Home
About me
Advertise
Sitemap
Wordpress SEO
Contact
SEO jargon busters
RSS feeds
Daily SEO Blog
Jul
08

Malicious WordPress plugin steals your admin password, and you didn’t even know ?

Now, how would you react knowing that the plugin that you had used for ages emailed your admin login credentials to the plugin developer and you didn’t even know ?
Scary – isn’t it ? Well, that’s just what happened to this blogger Sven.

Sven reports in his post that while experimenting with a few plugins he found that a plugin (Pushit) plugin actually emailed his admin id and password to an email.
Now, this could have been an oversight or a mistake but its a serously scary thought.

What can you do to make sure that your WordPress plugins are “safe” ?

Quite honestly, I don’t know of anything that will give us a 100% security but there are certain things you can do for sure.
1. Install and run plugins only from developers who have a good reputation.
2. Always test the plugin on a demo/test blog.
3. Look for plugin reviews on the plugin page(usually developers blog) comments, or elsewhere on the web.
4. Never install plugins not tested with your version of blog software.

WordPress plugins are great resources and probably one of the USPs for us liking the software as millions do. But blindly trusting all of them could also land us in trouble, just a word of caution to all.

SEO Auditor Features
- Complete SEO audit
- Competitor Analysis
- Report generation
Try it today !
Link Assistant Features
- Easy Link Building
- Finds link partners
- Get backlinks regularly
Try it today !
Rank Tracker Features
- Rank Check reports
- 558 Search Engines
- Keyword Research
Try it today !



Possibly related SEO & Social Media Articles

  • The best Wordpress Plugin developers of 2008
    Here is a nice list I found the other day. W-Shadow has put up a top 10 list of the best Wordpress plugin developers of 2008, based on plugin popularity and number of plugins developed. I think it’s a very apt and true list. Check out the plugins from these authors, they’re all cool. Michael Torbert [...]...
  • Wordpress plugin to replace post titles with fancy fonts
    Dinu, a fellow blogger from Cochin is pretty impressed with Amy Mahon’s  wordpress theme over here, and was wondering what’s that funky text doing at the post titles ? Watch closely and you’ll find that the post titles are replaced with cool text effects rather than the plain text. Right click on the title and you’ll [...]...
  • Add a Twitter button on your posts – Wordpress plugin, “Tweet this”
    Now, that you and your friends are tweeting more these days, it’s not alarming to see someone come up with the plugin. And that someone is – Richard X Thripp, and the plugin in a simple wordpress one, that adds a cute twitter bird image on top right corner of all of your posts, which [...]...
  • A Wordpress plugin that help fight scrapers and copycats
    Scrapers/ Sploggers and copy cats are the names you’d never want to hear these days. Simply because every blog has a splogger who’s scraping your content from the RSS feeds everyday.There are lot of tools available to fight scrapers, and here’s a brand new plugin for Wordpress that’ll help you to fight scrapers. It’s the categories Autolink [...]...
  • A wordpress plugin that will help you make money from your blog
    Wordpress plugins are made keeping in mind the utility and functional aspects of your blog. Sometimes, they turn out to help you make money from your blog as well. Here is a great plugin which was meant for something else but ultimately will help you make money online. This wordpress plugin is actually made for making [...]...

Category: Wordpress SEO | Author: Mani Karthik
SEO Wordpress Themes
  1. Wordpress DevelopersNo Gravatar

    Thank you very much for sharing such a valuable information. Really this post create awareness for all word press developers.

    Reply

  2. ZirroNo Gravatar

    Is it impossible to see the code of Wordpress plugins then?

    Reply

    Tech @ InkAPointNo Gravatar Replied:

    Yes. You can. Just open the plugin’s zip file and see the php files.

    Reply

  3. Yael K. MillerNo Gravatar

    I have to disagree with #4 completely.

    I’ve installed WordPress 2.8 (not on my main site, I admit) and since a lot of plugin creators seem to have ignored the release of 2.8, I’ve had to test myself whether the plugins will work.

    DailySEOBlog seems to have ignored #4 itself.

    I can’t say positively but I’m pretty sure that the “Notify me of follow-up comments via e-mail” is the Subscribe to Comments plugin. If you look at the Subscribe to Comments page (wordpress.org/extend/plugins/subscribe-to-comments) you will notice that is listed as officially only “Compatible up to: 2.3.1″ That hasn’t stopped the thousands of people who download it weekly.

    Reply

    Mani KarthikNo Gravatar Replied:

    I completely agree Yael. In fact, I hadn’t taken it seriously to this time. If the plugin works fine even after an upgrade, then I’d keep it. But I think this is a mistake I’ve been making and am seriously considering pulling them off with minimum user exp problems.

    Reply

    Tech @ InkAPointNo Gravatar Replied:

    You are right Mani. Sometimes plugins will work like upward compatible versions. But what’s the problem is not all plugins are working as 100% compatible to newer versions of WP.

    We can’t say that plugins will not work if it is developed for earlier versions of wp.

    Reply

  4. Kurtis TaylorNo Gravatar

    I would have thought that Wordpress’s approval process would be a little more careful about the kind of code placed in these plugins but I guess not.

    Reply

  5. Anish K.SNo Gravatar

    Thanks mani for the advise.

    Reply

  6. NiharNo Gravatar

    I think one should always use a plugin which is there on wordpress directory.

    DOn’t use plugins from the the authors site.

    What do you think?

    Reply

  7. Sarah LewisNo Gravatar

    @Nihar: until Sven’s post, that particular plugin was in the WordPress directory.

    However, I think the title of this post is (unintentionally) misleading. If you read Sven’s post again, you’ll see that the plugin did not do anything with the WordPress admin password, only some basic SMS request data (that included the username and password for the SMS service, but nothing as sensitive as the WordPress admin password).

    Don’t get me wrong; it’s still a security issue. After all, the plugin was doing something without the user’s permission.

    But I’m pretty sure that your admin password is actually very safe, even from malicious plugin authors, because it is not stored clear text (even in the database). There’s no way that I know of for a plugin to ever access the unencrypted version of the password.

    All that said, it is definitely best to be cautious with any plugins. I think your tips are good ones. Perhaps some enterprising security pro will start a plugin-review blog and do us all a favor. :)

    Reply

  8. marcelomuraro (marcelo muraro)No Gravatar

    Malicious WordPress plugin steals your admin password, and you didn’t even know? http://tinyurl.com/machfl

    Reply

  9. teratipsNo Gravatar

    its best but also its naughty tool

    Reply

  10. gheoNo Gravatar

    great one,and well doen.keep up

    Reply





Click to cancel reply

  • SEO Blog Sponsors

    MLM Leads with SEO SEO CockPit
    Advertise Here
  • Create Flash Websites
  • Recent SEO Blog Articles

    • New site not indexed on Google yet ? Here’s what to do
    • Confused over .com and regional domain SEO Advantages ?
    • How to detect mobile browsers & Redirect mobile users to another URL
    • 3 Effective Ways to block Google from crawling parts of your website
    • News from Google: Fix duplicate content issues using canonical tag across websites
    • Header Tags – What are they ? Where and How to Use Them Effectively
    • Speed up your pages like right now !
    • 5 Routine SEO house keeping tasks to check site health regularly
    • 4 SEO Factors Search Engines might talk about more in 2010
    • 3 Simple Ideas that will get backlinks, even if you don’t ask
    • SEO Tips Day 14 – How to submit a new website to search engines ?
    • SEO Tips Day 13 – 3 Crucial things you should avoid in SEO
    • SEO Tips Day 12 – Top 3 Influencing factors in backlinks
    • Google now indexes pages via RSS/Atom feeds on your site
    • SEO Tips Day 11 – How to deal with duplicate content issues
    • SEO Tips Day 10 – Domain Age and SEO – How important is it ?
    • SEO Tips Day 9 – Optimizing URLs for Search Engines
    • SEO Tips Day 8 – Will linking to other sites, reduce your Page Rank ?
    • SEO Tips Day 7 – Would buying links get you banned from Google ?
    • SEO Tips Day 6 – Use of Keywords in Page Title
    • SEO Tips Day 5 – Don’t pick the keyword with highest search volume
    • SEO Tips Day 4 – Make an attractive page title for better click through rate
    • SEO Tips Day 3 – 5 Handy Internal Linking Tips
    • SEO Tips Day 2 – SEO is Skeleton, Content – Muscles, Social Media – Physique
    • SEO Tips Day 1 – Content is King, But Package it well
  • Popular at Daily SEO blog

    • 10 Twitter tools to effectively manage your followers (125)
    • How to get indexed by Google in 48 hours (102)
    • How to get a Google Wave invite (even if you didn’t sign up earlier) (91)
    • How to get free backlinks (81)
    • Free SEO Wordpress theme – SEO Blog (75)
    • Ultimate list of Dofollow Social Bookmarking sites (74)
    • 9 Twitter Tips that will help you gain respect in the Twitterverse (Like @Zaibatsu) (72)
    • 25 SEO Gurus you should follow on Twitter (61)
    • SEO for Wordpress - A quick guide (57)
    • New Wordpress theme - "SEO Green" from DailySEOblog (57)
  • SEO Tools & Resources

    • Google introduces “Browser Size” tool for webmasters
    • 10 Essential Adobe Air Applications for Social Media Addicts
    • Integrity – Broken Link Finder SEO Software for Mac
    • Find out people who’re not following you back on Twitter
    • Google Advanced Search Operators right in your browser (So you don’t have to memorize them)
    • You can actually make money on Twitter, A method that really works !
    • Firefox Plugin – Monitor AdSense earnings from Firefox statusbar
    • Best SEO Software – Rank Tracker Review – Check ranks on multiple search engines automatically
    • 9 Free Tools to check Social Media Backlinks & Popularity of your website
    • A free tool to check your site rankings, backlinks & social popularity
  • Social Media Articles

    • New to Twitter ? 7 Tips to make Twittering a rewarding experience
    • Why is it easy to convince your client of Social Media Marketing but not implementing it
    • 4 Cool Twitter Applications to help you monitor weight, health and stay fit !
    • Why I Tweet Frequently (and still don’t count it as a mistake)
    • 5 Tips to make Twittering more meaningful by increasing the signal to noise ratio
    • StumbleUpon gets a makeover – Gets cool new features !
    • Top 25 Most Popular PodCasters on Twitter you shouldn’t miss following
    • 5 Features I’d like to see on the Su.pr URL sharing service
    • Top 35 News Sources on Twitter you should follow : Keep updated with the latest news
    • 8 Habits of Successful & Popular Twitter users for Inspiration
    • 10 Tricks to search Twitter better, Beyond your timeline – Around the world
    • How to make money on Twitter ? Some ideas that work ( without screw ups ) !
    • 9 Mistakes I committed on Twitter and could’ve avoided !
    • 9 Reasons why I prefer to DM you rather than reply in public on Twitter
    • Social Media Power user. What, So he’s like superman or something ?
  • Recent SEO Tips

    • New to Twitter ? 7 Tips to make Twittering a rewarding experience
    • New site not indexed on Google yet ? Here’s what to do
    • Confused over .com and regional domain SEO Advantages ?
    • Website security tips – What to do if website is hacked or malware infected
    • Google PageRank Update 2009 December is happening as I write this
    • 5 Reasons why Google PageRank sucks (and is no more a valid metric) !
    • Google gives top users at Webmasters Forum a pat on the back !
    • How to detect mobile browsers & Redirect mobile users to another URL
    • Google Introduces keyboard shortcuts to access Search results – Accessibility Search
    • 3 Effective Ways to block Google from crawling parts of your website
    • DSB Needs a redesign. Looking for ideas and options.
    • Google Guru might be Google’s answer to Yahoo Answers. Or is it ?
    • Google introduces “Browser Size” tool for webmasters
    • 10 Essential Adobe Air Applications for Social Media Addicts
    • News from Google: Fix duplicate content issues using canonical tag across websites
  • Top SEO Tags

    ads adsense backlinks blog blogger Blogging blogosphere blogs categories check crawler crawling crowd Excel google image images indexing india indian instances internet javascript keywords links pages rank robots search engine optimization seo tips serps sitemap submit tags templates theme themes upload video wordpress Wordpress SEO wordpress seo wordpress tips yahoo youtube

Basic SEO Tips

  • Change the way your site appears on Google SERPs
  • Control Google's crawl frequency to your site
  • How does Google see your site?
  • Importance of footer text in SEO
  • Optimizing header images
  • SEO tips for MSN search engine
  • Optimizing blog titles for Google
  • SEO friendly layout
  • What is an SEO friendly site structure?
  • Importance of keywords - SEO Tips
  • Anchor text importance - SEO Tip
  • SEO Tips for blogs and bloggers
  • Absolute links or relative links is good for SEO?
  • Important SEO tips for wordpress

SEO Tips for blogs

  • 24 Must have SEO plugins for Wordpress
  • SEO Tips - Copy writing guide
  • How to get quality backlinks?
  • Social media and link building tips
  • SEO Tips - Landing page Optimization
  • How to increase traffic to your blog?
  • How to increase your Page Rank?
  • Image optimization tips for blogs
  • 7 steps to your blog's SEO
  • How and where to find incoming links?
  • SEO tips for Google
  • SEO metrics to track
  • How to build a sitemap for blogger
  • How to get Google sitelinks?
  • Find out when Google indexed you
Mani Karthik Hi, I'm Mani Karthik, SEO, Blogging & Social Media Enthusiast. I primarily blog about SEO and Social Media on this blog, basically How-to articles and tutorials to help the SEO learner. Feel free to have a look around and drop comments. Hope you enjoy your stay.
>> More about me
© 2009 DailySEOblog.com Privacy policy