{"id":3380,"date":"2017-04-14T16:51:16","date_gmt":"2017-04-14T22:51:16","guid":{"rendered":"https:\/\/www.whitefirdesign.com\/blog\/?p=3380"},"modified":"2017-04-14T16:51:16","modified_gmt":"2017-04-14T22:51:16","slug":"the-obviousness-of-unnatural-reviews-for-a-wordpress-security-plugin","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2017\/04\/14\/the-obviousness-of-unnatural-reviews-for-a-wordpress-security-plugin\/","title":{"rendered":"The Obviousness of Unnatural Reviews for a WordPress Security Plugin"},"content":{"rendered":"<p>An important element of security is trust, seeing as most people are not going to have ability to independently verify what a security product or service is doing what it is claimed to do and instead have rely on the those behind it to be truthful. What we have seen in\u00a0our experience with the industry is that they don&#8217;t even really attempt to be honest with the public, instead correctly seeing that they can get away with misleading and outright lying\u00a0because the checks that should exist against that are not working.\u00a0The end result of this is current poor state of security.<\/p>\n<p>Over at the blog for our Plugin Vulnerabilities service today <a href=\"https:\/\/www.pluginvulnerabilities.com\/2017\/04\/14\/plugin-using-wpscan-vulnerability-database-data-doesnt-warn-when-using-unfixed-vulnerable-plugins\/\">we looked at a security plugin that fails to actually do its most important function<\/a>. We also noted that most of the reviews for the plugin look like they came from people\u00a0that were connected to the plugin, which provided a distorted view of the plugin.<\/p>\n<p>That plugin certainly isn&#8217;t alone among WordPress security plugins having many reviews that don&#8217;t look to have come naturally. Another plugin we came across within the last few days pretty obviously has unnatural reviews. The plugin\u00a0<a href=\"https:\/\/wordpress.org\/plugins\/wp-security-optimizer\/\">WP Security Optimizer<\/a> has 4\u00a0reviews despite having less than 10 active installs:<\/p>\n<p><a href=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/04\/wp-security-optimizer-active-installs-and-reviews.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-3381\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/04\/wp-security-optimizer-active-installs-and-reviews.png\" alt=\"\" width=\"300\" height=\"540\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/04\/wp-security-optimizer-active-installs-and-reviews.png 300w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2017\/04\/wp-security-optimizer-active-installs-and-reviews-167x300.png 167w\" sizes=\"auto, (max-width: 300px) 85vw, 300px\" \/><\/a><\/p>\n<p>That is well beyond even an extremely high number of reviews for the amount of active installs. By comparison our plugins have the following mix of reviews to installs:<\/p>\n<ul>\n<li>Automatic Plugin Updates: 9 reviews \/ 10,0000+ active installs<\/li>\n<li>Plugin Vulnerabilities: 14 reviews \/ 5,000+ active installs<\/li>\n<li>No Longer in Directory 10 reviews \/ 1,000 active installs<\/li>\n<\/ul>\n<p>Not only are the reviews out of line with the number active installs, but three of the four accounts used for the reviews were created on the same day as the review and have not been used for anything else (the fourth was created several days before the review).<\/p>\n<p>Also like many other plugins it is promoted in a way that is likely far from reasonable, considering that the description of the plugin begins:<\/p>\n<blockquote><p>Prevent hackers to sabotage your rankings in search engines.<\/p><\/blockquote>\n<p>While we haven&#8217;t tested the plugin against real vulnerabilities yet, it looks like it is mainly focused on trying to hide the fact that a website contains vulnerable software instead of doing anything\u00a0that could resolve the website being vulnerable. Considering many times hackers don&#8217;t do any checks before trying to exploit a vulnerabilities, it wouldn&#8217;t do much to prevent hackers from succeeding.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>An important element of security is trust, seeing as most people are not going to have ability to independently verify what a security product or service is doing what it is claimed to do and instead have rely on the those behind it to be truthful. What we have seen in\u00a0our experience with the industry &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2017\/04\/14\/the-obviousness-of-unnatural-reviews-for-a-wordpress-security-plugin\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The Obviousness of Unnatural Reviews for a WordPress Security Plugin&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,32],"tags":[115],"class_list":["post-3380","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-wordpress-plugins","tag-wp-security-optimizer"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3380","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=3380"}],"version-history":[{"count":2,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3380\/revisions"}],"predecessor-version":[{"id":3383,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/3380\/revisions\/3383"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=3380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=3380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=3380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}