Home › Forums › Weaver Xtreme Theme › malicious code?
- This topic has 9 replies, 3 voices, and was last updated 1 year, 2 months ago by
Yvonne.
-
AuthorPosts
-
July 8, 2025 at 09:42 UTC - Views: 60 #75781
Yvonne
ParticipantMy malicious code scanning system has detected such code in your plugin. Please give me your opinion
July 8, 2025 at 10:26 UTC - Views: 56 #75782User
ModeratorHi Yvonne,
Neither that url or the domain are accessible so we can’t comment on that.
Regarding the Weaver plugin, for our information, please kindly let us know which version you have installed.
At the moment, I can confirm that no one else has reported any issues with Weaver plugins, so I don’t believe there are issues.
For you peace of mind on this issue, may I humbly suggest that you turn off your malicious code scanning system and download another one for testing purposes. As you are aware, “False Positives” are not unknown in such testing.
Please do let us know how you get on.
Regards and thanks!
July 8, 2025 at 10:30 UTC - Views: 52 #75783Yvonne
Participantthe page is available.
and I’ve been using your plugin for years, so I haven’t had any bad experiences.
I installed a security system including malicious code scanning and it just detected itJuly 8, 2025 at 10:43 UTC - Views: 48 #75784User
ModeratorHi Yvonne,
That url and domain are not available to me directly, or via VPN, or testable on pingdom.com, and Google Lighthouse say:
Core Web Vitals Assessment: <span class="bXhnD">Failed</span>So we cannot access it.
For our information, what was the
malicious code scanningplugin you installed?Regards.
July 8, 2025 at 10:53 UTC - Views: 47 #75785Yvonne
ParticipantDefender PRO from WPMU DEV
July 8, 2025 at 13:58 UTC - Views: 43 #75786User
ModeratorHi Yvonne,
I installed Defender (Not-Pro) on my test site and it revealed nothing.
Please kindly let us have a text copy or a screen capture of what Defender is objecting to , and what changes it wishes to make to code, if any.
In the meantime, perhaps someone else has some suggestions.
Regards!
July 9, 2025 at 17:00 UTC - Views: 37 #75788Weaver
KeymasterI understand the warning. It comes from the Weaver Xtreme Plus plugin. That is not part of the standard WP plugin library.
It is an advanced feature that allows advanced users to add PHP code directly to their pages, and is supported after discussions with advanced Weaver users. Using the [php] shortcode requires that it be explicitly be enabled by the user. It can’t be used by a user without that enabling, and the code will not be accessible by any other theme or plugin. So unless you’ve enabled the [php] shortcode in the Weaver Xtreme Plus plugin, you don’t have anything to worry about.
If you are concerned, it is also possible to completely disable the “eval” PHP function in your hosting PHP control panel. Search the web for how to do that. If your security scanner is really well done, it would check to see if eval is disabled before issuing the warning message.
July 10, 2025 at 13:26 UTC - Views: 25 #75789Yvonne
Participantno, not enabled.
July 10, 2025 at 15:16 UTC - Views: 19 #75790User
ModeratorAt last I can get access to the site and images…..
I confess I know nothing about this and your comment seems totally reasonable and logical.
However, in image https://pogon24.info/screen/001.png I now see on Line 187 a reference to
PHP_VERSION 5.0.0On seeing that, I was wondering if there any chance that this reference to an outdated PHP is in part contributing to this false-positive warnings?
Just a thought….
Hi Yvonne,
The error notice says reasonably: “…. please reach out to our support.”
Given Weaver’s explanation and this looking like a false-positive warning, have you contacted WPMU DEV with Weaver’s reply and advice, and asked them to investigate further, and if so, what was their response?
Regards!
July 11, 2025 at 07:07 UTC - Views: 11 #75791Yvonne
Participant -
AuthorPosts
- You must be logged in to reply to this topic.

