Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

No indication of vulnerable state when frequency == only on change #28

Open
ssnepenthe opened this issue Jul 20, 2017 · 0 comments
Open

Comments

@ssnepenthe
Copy link
Owner

ssnepenthe commented Jul 20, 2017

When notification frequency is set to only send after scans where status has changed - you will get a single notification and then there is no further indication that your site is vulnerable.

It would be very easy to forget to update and then never receive another notification.

One option would be to drop this setting completely - it was only implemented for the email host header injection vuln which hasn't been patched for a while.

Another (probably better) option would be to have some sort of visual indication in wp-admin. This might go hand-in-hand with implementing DB notifications or could just be a flag in the settings table.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant