[{"data":1,"prerenderedAt":26},["ShallowReactive",2],{"$frZTBoJq7YHtnt-7qkRsvRl7VSMrss1Y2ATsNGyzBmeI":3},{"id":4,"slug":5,"url":6,"date":7,"modified":8,"title":9,"excerpt":10,"content":11,"featuredImage":12,"featuredImageAlt":13,"tags":14},583,"online-shop-plugins-weakest-link","https://blog.grizzlyware.com/online-shop-plugins-weakest-link/","2026-10-07T15:27:28","2026-10-07T15:53:49","Your online shop&#8217;s plugins could be its weakest link","\u003Cp>Every plugin on your shop is made by a different company, updated on its own schedule, with its own access to your shop. Here&#8217;s a free check you can do today.\u003C/p>\n","\n\u003Cp class=\"wp-block-paragraph\">\u003Cem>Part 2/5 of our October series: small, free steps to take control of your own cyber security.\u003C/em>\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">If you look through the plugin settings of your online shop, chances are you&#8217;ll come across several that you no longer use. You may even encounter a few whose purpose you can&#8217;t remember at all. As a small business owner, you&#8217;re already spinning multiple plates, and seemingly insignificant admin tasks such as removing old plugins frequently get pushed back to another day. It&#8217;s not urgent, right?\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">But every third-party plugin on your site is another &#8216;door&#8217; hackers can use to access your admin area and customer data. Every unnecessary plugin adds vulnerability, with no benefit.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>What happened to Master of Malt\u003C/strong>\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Back in September, well-established and award-winning online spirits retailer Master of Malt had to tell its customers that their names, email addresses, phone numbers and addresses had been exposed. This is a horrible experience for any business, made worse in this case by the fact that Master of Malt had done nothing wrong.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Master of Malt wasn&#8217;t the target of the hack, and neither was BigCommerce &#8211; the platform its shop runs on. The attackers had stolen the key for a single third-party app, Ribon, which is installed on hundreds of shops to improve the shopping experience, and used it to reach their customer data.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>Could Master of Malt have spotted the breach before it affected customers?\u003C/strong>\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">As the stolen key belonged to the Ribon app rather than to Master of Malt, only the app&#8217;s developer or BigCommerce could have noticed it being misused. The download didn&#8217;t trigger any alert for Master of Malt.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">This just goes to show that you can neither constantly monitor nor fully control third-party add-ons, which is why keeping only the ones you really need is crucial.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>Are plugins bad?\u003C/strong>\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Almost all online shops rely on plugins for some things. They allow lots of desirable features, such as reviews, subscriptions and gift cards, to be added to your shop at an affordable price. Often, they&#8217;re well built and maintained, and add genuine value to your site.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">On some setups, such as WooCommerce on WordPress, it&#8217;s easy to end up with dozens.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Plugins are where most of the risk sits. In 2025,\u003Ca href=\"https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/\"> Patchstack\u003C/a> found 91% of new WordPress security flaws were in plugins. WordPress itself had only six.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Each plugin is made by a different company and updated on its own schedule. This can cause two main problems:\u003C/p>\n\n\n\n\u003Cul class=\"wp-block-list\">\n\u003Cli>\u003Cstrong>Security.\u003C/strong> A single plugin that stops being updated by its developer leaves a vulnerability, even if you&#8217;ve followed security advice to a tee everywhere else on your site.\u003C/li>\n\n\n\n\u003Cli>\u003Cstrong>Conflicts.\u003C/strong> Updating one plugin can break another. Sometimes this just means the styles or animations on your site don&#8217;t appear quite as they should, but sometimes it leads to bigger issues, like your checkout no longer working &#8211; with no obvious point of failure.\u003C/li>\n\u003C/ul>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">None of this means plugins are inherently bad, but it does mean that the more you use, the more likely you are to run into a problem. The benefit of each plugin must outweigh the risk it introduces.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>Your 20-minute task\u003C/strong>\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Once Ribon had been removed from its site, this is exactly what Master of Malt did next: it started checking all the plugins and add-ons connected to its shop, and limiting what each one can reach. Whatever your shop runs on, you can protect yourself by doing the same today, and regularly going forward.\u003C/p>\n\n\n\n\u003Col class=\"wp-block-list\">\n\u003Cli>\u003Cstrong>Look in detail at every plugin and add-on.\u003C/strong> Make sure you understand what each one does. This includes everything on your plugin, add-on and theme pages, as well as anything connected externally, like accounting or email software.\u003C/li>\n\n\n\n\u003Cli>\u003Cstrong>Check that each one is being maintained.\u003C/strong> Well-maintained plugins are usually updated regularly. If one hasn&#8217;t been updated in the last six months, you should question whether it&#8217;s still safe to trust.\u003C/li>\n\n\n\n\u003Cli>\u003Cstrong>Delete what you don&#8217;t use.\u003C/strong> Make sure you delete it rather than just deactivating it, as a dormant plugin&#8217;s files will remain on your site.\u003C/li>\n\n\n\n\u003Cli>\u003Cstrong>Keep the rest up to date.\u003C/strong> Take a backup first in case of conflicts, and check now and then that your\u003Ca href=\"https://www.grizzlyware.com/blog/cyber-security-for-small-businesses-nine-things-that-cost-nothing\"> backups\u003C/a> actually work.\u003C/li>\n\n\n\n\u003Cli>\u003Cstrong>Make it a recurring event.\u003C/strong> Add a reminder to your calendar to do this again in a few months&#8217; time &#8211; six at the most.\u003C/li>\n\u003C/ol>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">Twenty minutes of your time every few months can prevent big problems in the future.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>Fewer is simpler\u003C/strong>\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">A shop with a few well-chosen add-ons is much easier to manage than one with thirty. This is one of the things we weigh up when choosing a platform, and part of the reason we build new eCommerce sites on \u003Ca href=\"https://www.aerocommerce.com/\">Aero Commerce\u003C/a>. A lot of the essentials come as standard, and we can build many of the rest in-house, which makes monitoring easier and reduces the chance of conflicts.\u003C/p>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">But a tidy, up-to-date shop on any platform is in good shape, and that can be achieved and maintained using the check above.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>Need a hand?\u003C/strong>\u003C/h3>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">If your plugin list has grown longer than you&#8217;d like, or updates have become something you dread, our\u003Ca href=\"https://www.grizzlyware.com/blog/business-process-audit\"> free process audit\u003C/a> can take a look and tell you honestly what needs doing &#8211; if anything. Call us on 01637 222001 or\u003Ca href=\"https://www.grizzlyware.com/contact-us\"> get in touch\u003C/a>.\u003C/p>\n\n\n\n\u003Ch3 class=\"wp-block-heading\">\u003Cstrong>Sources\u003C/strong>\u003C/h3>\n\n\n\n\u003Cul class=\"wp-block-list\">\n\u003Cli>\u003Ca href=\"https://www.teiss.co.uk/news/cyber-attack-on-ribon-compromises-bigcommerce-impacts-master-of-malt-18201\">teiss: Cyber attack on Ribon compromises BigCommerce, impacts Master of Malt\u003C/a>\u003C/li>\n\n\n\n\u003Cli>\u003Ca href=\"https://www.masterofmalt.com/sorry/technical/\">Master of Malt: What happened &#8211; a technical explanation\u003C/a>\u003C/li>\n\n\n\n\u003Cli>\u003Ca href=\"https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/\">Patchstack: State of WordPress Security in 2026\u003C/a>\u003C/li>\n\u003C/ul>\n\n\n\n\u003Ch2 class=\"wp-block-heading\">Related articles\u003C/h2>\n\n\n\n\u003Cul class=\"wp-block-list\">\n\u003Cli>\u003Ca href=\"https://www.grizzlyware.com/blog/cyber-security-for-small-businesses-nine-things-that-cost-nothing/\">Cyber security for small businesses: nine things that cost nothing\u003C/a>\u003C/li>\n\u003C/ul>\n\n\n\n\u003Cp class=\"wp-block-paragraph\">\u003C/p>\n","https://blog.grizzlyware.com/wp-content/uploads/2026/10/pexels-dellsad-13672876-scaled.jpg","weak link",[15,19,23],{"id":16,"name":17,"slug":18},131,"cyber security","cyber-security",{"id":20,"name":21,"slug":22},132,"eCommerce","ecommerce",{"id":24,"name":25,"slug":25},133,"plugins",1791385196826]