• This is missing a honeypot feature to block out bots as fake “members” so it allows bots to create a user profile, then someone can use that new profile to create fake listings or try to find ways to put malware into the website.

    Even the paid version doesn’t include it, according to PluginWare. I reached out with a support ticket, and they told me it does not have a honeypot feature if you allow the plugin to take care of user Login/Registration. It’s a pretty significant security gap, IMO! Especially for something as expensive as this. You’d have to layer it on with something else to fill the gap.

    • This topic was modified 3 years, 1 month ago by morgancarrie.
Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author pluginsware

    (@pluginsware)

    Hi,

    Thanks for your feedback.

    Actually, we have integrated RECAPTCHA and you can enable it on your registration form and Add Listing form which will stop bots from creating user profiles.

    Also, we are completely sanitizing all our form data before it is uploaded. So there is no way to upload malware through our plugin.
    Kindly look at the “save_listing” function in the file /wp-content/plugins/advanced-classifieds-and-directory-pro/public/class-acadp-public-user.php to see how we sanitize our form data before we upload it.

    Also, we will take note of honeypot integration and will add it to our TO-DO list.

    Thanks

    Thread Starter morgancarrie

    (@morgancarrie)

    That is fantastic!! I see it on the settings page, but it doesn’t have any instuctions on where to get a site key or the secret key.

    Plugin Author pluginsware

    (@pluginsware)

    Dear Customer,

    Please refer https://developers.google.com/recaptcha/intro to get the site key and secret key.

    Thanks

Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘No honeypot, fills up with spam’ is closed to new replies.