[wp-trac] Re: [WordPress Trac] #6871: Plugins without headers don't show in the plugins page, keeping some exploits hidden

WordPress Trac wp-trac at lists.automattic.com
Tue Jul 15 22:46:04 GMT 2008


#6871: Plugins without headers don't show in the plugins page, keeping some
exploits hidden
-----------------------------------------------------+----------------------
 Reporter:  guillep2k                                |        Owner:  guillep2k
     Type:  defect                                   |       Status:  assigned 
 Priority:  high                                     |    Milestone:  2.6.1    
Component:  Security                                 |      Version:  2.6      
 Severity:  critical                                 |   Resolution:           
 Keywords:  exploit security has-patch dev-feedback  |  
-----------------------------------------------------+----------------------
Comment (by santosj):

 Keep in mind that validation should be in the plugins page. If you add
 this to the wp-settings.php then you could increase the load and decrease
 the performance. The reason why it is done on the plugins administration
 page is because it will only affect that page.

 You really don't need to do this every time. If the user will visit the
 plugins page every once in a while, then that should be good enough.

-- 
Ticket URL: <http://trac.wordpress.org/ticket/6871#comment:17>
WordPress Trac <http://trac.wordpress.org/>
WordPress blogging software


More information about the wp-trac mailing list