7th October 2026·The Grizzlyware team

Your online shop’s plugins could be its weakest link

weak link

Part 2/5 of our October series: small, free steps to take control of your own cyber security.

If you look through the plugin settings of your online shop, chances are you’ll come across several that you no longer use. You may even encounter a few whose purpose you can’t remember at all. As a small business owner, you’re already spinning multiple plates, and seemingly insignificant admin tasks such as removing old plugins frequently get pushed back to another day. It’s not urgent, right?

But every third-party plugin on your site is another ‘door’ hackers can use to access your admin area and customer data. Every unnecessary plugin adds vulnerability, with no benefit.

What happened to Master of Malt

Back in September, well-established and award-winning online spirits retailer Master of Malt had to tell its customers that their names, email addresses, phone numbers and addresses had been exposed. This is a horrible experience for any business, made worse in this case by the fact that Master of Malt had done nothing wrong.

Master of Malt wasn’t the target of the hack, and neither was BigCommerce – the platform its shop runs on. The attackers had stolen the key for a single third-party app, Ribon, which is installed on hundreds of shops to improve the shopping experience, and used it to reach their customer data.

Could Master of Malt have spotted the breach before it affected customers?

As the stolen key belonged to the Ribon app rather than to Master of Malt, only the app’s developer or BigCommerce could have noticed it being misused. The download didn’t trigger any alert for Master of Malt.

This just goes to show that you can neither constantly monitor nor fully control third-party add-ons, which is why keeping only the ones you really need is crucial.

Are plugins bad?

Almost all online shops rely on plugins for some things. They allow lots of desirable features, such as reviews, subscriptions and gift cards, to be added to your shop at an affordable price. Often, they’re well built and maintained, and add genuine value to your site.

On some setups, such as WooCommerce on WordPress, it’s easy to end up with dozens.

Plugins are where most of the risk sits. In 2025, Patchstack found 91% of new WordPress security flaws were in plugins. WordPress itself had only six.

Each plugin is made by a different company and updated on its own schedule. This can cause two main problems:

  • Security. A single plugin that stops being updated by its developer leaves a vulnerability, even if you’ve followed security advice to a tee everywhere else on your site.
  • Conflicts. Updating one plugin can break another. Sometimes this just means the styles or animations on your site don’t appear quite as they should, but sometimes it leads to bigger issues, like your checkout no longer working – with no obvious point of failure.

None of this means plugins are inherently bad, but it does mean that the more you use, the more likely you are to run into a problem. The benefit of each plugin must outweigh the risk it introduces.

Your 20-minute task

Once Ribon had been removed from its site, this is exactly what Master of Malt did next: it started checking all the plugins and add-ons connected to its shop, and limiting what each one can reach. Whatever your shop runs on, you can protect yourself by doing the same today, and regularly going forward.

  1. Look in detail at every plugin and add-on. Make sure you understand what each one does. This includes everything on your plugin, add-on and theme pages, as well as anything connected externally, like accounting or email software.
  2. Check that each one is being maintained. Well-maintained plugins are usually updated regularly. If one hasn’t been updated in the last six months, you should question whether it’s still safe to trust.
  3. Delete what you don’t use. Make sure you delete it rather than just deactivating it, as a dormant plugin’s files will remain on your site.
  4. Keep the rest up to date. Take a backup first in case of conflicts, and check now and then that your backups actually work.
  5. Make it a recurring event. Add a reminder to your calendar to do this again in a few months’ time – six at the most.

Twenty minutes of your time every few months can prevent big problems in the future.

Fewer is simpler

A shop with a few well-chosen add-ons is much easier to manage than one with thirty. This is one of the things we weigh up when choosing a platform, and part of the reason we build new eCommerce sites on Aero Commerce. A lot of the essentials come as standard, and we can build many of the rest in-house, which makes monitoring easier and reduces the chance of conflicts.

But a tidy, up-to-date shop on any platform is in good shape, and that can be achieved and maintained using the check above.

Need a hand?

If your plugin list has grown longer than you’d like, or updates have become something you dread, our free process audit can take a look and tell you honestly what needs doing – if anything. Call us on 01637 222001 or get in touch.

Sources

Related articles