ws_plugin__s2member_js_w_globals potential security risk??
Posted: January 8th, 2011, 9:23 pm
After playing around with s2member (non-pro), I noticed that it seems to feed a ws_plugin__s2member_js_w_globals.js file with a huge amount of member/site data that really should not be accessible browser-side. Even without someone being logged in, it still shows some paypal info, along with a bunch of other stuff that seems pretty much unnecessary for most usage cases. Is there any way to completely (or at least mostly) stop this data from being transmitted? I thought I'd try just blocking it altogether from the PHP to see what happens, but felt I should at least bring it up in the forums as well.
Thanks.
Thanks.