Okay
  Public Ticket #3676471
WordFence is reporting Malware in Amelia
Closed

Comments

  • Markus Größing started the conversation

    Wordfence is reporting this critical security issues:

    • Filename: /opt/eit/experta/wp-content/plugins/ameliabooking/src/Infrastructure/WP/ShortcodeService/AmeliaShortcodeService.php
    • File Type: Not a core, theme, or plugin file from wordpress.org.
    • Bad URL: http://polyfill.io/v2/polyfill.js
    • Details: This file contains a URL that is currently listed on Wordfence's domain blocklist. The URL is: http://polyfill.io/v2/polyfill.js


    • Filename: /opt/eit/experta/wp-content/plugins/ameliabooking/src/Infrastructure/WP/WPMenu/SubmenuPageHandler.php
    • File Type: Not a core, theme, or plugin file from wordpress.org.
    • Bad URL: http://polyfill.io/v2/polyfill.js
    • Details: This file contains a URL that is currently listed on Wordfence's domain blocklist. The URL is: http://polyfill.io/v2/polyfill.js

    Please fix it asap.

    Greetings

    Markus Größing

  •  1,501
    Uroš replied

    Hello Markus,

    Thank you for reaching out to us.

    We checked with our developers and there is nothing wrong with Amelia despite WordFence showing warnings.

    That line of code is turned on if the "Enable usage for older IE browsers" setting is turned on... That setting has been turned off by default for about 2 years, so it must be turned on manually in order for this allegedly problematic JS to appear on the page. Our developers will work on removing it completely in one of the next updates. We will completely remove the call to that JS polyfill script and that warning should no longer appear.

    If you have Enable usage for older IE browsers turned on in settings activations, just turn it off and make sure to purge the cache, and this should not appear anymore. In the event that it continues to appear as you mentioned, there is nothing wrong with Amelia that would harm your site or similar, and in one of the next updates, very possibly in the next one, we hope that our developers will remove that string and this warning should no longer appear. appears

    I wanted to bring to your attention that when the settings are turned off, JavaScript (JS) will not be invoked on the page. However, Wordfence will still detect the presence of a supposedly Amelia issue with code, likely based on identifying that specific string. Therefore, even if you have disabled this option, you may still be able to identify the issue.  Rest assured, we plan to address this with an upcoming update scheduled for following week, tentatively on Tuesday, where we will ensure that JS is not called to the page. Thank you for your attention to this matter. Best regards.

    Kind Regards, 

    Uros Jovanovic
    [email protected]

    Rate my support

    wpDataTables: FAQ | Facebook | Twitter | InstagramFront-end and back-end demo | Docs

    Amelia: FAQ | Facebook | Twitter | InstagramAmelia demo sites | Docs | Discord Community

    You can try wpDataTables add-ons before purchasing on these sandbox sites:

    Powerful Filters | Gravity Forms Integration for wpDataTables | Formidable Forms Integration for wpDataTables | Master-Detail Tables