cxswatch Scanning of our server generates security alerts.

#640484
  • Resolved Anonymous
    Rank Math free

    Hi,

    Cxswatch scan of our server generates these alerts:

    the file
    wp-content/plugins/seo-by-rank-math/includes/admin/class-serp-preview.php
    has
    Universal decode regex match = [universal decoder]

Viewing 3 replies - 1 through 3 (of 3 total)
  • Hello,

    Thank you for your query and we are so sorry about the trouble this must have caused.

    The errors you see are false positives and are not related to any kind of security issue in the plugin. The security software you use is simply looking for words in the code that may indicate security issues. This results in many false positives because there are plenty of safe and legitimate uses of said words in the code.

    I checked the file in question, and I presume it’s the word base64 that triggers the error. This function is sometimes used to obfuscate malicious code, but of course, it has many legitimate uses, for example with its help we can embed image data inside the HTML code, which is what happens in Rank Math.

    ​​​​​​​You can learn more about the security of our plugin here: https://rankmath.com/kb/is-rank-math-safe-to-use/

    Hope that helps and please do not hesitate to let us know if you need our assistance with anything else.

    Anonymous
    Rank Math free

    Hi,

    Thanks for responding. I take it to be false positive.

    Hello,
    
    You’re welcome.

    We are super happy that we have addressed your concern. If you have any other questions in the future, know that we are here to help you.
    
    If you don’t mind me asking, could you please leave us a review (if you haven’t already) on https://wordpress.org/support/plugin/seo-by-rank-math/reviews/#new-post about your overall experience with Rank Math? We appreciate your time and patience.
    
    If you do have another question in the future, please feel free to create a new forum topic, and it will be our pleasure to assist you again.
    
    Thank you.

Viewing 3 replies - 1 through 3 (of 3 total)

The ticket ‘cxswatch Scanning of our server generates security alerts.’ is closed to new replies.