[Defender Pro] Scan for “WP Code” plugin & alert throughout all of the Dashboard

1

The subject says it all.

Maybe offer an additional toggle in Defender Pro > Recommendations settings to disallow the plugin’s installation?

###

I’ve had several of my clients’ websites compromised within the past year or so. The WP Code plugin is simply too powerful for the WP Repo, IMHO.

The attacker:
– uses a compromised u/n & pass
– installs the WP Code plugin
– adds code that hides any evidence of the plugin’s installation
– does their damage

I’m not certain what damage they’re actually doing though, and I’m still unsure on that. The site will start having weird oddities, but still runs as expected.

Something “deep” has to be happening in the background, as there’s too much involved to not be doing something that sneaky.

  • Patrick Freitas
    • FLS

    Hi splaquet

    I hope you are doing well.

    The WP Code plugin is simply too powerful for the WP Repo, IMHO.

    I always felt is not a good practice to save the code in the database as those snippet plugins do, but you have a good point about the injected JS / Malware, I see we could include a recommendation about it.

    We forwarded this request to the Defender team.

    Best Regards
    Patrick Freitas