{"id":2086,"date":"2014-06-16T15:41:35","date_gmt":"2014-06-16T21:41:35","guid":{"rendered":"http:\/\/www.whitefirdesign.com\/blog\/?p=2086"},"modified":"2014-06-16T15:41:35","modified_gmt":"2014-06-16T21:41:35","slug":"managewp-shows-lack-of-concern-for-security-by-running-insecure-version-of-wordpress","status":"publish","type":"post","link":"https:\/\/www.whitefirdesign.com\/blog\/2014\/06\/16\/managewp-shows-lack-of-concern-for-security-by-running-insecure-version-of-wordpress\/","title":{"rendered":"ManageWP Shows Lack of Concern for Security by Running Insecure Version of WordPress"},"content":{"rendered":"<p>When it comes to the security of websites, what we see over and over is that the basics are not even being handled by people that shouldn&#8217;t have a problem doing it. If you are running a WordPress website then part of Security 101 is keeping WordPress up to date, as it prevents your website from being hacked due to a known vulnerability in an older version of WordPress. Unfortunately, that isn&#8217;t being done in many cases as can been seen in the fact that\u00a0<a href=\"http:\/\/www.whitefirdesign.com\/blog\/2014\/03\/03\/outdated-versions-of-joomla-2-5-x-and-3-x-widely-used\/#wordpress\">only 40 percent of WordPress websites were running the latest series of WordPress in the data set we looked at\u00a0in March<\/a>.<\/p>\n<p>You would think that providing better management tools would help this situation, though the example of one of the providers of such a tool would say otherwise. ManageWP describes its services as providing you the ability to\u00a0&#8220;Manage all your WordPress sites from one place &#8211; including updates, backups, security and more.&#8221; You would certainly expect they would be keeping the WordPress installation powering their website up to date, but they&#8217;re not:<\/p>\n<p><a href=\"http:\/\/www.whitefirdesign.com\/wordpress-version-check\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-2087\" src=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/managewp-wordpress-version.png\" alt=\"ManageWP is Running WordPress 3.5.2\" width=\"500\" height=\"150\" srcset=\"https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/managewp-wordpress-version.png 500w, https:\/\/www.whitefirdesign.com\/blog\/wp-content\/uploads\/2014\/06\/managewp-wordpress-version-300x90.png 300w\" sizes=\"auto, (max-width: 500px) 85vw, 500px\" \/><\/a>WordPress 3.5.2 is over ten months out of date and there have two subsequent releases with security updates (<a href=\"http:\/\/wordpress.org\/news\/2013\/09\/wordpress-3-6-1\/\">3.6.1<\/a>\u00a0and <a href=\"http:\/\/wordpress.org\/news\/2014\/04\/wordpress-3-8-2\/\">3.8.2<\/a>).<\/p>\n<p>ManageWP&#8217;s failure to take handle a basic security task is sharp contrast to their claims of security. For example, <a href=\"https:\/\/managewp.com\/features\">they claim<\/a><\/p>\n<blockquote><p>Securing ManageWP and the sites we interact with has always been our highest priority. We use state-of-the-art encryption and security standards that go above and beyond what WordPress, itself, offers, to ensure that your sites are protected.<\/p><\/blockquote>\n<p>On another <a href=\"https:\/\/managewp.com\/security\">page<\/a>\u00a0they make a series of claims about their security:<\/p>\n<blockquote>\n<h2 style=\"font-weight: bold; color: #333333;\">How ManageWP Is Secure<\/h2>\n<ul class=\"mwp_security-list\" style=\"color: #333333;\">\n<li>We have a full-time security specialist<\/li>\n<li>We regularly perform penetration testing<\/li>\n<li>No credit card information stored<\/li>\n<li>No WordPress passwords stored<\/li>\n<li>OpenSSL encryption<\/li>\n<li>ManageWP is built on top of WordPress<\/li>\n<li>Account password encryption<\/li>\n<li><a style=\"color: #0088cc;\" href=\"https:\/\/managewp.com\/white-hat-reward\">White hat reward program<\/a><\/li>\n<\/ul>\n<\/blockquote>\n<p>If you are\u00a0security specialist who\u00a0fails to make sure such a basic security measure is taken then you probably should find another profession.<\/p>\n<p>Another bad sign for their concern for security is their integration of <a href=\"http:\/\/www.whitefirdesign.com\/blog\/2012\/06\/25\/false-positives-highlight-deeply-flawed-website-malware-scanners\/#sucuri\">Sucuri.net&#8217;s deeply flawed malware scanning<\/a>\u00a0into their <a href=\"https:\/\/managewp.com\/features\">service<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When it comes to the security of websites, what we see over and over is that the basics are not even being handled by people that shouldn&#8217;t have a problem doing it. If you are running a WordPress website then part of Security 101 is keeping WordPress up to date, as it prevents your website &hellip; <a href=\"https:\/\/www.whitefirdesign.com\/blog\/2014\/06\/16\/managewp-shows-lack-of-concern-for-security-by-running-insecure-version-of-wordpress\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;ManageWP Shows Lack of Concern for Security by Running Insecure Version of WordPress&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,3],"tags":[],"class_list":["post-2086","post","type-post","status-publish","format-standard","hentry","category-bad-security","category-wordpress"],"_links":{"self":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/comments?post=2086"}],"version-history":[{"count":1,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2086\/revisions"}],"predecessor-version":[{"id":2088,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/posts\/2086\/revisions\/2088"}],"wp:attachment":[{"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/media?parent=2086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/categories?post=2086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whitefirdesign.com\/blog\/wp-json\/wp\/v2\/tags?post=2086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}