Knowledgebase

Managing Extensions and Plugins Safely Print

  • otherapplicationsscripts, other, plugins, security, hacked, troubleshooting, guide, howto
  • 0

Third-party code running on your site.

BEFORE INSTALLING

When was it last updated? Anything untouched for a year is a risk. How many people use it, and what do recent reviews say? Does it come from the official repository or the developer's own site? Does it duplicate something you already have?

NEVER

Install from a site offering premium extensions free. This is the most common cause of compromised sites.

HOW MANY

Fewer is faster and safer. Each one is code running on every page, something to update, and potential attack surface.

REVIEWING

Periodically list what is installed and ask whether each is still needed. Delete what is not, rather than disabling it.

A disabled extension is still files on the server, and many vulnerabilities are exploitable without activation.

ABANDONED EXTENSIONS

An extension whose developer has stopped maintaining it receives no security fixes. Identify these and plan replacements before they become urgent.

AFTER INSTALLING ANYTHING

Test the site immediately. An extension that breaks something is easier to identify when you have just installed it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot