• Today our clients started reporting seeing new WP Admin Panel messages in their dashboard asking them to visit other websites (wpbeginner) to read articles on that site. We spent hours looking for malware code. Guess what? We found it was just Monster Insights!

    WTH!?! Do you think my private WordPress admin area is your own private billboard to spam links to your website?!?! I don’t know your website; I didn’t give you permission to advertise to me or my clients.

    Disgusting practice. WILL NEVER use or recommend this plugin again. The irony is that link it pointed to an article about GDPR and respecting personal privacy.

Viewing 6 replies - 1 through 6 (of 6 total)
  • Plugin Author chriscct7

    (@chriscct7)

    Hi there,
    We included a single admin notice with a link to an article we wrote on GDPR and compliance for analytics as it’s an important and timely thing for our users and we’ve been fielding a lot of questions about how GDPR affects our plugin and WordPress in general. It’s also permenantly dismissable like any standard WordPress notice with the standard x to close on the upper right.

    -Chris

    Thread Starter bluep92877

    (@bluep92877)

    Doesn’t matter what your justification is. Random messages popping up without authorization to the 182 clients in our network is absolutely unacceptable. Our developer spent hours with the security team analyzing code, even the Monster Insights code to make sure there wasn’t a breach even in your files. That has a real world price tag associated with it.

    I don’t see anywhere in the settings where I can enable or disable these messages globally, or opt in so I can expect messages from time to time from MI. The way you handled it how could it not be considered a security breach?

    This was an epic fail on the part of MI. We’ll be choosing another solution for our clients.

    Plugin Author chriscct7

    (@chriscct7)

    It’s not a security breach because nothing was breached. Admin notices are a built in part of WordPress Core designed to allow plugin, theme and WordPress core to communicate important notices and warnings, for example major legal changes, update routine required notices, required configuration changes or issues, and so forth.

    An example of a really common usecase is to allow for upgrade routines that require batch processing to start, because that has to be initiated by a user on the site, and something we’ve used it for in the past since there are sometimes upgrade routines that for performance reasons cannot and/or should not be performed automatically.

    It’s a built in system of WordPress, much like Notifications API in Windows, the Notification center in Ubuntu, or the notifications system on any major smartphone operating system.

    When any plugin on www.remarpro.com is designed it is done for the average install use case, and we can’t predict every possible use case. I know we have a block of time set aside later in the third quarter to look at making MonsterInsights’s notifications into a standalone submenus page similar to how the upgrades system WordPress has works, though in the meantime we have to do the best we can to protect our average user whose site can be impacted by the implications of GDPR when fines and penalties start to go into effect less than 24 hours from now.

    Our first priority will always be to protect our users and look out for their best interest and guide them as best we can. I understand you might not be happy with how we had to release that guidance, but we did so with the best of intentions to help guide as many of our users as best we could to relevant, easy to understand guidance in an effective manner, and at the end of the day, if you’re not happy with how that was done I both understand your decision, and also want to point out this is something we are always working to make better, starting with our Notifications center later this year.

    • This reply was modified 6 years, 10 months ago by chriscct7.

    I do have the same problem too. my website was link into Windows 7 Ultimate Download SITE! and Im so sick about it because it affects my website performance on Google Search…!

    @bluep92877 please send me a help on this.

    Plugin Author chriscct7

    (@chriscct7)

    If it’s a link on the frontend it’s not from us. That sounds like a Chrome or other browser extension/add-on.

    -Chris

    Nope, It’s not a link from frontend it’s from backend, and it seems like it was injected on the backend of my website and I don’t know where to locate it.

Viewing 6 replies - 1 through 6 (of 6 total)
  • The topic ‘Spams Admin Dashboard’ is closed to new replies.