Site logo

Archived topic

Bitdefender blocks my GP sites as dangerous / infected - false positives

25 replies · Started by TogaD on January 23, 2021

Viewing posts 16–26 of 26

To Lead Developer Tom - I've discovered something important. Will provide it in the "Private information" field.

Well, what's strange there is if you link to the file, it comes up completely clean: https://generatepress.com/wp-content/plugins/gp-premium/blog/functions/js/controls.js

However, if you upload the file, even though the uploaded version is identical, it's "not".

Then, if I upload the entire .zip (that contains the same file), it's perfectly clean.

Now, if I alter the file at all, like add a . at the end of a comment, the same file is now clean. None of the code changed - only a period was added.

A quick look at the file shows it's about as simple as a javascript file gets - a handful of arrays with simple loops that display/hide elements in the Customizer. Nothing malicious, or even close to malicious.

Feel free to email directly if you'd like: support@generatepress.com

I'll continue to Google why something like this would be flagged. Like I said, the file itself is clean, and the code being used is being used on millions of websites - it's very basic javascript/jQuery.

This seems to be resolving itself. According to VirusTotal, Bitdefender is no longer finding these false positives and is reporting the entire gp-premium.zip file as clean. While some lesser-known services are still reporting false positives, I can only assume those will clean themselves up as well over the next day or so.

I'll continue to monitor. The important thing is that these were definitely false positives. I spent a few hours yesterday running these files through the scanner. The issue had something to do with the file hash - not the contents of the file.

This definitely seems to be resolving itself, and I'd like to think that the time we've spent submitting the false-positive reports (URLs *and* individual files) to Bitdefender's team has played a part.

After submitting URLs and several of the .js Files to BD over the weekend, I've run Bitdefender Update a few times and now as of today BD is no longer popping detection warnings or blocking the editor on sites :-)

Hoping the lesser-knowns seen over on VirusTotal will follow suit quickly as well.

Thanks for your diligence and great support!

I've contacted them too, so hopefully they resolve the false-positives as well.

Thanks for all your help!

I can confirm BitDefender doesn't show any warning anymore on all my websites.

Thanks for letting us know! :)

I too am no longer getting error messages from Bitdefender. Thank you, Tom, and everyone else who contacted Bitdefender to get this cleared up!

Awesome - thank you! :)

I have a similar Bitdefender warning yesterday but didn't reappear until today where BD completely blocked one of my sites. I already requested (my hosting) for a full malware scan for all my sites and the reports say they are clean. I also tried other site scanners and they all returned the same result - clean. I'm worried about my first time visitors using BD because they will be blocked and may not return to visit my site again. I hope this issue will be over soon.

Fun Fact: Since today BitDefender blocks my robots.txt files on all websites that use a .htaccess password as dangerous and infected...

This archived topic is closed to new replies.