TimThumb Scanner Plugin Activation Error
After finding evidence this morning in my logs that some visitors to the site were trying to take advantage of the timthumb vulnerability in WordPress, I installed the TimThumb Scanner plugin, which I have used before. Upon activating, I got the following error:
The plugin generated 327 characters of unexpected output during activation. If you notice “headers already sent” messages, problems with syndication feeds or other issues, try deactivating or removing this plugin.
I can’t seem to find anyone else who has had this problem with this plugin. And while I haven’t had any headers already sent messages or other issues, it concerns me and makes me curious to sort out what it means. In all my years of WordPress this is not an error message I have ever seen. What makes a plugin generate unexpected output on activation? What happens to this unexpected output?
