- Posts: 22
- Thank you received: 0
Please post all pre-sales questions of all products on this forum
Is my version secure?
- koldhands
- Topic Author
- Offline
- Junior Member
-
Less
More
10 years 2 months ago #59016
by koldhands
Is my version secure? was created by koldhands
Hi all,
I have PF running on an old site form a couple of years ago (J3.3.6 with PF 3.0) and as it was hacked last week, I'm wondering if the version of PF I have is secure?
I ran a few checks and one of the files (/components/com_pmform/helper/fields.php) flags as possibly malicious!
Any ideas if this is ok or should I think about upgrading? I don't any more functionality and the PF works great, just a bit concerned about security!
Thanks,
Sean.
p.s. specifically this line is suspect:
// Line: 1363
eval($script) ;
I have PF running on an old site form a couple of years ago (J3.3.6 with PF 3.0) and as it was hacked last week, I'm wondering if the version of PF I have is secure?
I ran a few checks and one of the files (/components/com_pmform/helper/fields.php) flags as possibly malicious!
Any ideas if this is ok or should I think about upgrading? I don't any more functionality and the PF works great, just a bit concerned about security!
Thanks,
Sean.
p.s. specifically this line is suspect:
// Line: 1363
eval($script) ;
Please Log in or Create an account to join the conversation.
- Tuan Pham Ngoc
- Away
- Administrator
-
10 years 2 months ago #59017
by Tuan Pham Ngoc
Replied by Tuan Pham Ngoc on topic Is my version secure?
Hi
No security issue found for Payment Form in few years (from the date it was born), so it is a secure extension, you can still use it on your site
For that line of code, it is normal. eval function sometime is disabled on some hosting provider for some reasons. However, in that script :
1. It is only used if your form has custom fee calculation script
2. Even if you have custom fee calculation script, that's your own script, so it is secure
So in conclusion, you can keep using that version. Upgrade is better but it is not required
Tuan
No security issue found for Payment Form in few years (from the date it was born), so it is a secure extension, you can still use it on your site
For that line of code, it is normal. eval function sometime is disabled on some hosting provider for some reasons. However, in that script :
1. It is only used if your form has custom fee calculation script
2. Even if you have custom fee calculation script, that's your own script, so it is secure
So in conclusion, you can keep using that version. Upgrade is better but it is not required
Tuan
The following user(s) said Thank You: koldhands
Please Log in or Create an account to join the conversation.
- koldhands
- Topic Author
- Offline
- Junior Member
-
Less
More
- Posts: 22
- Thank you received: 0
10 years 2 months ago #59019
by koldhands
Replied by koldhands on topic Is my version secure?
As usual, a concise and quick response!
Many thanks Tuan and keep up the good work!
Sean.
Many thanks Tuan and keep up the good work!
Sean.
Please Log in or Create an account to join the conversation.
Moderators: Tuan Pham Ngoc, Giang Dinh Truong, Mr. Dam
Support
Documentation
Information
Copyright © 2025 Joomla Extensions by Joomdonation. All Rights Reserved.
joomdonation.com is not affiliated with or endorsed by the Joomla! Project or Open Source Matters.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.
The Joomla! name and logo is used under a limited license granted by Open Source Matters the trademark holder in the United States and other countries.