PDA

View Full Version : Show Top Commentators Plugin flaw


SarahG
03-08-2008, 12:25 PM
I read about this last month but have started to suffer from the flaw myself recently. The top commentators plugin by Nate Sanden has a flaw that's easily abused by others as it creates the list by counting the number of comments per name not email address. Anyone can use the same name as someone from the list, give their own URL and tada, they have a nice link from your front page to their site.

So I've modified the plugin to count by email not name, something that cannot be forged easily. It's available for anyone to download and upgrade to at Top Commentators :: Stuff by Sarah (http://www.stuffbysarah.net/blog/wordpress-plugins/top-commentators/)

Jeremy
03-08-2008, 07:30 PM
Ahh, good to know. I haven't encountered a problem of multiple people using the same name, but I guess it would be better to stop it before it becomes an issue. Thanks!

But your link to the zip file is a 404 :(

SarahG
03-08-2008, 09:13 PM
Ahh cheers Jeremy. I put an underscore in the filename instead of an hyphen. Got a major headcold, not thinking very clearly (but the plugin is fine as it's running on my site!).

I've just started to experience this, noticing comments off 3 of my top commentators list and started to catch on to the fact that these names were copied. Plus to be fair, it can happen accidentally with people of the same name.

Dan Schulz
03-09-2008, 03:57 AM
Neat. Too bad I don't use the plugin though.

SarahG
04-30-2008, 11:23 AM
Just an update, I've just found another flaw that needed fixing, despite getting a correct list out, the URL was still being pulled out on the author name. I've updated the plugin for this and again it's available from Top Commentators :: Stuff by Sarah (http://www.stuffbysarah.net/blog/wordpress-plugins/top-commentators/)

Should be the last one that's needed, unless of course there's call for having an admin page for it instead of having to edit the plugin. I know the widget has an admin page, but I'm not a widget person :D

Any problems give me a shout.