tagDiv Composer problem

Posted in: Newspaper
Post count: 3

Hallo, when i instal Tagdiv Composer, web go down
There has been a critical error on this website. Please check your site admin email inbox for instructions. If you continue to have problems, please try the support forums.

Learn more about troubleshooting WordPress.

Post count: 35449

Hi,
Is this situation persisting using the last theme version with the last WordPress version and with a PHP version 8-8.3? Can you make a test using only tagDiv plugins? In the case that the problem no longer persists, it means that this is a plugin conflict, but in case the situation is the same, then we’ll need to check it out, and we’ll need cPanel and WP-Admin access to do this.
Thank you!

Post count: 3

Hi Calin, can you write me in privat to give you acces please!

  • This reply was modified 10 months by Nuredin.
Post count: 35449

Hello,
We can hear each other via email at contact@tagdiv.com
Thank you!

Post count: 3

I think i have found the issue, after reinstalling multiple times, changing php versions, i discovered that CpGuard is deleting this file, see the details below:

common.php Virus File {HEX}Malware.Expert.php.base64.decode QUARANTINED

VIRUS DETAIL

#ID170583

File Name common.php
Original Path /home/euromedi/public_html/pirok.mk/wp-content/plugins/td-composer/legacy/common/common.php
Reason
Definition
Time 2025-09-16 00:41:45
Quarantine Path/etc/cpguard/quarantine/1605452187-common.php
File Size14008 bytes
Status Quarantined

Post count: 35449

Hi,

It seems that because encryption and decryption are being used, CpGuard might be flagging the common.php file as a potential threat, simply because it cannot verify the encrypted content. This appears to be a harmless false positive.

Thank you!

Post count: 83

I apologize for butting in, but our host is reporting the same problem on two separate sites: the file …/td-composer/legacy/common/common.php has been quarantined because it was detected as an infected file.
They suggest it “entered” through a WordPress, theme, or plugin vulnerability, but since the same file is on two different sites that share no plugins, it’s either WordPress or the theme, but my Newspaper installations are working very fine.
Please, Calin, confirm us if you can, or as soon as you can, that this is a “false positive” to give us peace of mind.
We’re always very grateful.
Mattia

Post count: 20688

Hi,

We saw nothing suspicious in the similar cases we investigated, the contents of that file was in order. The code itself is safe, it’s definitely a false positive. CpGuard detects part of the code as suspicious however, and the solution would be to whitelist that file in the cpguard settings so it doesn’t get moved to quarantine. We will try to maybe modify the code but its a very tricky part of the code which could cause problems for the theme users if we do it wrong.

Thanks.

Post count: 83

Thank you Simion,
for me ” it’s definitely a false positive” is enough.
Our sites work fine even with that file in “Quarantine” mode; apparently, it’s only needed during the compilation phase, which we’ve long since outgrown.
So, we’ll leave everything as is and move forward with peace of mind, as there’s no danger to our visitors.
Many thanks.
M.

Viewing 9 posts - 1 through 9 (of 9 total)
The forum ‘Newspaper’ is closed to new topics and replies.