• Resolved magicpowers

    (@magicpowers)


    Hi

    In the past week, my Wordfence Security has alerted me to the fact that three files in your plugin have been modified since the last update – which normally should not happen and potentially indicates hacking.

    I marked those files as fixed, and now got a second warning about yet another three files (or the same?) that have been modified.

    It said further:

    If you see a lot of changed files in a plugin that have been made by the author, then try uninstalling and reinstalling the plugin to force an upgrade. Doing this is a workaround for plugin authors who don’t manage their code correctly.

    Have you pushed those file changes and if so, why didn’t you do that via an official update?

    Please advise. Thanks.

Viewing 10 replies - 1 through 10 (of 10 total)
  • Plugin Author Heateor Support

    (@heateor)

    Hi,

    Plugin updates the color in the default CSS files if you customize the logo color from Theme Selection section, every time you update the plugin. If you have kept the “Logo Color” option blank, plugin doesn’t make any changes in the CSS files of the plugin.

    Thread Starter magicpowers

    (@magicpowers)

    Hi

    thanks for your reply.

    Plugin updates the color in the default CSS files if you customize the logo color from Theme Selection section, every time you update the plugin

    Yes, I have the Logo Colour selection blank – however you are referring to file changes during an update.

    Perhaps I wasn’t very clear: The file changes in your plugin on my website has occured OUTSIDE the update.

    of course WordPress knows that files are being modified in an update – that’s the whole point of updates.

    Here is the full text pf the warning:

    This file belongs to plugin “Sassy Social Share” version “3.3.11” and has been modified from the file that is distributed by www.ads-software.com for this version. Please use the link to see how the file has changed. If you have modified this file yourself, you can safely ignore this warning. If you see a lot of changed files in a plugin that have been made by the author, then try uninstalling and reinstalling the plugin to force an upgrade. Doing this is a workaround for plugin authors who don’t manage their code correctly.

    “has been modified from the file that is distributed by www.ads-software.com for this version” is the key issue here.

    I can see the difference between the two files (original and modified) which is just a long string of code I don’t understand.

    If you definitely have not pushed any final changes after the official update – I will have to uninstall the plugin and reinistall from scratch.

    Please advise. Thanks

    Plugin Author Heateor Support

    (@heateor)

    Not sure how the files are being updated without even updating the plugin. If you drop an email at support[at]heateor[dot]com regarding the same, I would be able to look into it.

    Same here, and this is not the first time this has happened, for me.

    Thread Starter magicpowers

    (@magicpowers)

    @jess888

    I have emailed a copy of those changed files to the developer – he can’t tell what has changed and why, blaming my Wordfence Security plugin (!) for those changes.

    Seriously?….

    Plugin Author Heateor Support

    (@heateor)

    @magicpowers
    Even if we push the changes without releasing a new version of the plugin, the file will not update automatically at your website unless you uninstall and reinstall the plugin. I am not blaming WordFence for these changes. Just thought you should check. If WordFence is not causing these changes, some other plugin is. If you are not sure what’s causing these changes, can you send a screenshot of the options you have configured in the Theme Selection section?
    FYI, if you compare the CSS file at your website https://gist.github.com/Heateor/fe1e2e77ae3fd7ac0a936880b7018132 with the original CSS file at the WordPress repository https://plugins.trac.www.ads-software.com/browser/sassy-social-share/trunk/admin/css/sassy-social-share-hover-svg-horizontal.css, you will find the diff-checker tool is matching the initial CSS @charset "utf-8";.heateor_sss_standard_follow_icons_container .heateorSssYummlySvg:hover,.heateor_sss_horizontal_sharing .heateorSssYummlySvg:hover,#heateor_sss_rearrange .heateorSssYummlySvg:hover{background:url('data:image/svg+xml;charset=utf8,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%20width%3D%22100%25%22%20height%3D%22100%25%22%20viewBox%3D%220%200%2030%2030%22%3E%3Cpath%20stroke%3D%22
    After this comes the color code %23fff which is not there in the file at your website. Since the CSS file is a compressed one and whole CSS is just one line for the diff-checker, it’s marking the remaining CSS different from the original.

    Thread Starter magicpowers

    (@magicpowers)

    @heateor

    As I said in my direct email to you, you don’t demonstrate the knowledge of how WordPress works and your suggestions are getting more and more bizarre.

    PLUGINS DO NOT MODIFY THE FILES OF OTHER PLUGINS.

    Now that you admit that Wordfence which is a security plugin, did not change those files after all, you are pointing the finger at my Theme settings.

    Seriously..?

    I will leave it at that and close this post.

    as my final comment – it’s a shame that the plugin DEVELOPER is not providing professional support for their plugin.

    Thread Starter magicpowers

    (@magicpowers)

    @heateor

    I have uninstalled and reinstalled the plugin.

    this should fix it.

    If the file modification alerts continue, I will consider other options.

    thanks

    Thanks, @magicpowers. Sigh….

    Plugin Author Heateor Support

    (@heateor)

    Sorry, this was a bug in the plugin. We have released the version 3.3.12 fixing this. Plugin won’t update the CSS files when you update it, if you don’t customize the logo color.

Viewing 10 replies - 1 through 10 (of 10 total)
  • The topic ‘Modified plugin files ouside of update’ is closed to new replies.