@sgtserial - See results from Wordfence below, I
think this is a false positive standard to a nulled plugin but
@Medw1311 @Babak might be better to confirm this?
----
Wordfence picked up potentially malicious code: * File appears to be malicious or unsafe: wp-content/plugins/elementor/core/common/modules/connect/apps/base-app.php
Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is:
->add_notice( esc_html__( 'Connected Successfully.', 'elementor' ) );\x0a\x0a\x09\x09$this->redirect_to_admin_page();\x0a\x09}\x0a\x0a\x09/**\x0a\x09 * @since 2.3.0\x0a\x09 * @access public\x0a\x09 */\x0a\x09public function action_disconnect() {\x0a\x09\x09if ...
The issue type is:
Suspicious : PHP/Elementor.nulled.12825
Description:
Elementor plugin likely been altered to disable license check