The flagged backup plugin is removed, and the site is connected to the agency's management service.
Craft business · DE · 2026
A plugin with a critical security hole removed, then an update plan
I removed a backup plugin with a critical vulnerability from a small business's WordPress site, connected the site to the agency's management service and gave the agency an ordered update plan.
A security scan of the hosting account found a backup plugin with a critical flaw on a small craft business’s WordPress site. Through it an attacker could take over the whole site. No admin access had been set up yet.
I asked for admin access at once and removed the plugin as soon as I got it. Then I connected the site to the agency’s backup and management service, the planned replacement for that plugin. A login captcha blocked the automatic connection, so I installed the connector by hand and noted that its backups still had to be switched on.
I wrote a short health report: pending updates, the risk of each, and plugins doing the same job twice. For approval I proposed an update order, with a full backup first, then the safe updates, then the larger ones, and the WordPress core update only on a test copy. I kept to the fix and wrote that in the report. Anything further is the client’s decision.
A new site for an earthworks company, from Figma to Elementor Pro
I built an eight-page site from a Figma design, with a mobile layout the design didn't have, and moved it to the client's host.
A German and English site a lighting studio can edit itself
I built a lighting studio's two-language block-theme site and moved its menus to where the client can edit them per language.
A housing developer's Hebrew website, built and run for almost four years
A Hebrew right-to-left site for a real-estate developer on Next.js and Strapi, which I ran until 2026, plus a campaign-page module marketing can use on its own.
Contact
Have something similar?
Use the form or message me on LinkedIn.
Already working with me on Upwork? Write there.