When a vulnerability is fixed, the fix is published — and so, effectively, is how to exploit sites that haven’t updated. Automated attacks follow within days.
What needs updating
| Component | How |
|---|---|
| Your CMS core (WordPress, Joomla, etc.) | Its admin dashboard, or Softaculous |
| Plugins, extensions and modules | The CMS admin |
| Themes and templates | The CMS admin, or the supplier |
| Composer and npm dependencies | Rebuild locally and redeploy |
| PHP version | DirectAdmin (How to change the PHP version in DirectAdmin) |
| Your own devices and browsers | Automatic updates |
The server’s operating system, web server and database are maintained by Traxio.
A simple routine
- Weekly: log in to the CMS and apply updates (or let auto-updates run for trusted plugins)
- Before updating: take a backup
- After updating: check key pages and forms
- Every few months: review plugins and remove any abandoned ones; check the PHP version is still supported
Softaculous installs
Softaculous can notify you of updates for apps it installed, and some apps can be set to update automatically from its installation settings.
Abandoned software
A plugin or app that no longer receives updates will eventually have an unfixed vulnerability. Replace it while it’s still working, not after it’s exploited.