Vulnerable plugins on site you host but didn't build - How to handle?
Let's say theoretically you have a dedicated server hosting 75 websites. 98% of those sites you built and are therefore "responsible" in case there are security patches.
2% of the sites used another vendor and have no ongoing relationship beyond paying for hosting.
If one of those sites has plugins with vulnerabilities how should I handle the situation? I can't just update the plugins on my own because some require new licensing.
If I leave them as-is and they get hacked, it could effect my other clients. But I can't force them to pay me to update their site - how do you guys handle this?
With other hosting set ups, each WP instance is isolated so it doesn't really matter if they're hacked (not my problem) but with everyone on the same server I worry about attacks (DDOS etc.) on this one site effecting all the others.
[link] [comments]