Support » Plugin: UpdraftPlus WordPress Backup Plugin » Security issue

Viewing 3 replies - 1 through 3 (of 3 total)
  • Plugin Author David Anderson



    Thank you for withdrawing this inaccurate report. That is appreciated.

    Many thanks,

    [ Signature moderated. ]

    Fair comment, David, I have withdrawn the post as far as seems able in this system.

    Perhaps you’d care to clarify for users before they purchase any premium multisite upgrade as to whether or not the account details they used for a financial transaction for Updraft (as opposed to a likely non-financially-related WordPress account) are indeed transmitted in HTTP cleartext rather than encrypted HTTPS after having paid for and installed the Premium version when they go to verify their Updraft Account in the dashboard.

    Rather than me doing it and getting it wrong again, that is.

    Plugin Author David Anderson



    Regarding financial transactions, we collect payments only via PayPal. PayPal never pass on any financial details to vendors. We only get a notification from PayPal that payment has cleared, and then the money appears in our PayPal balance.

    When you install the “UpdraftPlus Add-Ons Manager” plugin that allows you to claim your add-on purchases, it asks you for your password (not your WordPress password, and not your PayPal password, but the one you created at for managing purchases). That then gets sent, to in order to retrieve a list of your add-on entitlements. It’s true that that’s done without encryption – we did not prioritise encryption, because getting a list of add-on entitlements is the *only* thing that you can do with the password. If someone else knows your password, then all they can do is read a list of your purchases; they can’t make any new purchases.

    If you are still concerned about someone with “man-in-the-middle” access to your network connection getting your password, then after installing “UpdraftPlus Add-Ons” and claiming your purchases and running the WordPress updater (to update your version of UpdraftPlus to the one that includes the add-ons), you can then de-install “UpdraftPlus Add-Ons” and it won’t communicate with at all.


Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Security issue’ is closed to new replies.