WordPress.org

Making WordPress.org

Opened 2 years ago

Closed 2 years ago

#2659 closed defect (invalid)

Plugins displaying user email addresses alongside usernames on plugin cards

Reported by: netweb Owned by:
Milestone: Priority: normal
Component: Plugin Directory Keywords: needs-patch
Cc:

Description

Certain plugins are displaying users email addresses alongside usernames on plugin cards.

e.g. https://wordpress.org/plugins/search/act+stop+spam/

The first two plugins in that list the author as Username <some@email-address.com>

Expected: I would expect those to only have Username

Actual:

See also Slack discussion https://wordpress.slack.com/archives/C02QB8GMM/p1490952360941953

Change History (1)

#1 @dd32
2 years ago

  • Milestone Plugin Directory v3.0 deleted
  • Resolution set to invalid
  • Status changed from new to closed

In the cases listed here, the plugin authors have specifically set this as their Author header in the plugin - https://plugins.trac.wordpress.org/browser/cleantalk-spam-protect/trunk/cleantalk.php

I don't think the directory should specifically strip out email addresses if people deliberately put it into a public header, and regardless, the email is public as part of the code and will be shown in the wp-admin dashboard once you install the plugin.

Note: See TracTickets for help on using tickets.