DANGER - application security and protection for ClassiPress
Hello everyone,
I currently concentrating me protect my website ClassiPress because ClassiPress is often attacked ClassiPress ...
But I will come to realize that when we go on the profile of the sale, I have a URL that appears like this:
my-web-site-classipress/author/my_user_name
and also to the source code:
<body class="archive author author-my_user_name author- logged-in">
I make the difference between ID (login) and pseudonym
But when you give your username (login) is to do half the work of hackers.
How can we replace or change the link in apparrait clear?
Do you agree with me ?
Gentlemen of developers as ClassiPress, you can do some things for the next update, because it seems that this is a glaring security hole.
or a tutorial to prevent our name (login) appears to clear the link and source code.
Let the least open doors to these pirates web ...
Doing a thumbs up if you agree with me, that will inspire developers as ClassiPress to quickly make changes.
Thank you