Home › Forums › Weaver Xtreme Theme › TimThumb-script in Weaver Xtreme v6.4
- This topic has 9 replies, 4 voices, and was last updated 2 years, 2 months ago by
Meteorfan.
-
AuthorPosts
-
June 28, 2024 at 09:25 UTC - Views: 61 #74751
Meteorfan
ParticipantI use on my website Security Ninja-scanner (V5.196 – https://de.wordpress.org/plugins/security-ninja/). After last update with new features, the warning is displayed that the TimThump-file/script found in Weaver Xtreme V6.4.
The message is “We do not recommend using the TimThumb script for editing images. Apart from the security issues that some versions have had, WordPress has its own inbuilt functions for editing images that should be used instead. Contact the theme developer and ask them to update the theme. It’s unlikely that you’ll be able to fix this issue yourself.”
I found on other sites that the developer has abandoned the script and is no longer patching or updating it and also ” we highly recommend staying away from using TimThumb and instead using the features native to WordPress.”
I am a user and not a developer and now very confused. Is there any advice?
WP 6.5.5/Weaver Xtreme 6.4/Weaver Xtreme Theme Support 6.5.1
June 28, 2024 at 10:08 UTC - Views: 57 #74752June 29, 2024 at 01:20 UTC - Views: 48 #74753Weaver
KeymasterI’ve never heard of TimThumb. I checked all Weaver Xtreme files, theme support, and Plus, and there is no instance I can find of TimThumb. And there is no image resizing feature in any Weaver module.
The Security Ninja-scanner may have found an instance in another plugin?
Does it provide a more exact reference to the usage?
June 29, 2024 at 03:04 UTC - Views: 43 #74754User
ModeratorAfter checking with WP Archives, I found that Wordfence has reported false-positives on this issue in the past.
Given what @Weaver wrote, and the fact that no one else has reported this issue in regards to this Theme, may I humbly suggest that there is nothing here for you to worry about.
Regards!
June 29, 2024 at 17:39 UTC - Views: 36 #74755scrambler
ModeratorCould the site have been hacked and stuff been installed in weaver directory by a third party?
If you do not already have WordFence installed to protect your site, my be you should do so (the free version) and run a scan.
June 30, 2024 at 16:50 UTC - Views: 27 #74756Meteorfan
ParticipantI’m attaching a screenshot of the message, that’s all I have. But it`s german, sorry.
edit: This obviously does not work here with an image file from my hard disk.
I have not found any evidence of a hack of the site in my hoster’s log files. There are also no other unnatural anomalies. The small website has only a few hits. Other users cannot log in.
I will think about installing WordFence and contact the Security Ninja forum.July 1, 2024 at 05:01 UTC - Views: 17 #74757Weaver
KeymasterI’ve done another, completely thorough check of all Weaver Theme files, including Weaver plugins, and I can assure you that Weaver Xtreme does not use, nor never has used TimThumb. There is no legitimate reason that Security Ninja should be generating such a message. It must have some sort of bug in the search patterns it is using to scan theme files. I find such a message misleading, approaching slanderous.
July 1, 2024 at 05:35 UTC - Views: 14 #74758Meteorfan
ParticipantMany thanks to everyone for their help. I am now reassured.
@Weaver
May I use this answer in the Ninja support forum?July 1, 2024 at 05:50 UTC - Views: 14 #74759Weaver
KeymasterIt is not necessary. They’ve had an update recently that I just checked, and the message is no longer there.
I’ve also posted a new version of Weaver Xtreme (6.5.1) which updates the WordPress compatibility to 6.5, and removed the recommendation for the obsolete widget shortcode.
July 1, 2024 at 06:08 UTC - Views: 10 #74760Meteorfan
ParticipantThank you. I have just installed the new Ninja version. Everything is fine here too.
-
AuthorPosts
- You must be logged in to reply to this topic.

