Skip to content
View in the app

A better way to browse. Learn more.

Web Designer Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

If a site I designed and built is hacked am I obliged to fix it free of charge?

Featured Replies

Hello,

 

I have had one of my Wordpress websites hacked. I don't know if the reason is my own lack of updating/weak passwords. Or whether it is the persons own computer having a virus or the server (which is not owned by myself) having some sort of security leak.

 

I am suspicious of the server the site is on. because most of my own sites hosted by myself have not had any issues at all.

 

Anyway I was wondering; if the site is hacked is it my obligation to get it fixed free of charge and should the customer be rightfully angry with me?

 

thanks..

Anyway I was wondering; if the site is hacked is it my obligation to get it fixed free of charge and should the customer be rightfully angry with me?

Who else is going to fix it?

 

I think he's getting at charging for his time. If the customer's own hosting has been hacked, then it's not directly his responsibility so could charge some sort of fee to fix if he wished.

 

Ah right, I read the post too fast.

I agree with rallport, it's really down to your brief/agreement with the client. Wordpress is a well known target for exploitation so when using it it's always a good idea to put some provisos in to protect your back.

 

As rallport suggested if it doesn't take long to fix then that goodwill gesture will be a positive thing for you. It would also be a good opportunity to recommend actions your client needs to take to keep their site secure.

When you supply a system based on open source software, you can't provide the same warranties as for one based on commercial software because you can't back off the responsibility for a failure to anyone. I make it clear to my customers that what I am providing is configuration services. They must accept the GPL licence that comes with the CMS software and, specifically, that it comes with no warranties of any kind.

 

I do, of course, have a responsibility to make a website as secure as possible, within the limits of the platform used, e.g. changing admin account usernames, strong passwords, secure directory permissions, not using untrusted third party components etc etc. Those are configuration requirements, and I am negligent if I don't do them.

 

What happens after go-live and handover depends on the service I am contracted to provide. If there is no maintenance agreement in place and a site gets hacked because it isn't using current versions of all components, then that isn't down to me. If there is, then it is my responsibility to make sure security patches are applied.

 

If it turns out to be vulnerable hosting, then it isn't down to you, but that is difficult to prove.

This is one of the area of Wordpress I dislike. Because it's so popular it's become a victom of its own success and makes itself a target for hackers. Hell, I'm sure everyone remembers the infamous "Timthumb" saga :)

 

And the never ending security issues with the core - http://www.cvedetails.com/product/4096/Wordpress-Wordpress.html?vendor_id=2337 - then add poorly coded plugins to the mix and it's an ongoing recipe for disaster :)

And the never ending security issues with the core - http://www.cvedetails.com/product/4096/Wordpress-Wordpress.html?vendor_id=2337 - then add poorly coded plugins to the mix and it's an ongoing recipe for disaster :)

I tried once to argue the fact that Wordpress is a poor choice of clients on here once, people are too tied down by what they 'specialise' in or 'what they always use' to realise that there are better solutions out there that are far more suited to whatever job needs doing, Wordpress although useful for 'fast' development in my eyes is not suitable really for professional client works unless you are prepared to work the core files to protect your clients.

  • Author

Depends :)

 

What did your brief say?

 

It may also come down to the specific reasons the site was hacked.

 

If the site is hacked due to things like insecurely written code, poor site configuration, poor server configuration etc. then I'd say it's down to you. What did you discuss with the client with regards tokeeping Wordpress up to date (is their version of Wordpress up to date by way?)? Is it your responsibility, or their own?

 

If the site was hacked at a higher level E.g. someone broke into a hosting account and gained FTP access, then that's down to the customer, as they chjose their owen host.

 

Whoever is at fault, if the fix results in a few moments of yout time, I'd personally just do it as a goodwill gesture.

 

No it was an informal agreement to build a site. Nothing legal signed by either me or the client.

 

I don't know why the site was hacked or the reason that it now has a permanent link for online casinos. I have searched the database and individual files and I have concluded this spam has been inserted either remotely or through some kind of disguised code. It is also difficult to pinpoint because it disappears whenever I login to the admin of the site. So I can't simply go through plugins to find it.

 

I gave the client a login on completion of the site and let them do their edits. I was not paid to be webmaster of the site. I do not host the site.

 

My friend gave me a good analogy on the matter: 'If an artist is commissioned to paint a picture for someone and someone afterwards comes along and throws acid on it. You cannot hold the artist responsible.'

 

Whilst I will say I should have taken more precautions and dedicated some time to security (you live and learn). I am not legally obliged to fix anything without payment. Especially as in this case it means I will have to pay someone else to fix it. That it seems is most likely anyway.

 

I have said I will continue to try and help as goodwill. But have recommended the customer use this: http://quttera.com/anti-malware-website-monitoring-signup (that is what I would do if it was my own site).

 

This customer has been very cheap throughout building the site. They quibbled over every last bit of extra design I had to do (very fussy). They persuaded me against my better judgement that several hours of extra edits could be included in the original quote. In other words I have been very kind and not charged nearly as much as I could have so far. This is why I am not particularly happy to 'go the extra mile'.

Edited by Zapdos

Maybe this will be helpful in the future - http://codex.wordpress.org/Hardening_WordPress

There is a lot of info on the matter online, as well as plugins.

 

This one goes through all themes and plugins files and finds malicious code - http://wordpress.org/plugins/tac/

 

Quite often clients come to to fix their hacked WP websites (for the record - not built by me) and in most cases it's a hosting issue, sometimes it's not updating the system and plugins...

 

There are far to many "developers" who use Wordpress exclusivly and see that as a solution to any given project. I digress :)

 

...due to "developers" who have messed with the core files and disabled any updates.

I tried once to argue the fact that Wordpress is a poor choice of clients on here once, people are too tied down by what they 'specialise' in or 'what they always use' to realise that there are better solutions out there that are far more suited to whatever job needs doing, Wordpress although useful for 'fast' development in my eyes is not suitable really for professional client works unless you are prepared to work the core files to protect your clients.

 

 

 

 

Yer, unfortunate but true. Developer have a reponsibility to use the correct solution for the job. It will not always be Wordpress. There are far to many "developers" who use Wordpress exclusivly and see that as a solution to any given project. I digress :)

 

Indeed that's all part of the larger problem. We all know Wordpress is a good tool when it's appropriate but far too often it seems to be used without any real thought as to whether it's the best solution for a project. How many times have you seen someone asking for "ABC" and getting a dozen replies suggesting WP without any reply even asking any specifics to find out if it is the best fit for the client and the content structure?

  • Author

 

 

 

Indeed that's all part of the larger problem. We all know Wordpress is a good tool when it's appropriate but far too often it seems to be used without any real thought as to whether it's the best solution for a project. How many times have you seen someone asking for "ABC" and getting a dozen replies suggesting WP without any reply even asking any specifics to find out if it is the best fit for the client and the content structure?

 

Yeah I see what you mean. But for me personally its the cms I am familiar with and have been using and making templates for for years. I have used Joomla too but I find that a bit less user friendly and with less functionality in terms of plugins etc..

 

I think its probably just laziness. Rather than have to take on an unfamiliar cms people just stick to what they know, even if they end up being hacked.

 

teodora - thanks for that plugin you recommend. I will try that..

 

Yeah I see what you mean. But for me personally its the cms I am familiar with and have been using and making templates for for years. I have used Joomla too but I find that a bit less user friendly and with less functionality in terms of plugins etc..

 

I think its probably just laziness. Rather than have to take on an unfamiliar cms people just stick to what they know, even if they end up being hacked.

 

There's nothing wrong working with things you're familiar with :)

 

It's always a good idea to be familiar with a few platforms in addition to the one your specialise in so you can offer the best solution for the project in hand. In addition to giving your customers the best solution, should any particular system fall from grace then you always have fallbacks, plus of course broadening your skills and range of clients you can take on.

 

It's worth noting that there are 100's of general CMS's around, not just the usual ones that get banded about. A lot of them have relatively few developers so opportunities to pick up work are much greater.

Edited by BlueDreamer

 

...due to "developers" who have messed with the core files and disabled any updates.

Developers have an uncanny ability to blame a hacked Wordpress on whatever part it is they did not code or adjust themselves, there would be issues with people messing with the core despite what some developers think but likewise there are also pre-existing issues that do need sorting but it should be Wordpress themselves through their usual testing methods to fix those issues and not individual developers playing with core files.

 

Wordpress, until it's fixed by Wordpress and these issues are sorted, which so far they seem little incapable of doing properly is always going to be a poor choice.

 

Please don't get me wrong though, I used to use it and I used to like it too but we do forget sometimes that it was built as a blogging platform first and foremost, it's core files were not built from the ground up with security in mind in anticipation of an ecommerce site for example, it was never made for client websites originally, it was made for personal blogs.. In that respects I don't think it's suitable unless it's a personal website.

Oh, I meant developers who have edited the core files to a point where the site would break on an update, so they've disabled updates. Not a good practice.

 

Yes, I agree - the right tools for the right job. But WP has moved on from being a blog platform now. It's just another CMS platform to consider imo. There are other CMS that do the same / better job, if it fits the project, great, if not, there are other solutions.

 

^^^ Probably belongs in the infamous whine thread :)

 

It does!!!

 

 

 

Yer. Yesterday I came across a training company who have just blown £18,000 on an "advanced website" (to use their words) so they can seel their courses and takle bookings online. They have some pretty complicated products and variations. It;s been done using Woocommerce and is frankly crud. I take a look at the agency who developed the site and they seem to exlcusively use Wordpress :)

 

Well, for £18 000 I would expect a custom build the right solution.

Edited by teodora

Does the host in question offer any support? I once used (a long long long - did I say long - time ago) a web-based website builder to build a site. It was hacked. I called into the host and all I had to do was "republish" all files and it was fixed in 5 minutes. Not sure if fixing a hacked WP works the same or not.

Edited by RobertS

  • 2 weeks later...

Fix the site, because you built it and in the future. Build it in to your hosting fee. A monthly amount that will pay you to fix the site after it has been hacked and to keep Wordpress and plugins updated.



You can outsource the security and about £6.00 a month.

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.