New here

Tekno

Member
Apr 27, 2020
49
11
8
Hey, I'm a new member here, seems a good forum.

I'm curious about 1 question, I like the resources section in this forum, and I would like to know if those resources are really safe to use ?

thank you
 

MrSam_1

Well-known member
Administrative
Trusted Seller
Dec 1, 2018
23,755
27,099
120
Hello and welcome.
About your question: almost all resources are safe to use. Here are plenty of members tech savvy and they find anything unusual with shared resources. Tho, and this is a personal advice, you should run your own tests and checks on resources before placing them on production servers.
 

birdarabic

Member
May 28, 2019
79
23
8
Hello and welcome.
About your question: almost all resources are safe to use. Here are plenty of members tech savvy and they find anything unusual with shared resources. Tho, and this is a personal advice, you should run your own tests and checks on resources before placing them on production servers.

what are the best ways to test the plugins for non-techies, I do tests with virus total but is it enough?
 

MrSam_1

Well-known member
Administrative
Trusted Seller
Dec 1, 2018
23,755
27,099
120
what are the best ways to test the plugins for non-techies, I do tests with virus total but is it enough?
Virus total is a good idea, but there are snippets that might bypass virus verification like outsite requests disguised as api calls or downloaders disguised as important parts of plugin/theme/app. One workaround for everyone, from rookie to expert programmers, is to keep yourself informed and updated with latest programming exploits and, by extension, with any exploit that concern your programming language (for most resources would be php and javascript) and check everything you use against these exploits/malicious codes.

Edit: example of one malicious code i found in a plugin: it was doing api calls to developer website to check for updates but in between these api calls was implemented a call to an ip that didn't belong to developer with "/api/update?n=<sitename>&p=<siteip>&k=<random md5 hash>" and a GET request and install from same ip for couple malicious files that have been installed in wordpress core.

Edit2: Another option for wordpress users is to use a security plugin that scans files for rootkits/shells/malware/backdoors but don't bloat your website with too many cause it will slow it down or they'll block each other. A firewall with strict access rules to core folders and requests would also come in handy.
 
Last edited by a moderator:

Wildzhen

New member
Mar 7, 2019
29
4
3
Virus total is definitely the way I'd say never had any issues while using it but nothing is 100% secure in our world lol. Back then I used TAC but I don't think it is up to date so not good (sorry) I have not used in a while to be honest.
 

ELLIO7

Well-known member
Trusted Uploader
Banned User
Nov 27, 2019
2,202
2,775
113
125
Mars
Hi @Tekno , Welcome to BABIATO! I hope you get the most useful stuff on the internet through this forum.

- Read the Rules and try not to leech without contributing if possible.

About your question,
: Yes, they are 99.99% of the time safe to use.
 
  • Like
Reactions: Tekno

Forum statistics

Threads
69,308
Messages
908,839
Members
237,915
Latest member
Korsanbeycom

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu