litespeedtech / litespeedtech/lscache_wp
incorrect malware detection?
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 257
- Forks
- 123
- PR merge metrics
- No merged PRs in 30d
Description
Somebody has contacted our client saying that their internet provider has shown a malware:
> My internet provider recently blocked https://metalpackager.com/ from access with the following warning.
>
> “This website posed a malware risk. This risk tries to access sensitive info like login or credit card details. We blocked the connection to stop private data from being exposed.”
I don't have any further details, like what software reported this.
I ran it through all the website malware checkers I could find. It passed sucuri, google safe browsing, qualys ssl checks, etc.
But siteguarding.com reported this:
We have the "instant click" option turned on, and im guessing thats what this snippet of code is related to.
Not sure what can be done about this, but I thought I would report it just in case somebody knows a way to mitigate it.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the report with the WordPress plugin’s “instant click” option enabled, then inspect the snippet shown in the SiteGuarding report. The issue does not name a file, test, reporter, or exact malware signature; done would require identifying whether Instant Click causes the warning and documenting a confirmed mitigation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php, wordpress
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100