Skip to content
../services/dev

ERR_04

Security vulnerabilities

Outdated plugins expose your data and your customers' data.

Most intrusions target nobody in particular. They are bots sweeping the web for known vulnerable versions and exploiting the first one they find. A site with plugins untouched for two years is not "under the radar": it is simply waiting to be found. In Quebec, Law 25 adds mandatory disclosure and penalties in the event of a leak.

The warning signs

  • Plugins or a platform not updated in over a year
  • No two-factor authentication on admin access
  • Backups never tested — or whose location nobody knows
  • Former employees' accounts still active
  • No logging: impossible to know who did what, and when

The most common entry points

Unmaintained third-party components

Every plugin is code written by someone else. When a flaw is published in it, that flaw becomes public for everyone — including those sweeping the web for unpatched sites.

Over-broad access

One admin account shared by five people, no second factor, a password reused elsewhere: that is the most frequent scenario in real compromises.

Unencrypted data

Personal information stored in plain text, backups reachable without authentication, API keys left in the code: the leak is then total, not partial.

What it costs

A compromise is not limited to technical clean-up. There is the business interruption, the mandatory notification of the people affected, the loss of customer trust, and the search ranking that collapses if Google flags your site as dangerous. For a small business the bill almost always exceeds what prevention would have cost.

$25M

maximum penalty under Quebec Law 25

Promptly

notice required when there is a risk of serious harm

60%

of attacks target known third-party components

How we audit it

  • Component inventory cross-checked against published vulnerabilities
  • Review of access, roles and authentication
  • Verifying encryption of sensitive data, at rest and in transit
  • Actually restoring a backup — not just confirming it exists
  • Checking security headers and service exposure

Our action plan

01

Close the urgent gaps

We first patch known, exploitable vulnerabilities and shut unnecessary access. Those are what bots are actively hunting for.

02

Lock down access

Mandatory two-factor authentication, named accounts, permissions limited to what is needed, immediate revocation when someone leaves.

03

Make security continuous

Automated updates, alerts on new vulnerabilities, regularly tested backups, logging you can actually use during an incident.

The full answer

Proactive web security

Do you know what is exposed today?

We audit your exposure and hand back the vulnerability list ranked by severity, with the exact fix for each one.

Request a security audit

The other symptoms