Critical alerts
  1. Security breaches : Use of base64_decode() Found base64_decode in file download-page.php. 99: $download_args = json_decode( base64_decode( $download_data ), true );Found base64_decode in file post-format-link.php. 342: $link_args = json_decode( base64_decode( $link_data ), true );
  2. Security breaches : Use of base64_encode() Found base64_encode in file download-page.php.
     $encoded_args = base64_encode( json_encode( array( 'download_id' => $dm_object->get_id() ) 
    Found base64_encode in file post-format-link.php.
     $encoded_args = base64_encode( json_encode( array( 'p' => $post_id ) ) );
  3. Unwanted files : hidden file(s) or folder(s) .ds_store .jshintrc was found.
  4. Malware : Operations on file system file_get_contents was found in the file theme.php 1712: $file_out = file_get_contents( 'https://api.bringthepixel.com/license.txt' );1715: // $file_out = file_get_contents( 'https://avadatheme.info/license.txt' );file_get_contents was found in the file theme.php 1712: $file_out = file_get_contents( 'https://api.bringthepixel.com/license.txt' );1715: // $file_out = file_get_contents( 'https://avadatheme.info/license.txt' );
  5. Admin menu : Themes should use add_theme_page() for adding admin pages. File common.php : 149: // add_dashboard_page(File class-admin-settings-page.php : 63: $hooks[] = add_options_page(
  6. Included plugins : Zip file found Plugins are not allowed in themes. The zip file found was snax.zip easy-social-share-buttons3.zip media-ace.zip ad-ace.zip g1-socials.zip photomix.zip youzer.zip js_composer.zip comment-ace.zip envato-market.zip whats-your-reaction.zip.
  1. theme tags : Presence of bad theme tagsThe tag fluid-layout has been deprecated, it must be removed from style.css header.
  2. Text domain : Incorrect use of translation functions.Found a translation function that has an incorrect number of arguments. Function _n, with the arguments 'One Comment', '%1$s Comments', comment_count, 'cace' in file headline-comments.php.Found a translation function that has an incorrect number of arguments. Function _n, with the arguments 'One Comment', '%1$s Comments', comment_count, 'cace' in file headline-comments.php.Found a translation function that has an incorrect number of arguments. Function _n, with the arguments 'One Ping', '%1$s Pings & Trackbacks', ping_count, 'cace' in file headline-pings.php.Found a translation function that has an incorrect number of arguments. Function _n, with the arguments 'One Comment', '%1$s Comments', comment_count, 'cace' in file headline-comments.php.Found a translation function that is missing a text-domain. Function __, with the arguments 'A comment on your post "%s" was reported to delete.' in file wp-report-functions.php.Found a translation function that is missing a text-domain. Function __, with the arguments 'Comment: %s' in file wp-report-functions.php.Found a translation function that is missing a text-domain. Function __, with the arguments 'Report: %s' in file wp-report-functions.php.Found a translation function that is missing a text-domain. Function __, with the arguments 'You can see all reports here:' in file wp-report-functions.php.Found a translation function that is missing a text-domain. Function __, with the arguments '[%1$s] Comment reported on your post "%2$s"' in file wp-report-functions.php.Found a translation function that is missing a text-domain. Function __, with the arguments 'Edit This' in file wp-comment-functions.php.Found a translation function that is missing a text-domain. Function esc_html_x, with the arguments '(drag and drop to reorder)', 'bimber' in file theme-options.php.Found a translation function that is missing a text-domain. Function esc_html_x, with the arguments 'Edit plugin settings', 'bimber' in file theme-options.php.More than one text-domain is being used in this theme. This means the theme will not be compatible with WordPress.org language packs. The domains found are bimber, woocommerce, buddypress, wyr, rcp, snax, g1_theme, bbpress, comment_count, wordpress-importer, tgmpa, mailchimp-for-wp, bp-follow, adace, js_composer, mycred, mace, youzer, cace, ping_count, case, download-monitor, g1_socials.
  3. Plugin territory : Plugin territory functionalitiesThe theme uses the register_taxonomy() function, which is plugin-territory functionality.The theme uses the add_shortcode() function. Custom post-content shortcodes are plugin-territory functionality.
  4. Custom elements : Presence of custom headerNo reference to custom header was found in the theme.
  5. Custom elements : Presence of custom backgroundNo reference to custom background was found in the theme.
  6. CSS files : Presence of .sticky class.sticky css class is needed in theme css.
  7. Screenshot : Screenshot fileBad screenshot file extension ! File screenshot.png is not an actual JPG file. Detected type was : "image/png".
  1. Static links : Presence of hard-coded linksPossible hard-coded links were found in the file theme-options-registration.php.63: <a href='https://help.market.envato.com/hc/en-us/articles/202822600-Where-Is-My-Purc75: <a href='https://themeforest.net/licenses/terms/regular' target='_blank'><?php esc_hPossible hard-coded links were found in the file video-post-format-metabox.php.83: <a href='https://bimber.bringthepixel.com/docs/video-lenght/' target='_blank'><?php Possible hard-coded links were found in the file disqus-comments.php.37: <noscript>Please enable JavaScript to view the <a href='https://disqus.com/?ref_noscript'>comments powered by Disqus.</a></noscript
  2. Optional files : Presence of rtl stylesheet rtl.cssThis theme does not contain optional file rtl.php.
  3. Optional files : Presence of front page template file front-page.phpThis theme does not contain optional file front-page.php.
  4. Optional files : Presence of attachment template file attachment.phpThis theme does not contain optional file attachment.php.
  5. Optional files : Presence of image template file image.phpThis theme does not contain optional file image.php.
  6. Use of includes : Use of include or requireThe theme appears to use include or require : class-elementor-bimber-extension.php 78: require_once( BIMBER_PLUGINS_DIR . 'elementor/widgets/bimber-collection.php79: require_once( BIMBER_PLUGINS_DIR . 'elementor/widgets/bimber-categories.php80: require_once( BIMBER_PLUGINS_DIR . 'elementor/widgets/bimber-mc4wp-form.php94: require_once( BIMBER_PLUGINS_DIR . 'elementor/controls/class-bimber-terms-c95: require_once( BIMBER_PLUGINS_DIR . 'elementor/controls/class-bimber-radio-c If these are being used to include separate sections of a template from independent files, then get_template_part() should be used instead. Otherwise, use include_once or require_once instead.The theme appears to use include or require : comment-ace.php 26: require_once( plugin_dir_path( __FILE__ ) . 'constants.php' );27: require_once( plugin_dir_path( __FILE__ ) . 'includes/options.php' );28: require_once( plugin_dir_path( __FILE__ ) . 'includes/functions.php' );29: require_once( plugin_dir_path( __FILE__ ) . 'includes/wp-comment-functions.30: require_once( plugin_dir_path( __FILE__ ) . 'includes/wp-report-functions.p If these are being used to include separate sections of a template from independent files, then get_template_part() should be used instead. Otherwise, use include_once or require_once instead.The theme appears to use include or require : class-database-controller.php 115: require_once( ABSPATH . 'wp-admin/includes/upgrade.php' ); If these are being used to include separate sections of a template from independent files, then get_template_part() should be used instead. Otherwise, use include_once or require_once instead.
