3 ms·
Hi John, Thanks a lot for your detailed response. Really appreciated. Probably both sites were infected at some point. Again, I never saw the malware message
by softmodeling 13y ago
Hi John,
Thanks a lot for your detailed response. Really appreciated.
Probably both sites were infected at some point. Again, I never saw the malware message myself but the guy that alerted us first copied the message he got and it was explicitly mentioning the demo site: “Content from demos.shapingrain.com, a known malware distributor, has been inserted into this web page. Visiting this page now is very likely to infect your Mac with malware.”
And now, we’re going to immediately clean the CSS since this is something that had not occurred to us could be the cause of the problem. Let’s make sure we are not blacklisted again!
- JohnTHaller 13y agoSure thing. I've had some experience with the blacklist detection due to a JS file hosted on a trusted 3rd party site that had another section of their site hacked (meaning their site was blacklisted and anything pulling resources from their site was similarly blacklisted). I researched more about how things worked then and have been sharing when I can since then. I hadn't seen your specific situation before but it is my guess based on an understanding of how similar scanning setups work. For future reference, another useful tool is Sucuri SiteCheck, which will show you the results of multiple website malware blacklists on one page: http://sitecheck.sucuri.net/scanner/ http://sitecheck.sucuri.net/scanner/ (I checked and http://wp-abtesting.com/ http://wp-abtesting.com/ is clean)
- driverdan 13y agoYou shouldn't pull static assets from 3rd party sites like that. Looks like you've fixed it. You should also use W3 TotalCache, WP Minify, or a similar plugin to minify and combine your CSS and JS. You have a lot of files loading which slows the site down.
- JohnTHaller 13y agoThey apparently weren't pulling static assets from a 3rd party site. They were using a theme developed by a 3rd party. That theme is hosted on their own server but has the developer's name and URL listed in the comments of the CSS (which is fairly common practice). No assets were being loaded from an external site, but it looks like that URL in the comments triggered Google's alerts. That said, combining and minimizing CSS and JS would have eliminated the comments and prevented the issue with Google's scanner.