Item logo image for Plugin Vulnerabilities

Plugin Vulnerabilities

5.0(

1 rating

)
Item media 1 (screenshot) for Plugin Vulnerabilities

Overview

Adds warning message to WordPress Plugin Directory pages when plugins are from developer we have released security advisories for.

One of the little understood realities of security issues with WordPress plugins is that the insecurity of them is not evenly spread across those plugins. Instead, many developers are properly securing their plugins and others get them properly secured when alerted they haven’t done that, while other plugin developers either are unable or unwilling to properly secure their plugins. With the latter group, among the issues we have seen, are developers who have introduced new serious vulnerabilities that are substantially similar to vulnerabilities that they know have been exploited in their plugins. In situations where we become aware of developers who have shown that inability or unwillingness to properly secure their plugin, we are releasing advisories to warn customers of our service and the wider WordPress community of the risk of utilizing those developers' plugins. This extension adds a notice on the pages of the WordPress Plugin Directory for the plugins from those developers.

Details

  • Version
    1.0.32
  • Updated
    January 8, 2024
  • Offered by
    White Fir Design
  • Size
    9.98KiB
  • Languages
    English (United States)
  • Developer
    Email
    extensions@whitefirdesign.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Related

CrowdScrape

5.0

Scrape web content for indicators of interest and integrate CrowdStrike Intelligence information

Shodan

4.5

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

d3coder

4.1

Encoding/Decoding Plugin for various types of encoding like base64, rot13 or unix timestamp conversion

PhotOSINT

3.7

OSINT tool for images. Scans page for images with EXIF metadata, while browsing. Also has context menu options for images.

Vulners Web Scanner

4.4

Tiny vulnerability scanner based on vulners.com vulnerability database. Passively scan websites while you surf internet!

Breakbot

3.8

Quickly add disruptive unicode, naughty strings, and more to your clipboard.

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

Pulsedive Threat Intelligence

5.0

Highlight IPs, domains, and URLs on any website to enrich them using Pulsedive's threat intelligence.

Hack-Tools

4.6

The all in one Red team extension for web pentester

HackBar

4.2

A browser extension for Penetration Testing

Sputnik

5.0

OSINT web extension

IP, DNS & Security Tools | HackerTarget.com

4.2

Quick access to IP, DNS & Network Tools. Check DNS, Whois, ASN, Traceroute, Ping and more. Tools for technical operators.

CrowdScrape

5.0

Scrape web content for indicators of interest and integrate CrowdStrike Intelligence information

Shodan

4.5

The Shodan plugin tells you where the website is hosted (country, city), who owns the IP and what other services/ ports are open.

d3coder

4.1

Encoding/Decoding Plugin for various types of encoding like base64, rot13 or unix timestamp conversion

PhotOSINT

3.7

OSINT tool for images. Scans page for images with EXIF metadata, while browsing. Also has context menu options for images.

Vulners Web Scanner

4.4

Tiny vulnerability scanner based on vulners.com vulnerability database. Passively scan websites while you surf internet!

Breakbot

3.8

Quickly add disruptive unicode, naughty strings, and more to your clipboard.

OWASP Penetration Testing Kit

4.8

OWASP Penetration Testing Kit

Pulsedive Threat Intelligence

5.0

Highlight IPs, domains, and URLs on any website to enrich them using Pulsedive's threat intelligence.

Google apps