SerhiiNadolskyi
Hire me

Craft business · DE · 2026

A plugin with a critical security hole removed, then an update plan

I removed a backup plugin with a critical vulnerability from a small business's WordPress site, connected the site to the agency's management service and gave the agency an ordered update plan.

Security fix
1vulnerable plugin removed

The flagged backup plugin is removed, and the site is connected to the agency's management service.

A security scan of the hosting account found a backup plugin with a critical flaw on a small craft business’s WordPress site. Through it an attacker could take over the whole site. No admin access had been set up yet.

I asked for admin access at once and removed the plugin as soon as I got it. Then I connected the site to the agency’s backup and management service, the planned replacement for that plugin. A login captcha blocked the automatic connection, so I installed the connector by hand and noted that its backups still had to be switched on.

I wrote a short health report: pending updates, the risk of each, and plugins doing the same job twice. For approval I proposed an update order, with a full backup first, then the safe updates, then the larger ones, and the WordPress core update only on a test copy. I kept to the fix and wrote that in the report. Anything further is the client’s decision.

Contact

Have something similar?

Use the form or message me on LinkedIn.

Already working with me on Upwork? Write there.