Sending POST with existing WP user name, in json encoded ‘body’, and get this {“code”:”rest_missing_callback_param”,”message”:”Missing parameter(s): user”,”data”:{“status”:400,”params”:[“user”]}}
In authentication header sent user_name:password base64 encoded
What is wrong, please?
]]>Hi there,
This plugin hasn’t been updated or changed for 5 months and is now flagging as “Not compatible with your version of WordPress”. Are you planning on updating it to remove this message or check if their is any new vulnerabilities since WordPress and PHP have updated in that time?
Unfortunately I am forced to to use this plugin through my host and argued that its a security vulnerability due to it not being well established.
I have tried to remove this but they use an api to re-instate it. What are your policies if this is installed on thousands of users website without their consent and support is stopped/removed in any way?
I have not been able to get anywhere with asking them how they support my site if your plugin is hacked in anyway or allows a gateway into the site(s). How secure is it?
Please do update your plugin details to stress that you have no responsibility if a third part company is using your plugin without the customers consent and have no responsibility if the plugin is deemed a security risk in the distant future.
It now forces me to find a way to prevent your plugin from being installed without my knowledge. Security is king and this just makes things worse.
]]>Hi, one time login cannot be deleted, I delete it on my website and then a week later it is back as a plugin. I was wondering why it installs itself again.
Regards John Birch
]]>A really nice feature I’ve run into lately on a number of security-conscious sites is the ability to request a one-time login be sent to your email address. This can be particularly useful when you need access to a site from a less than secure location (coffee shop or other public wifi with questionable security).
The one-time login request is typically integrated into the login page, and of course would only work for existing users.
Any chance this could be incorporated, in your copious spare time?
Thanks!
]]>