Skip to content
Grav 2.0 is officially stable. Read the announcement →
Plugins

Docs for Diblas "Core" Plugins Require Browser Plugins?

Started by Colin Jaccino 6 years ago · 2 replies · 492 views
6 years ago

A number of plugins provided through the Grav admin plugin link to diblas.net. The documentation is hosted by this domain, which sends the user's browser through a gauntlet of pages requiring the user to add browser plugins. For any security conscious user, these popups, misdirections, and requests for software installation are alarming, raising questions about the legitimacy of the plugin provider. Way outside the norm of most websites.

An example URL: http://diblas.net/plugins/add-extra-markdown-files-to-any-page

Do we know that this provider is safe? Do we value the availability of plugins over the security of users? Is there something that can be done, or should concerned uses simply ignore the diblas plugins?

Thanks

6 years ago

The plugins are, but the domain was not renewed and was probably automatically bought up and used for landing pages, then auto-hosting ads, and subsequently wound up in the ad-loops.

The code for the plugins are on GitHub, and have been used without issue, the problem is that the author hosted demos on a domain which he let go of control over. I submitted an issue to the Core-repository, asking for a protocol to be established to handle these cases.

👍 1
last edited 01/29/20 by Ole Vik

Suggested topics

Topic Participants Replies Views Activity
Plugins · by Rene, 1 week ago
2 80 1 week ago
Plugins · by Xavier, 4 weeks ago
2 84 4 weeks ago
Plugins · by Luka Prinčič, 7 years ago
3 1210 1 month ago
Plugins · by Sebastian van de Meer, 1 month ago
1 77 1 month ago
Plugins · by PIERROT Alain, 2 months ago
3 104 2 months ago