBQuery.slow_db_query_meta_query WordPressVIPMinimum.Functions.RestrictedFunctions.url_to_postid_url_to_postid WordPressVIPMinimum.Functions.CheckReturnValue.DirectFunctionCall WordPressVIPMinimum.Functions.RestrictedFunctions.get_posts_get_posts WordPressVIPMinimum.Functions.RestrictedFunctions.wp_remote_get_wp_remote_get WordPressVIPMinimum.Functions.RestrictedFunctions.switch_to_blog_switch_to_blog WordPressVIPMinimum.Functions.RestrictedFunctions.wp_mail_wp_mail WordPressVIPMinimum.Security.ProperEscapingFunction.htmlAttrNotByEscHTML WordPressVIPMinimum.Security.ProperEscapingFunction.notAttrEscAttr WordPressVIPMinimum.Performance.WPQueryParams.PostNotIn_exclude WordPressVIPMinimum.Performance.RemoteRequestTimeout.timeout_timeout WordPress.PHP.PregQuoteDelimiter.Missing WordPress.WP.GlobalVariablesOverride.Prohibited WordPress.WP.DiscouragedFunctions.wp_reset_query_wp_reset_query VariableAnalysis.CodeAnalysis.VariableAnalysis.UndefinedVariable
This is a well-respected, major developer of WordPress sites and I am not prepared to push them to ‘do it anyway’ with assurances that you are ‘audited every three months’. Are there any plans in the work to address some of these vulnerabilities?
Thank you!
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘Review Severe Security Vulnerabilities’ is closed to new replies.