- Job title
- Clinic manager
- Sector
- Electrical-electronics
- Organization type
- early-stage startup
- Joined
- Dec 2023
- Message
- 128
our wordpress sites got attacked three times each time the hacker got in via an 'outdated plugin'. currently there are 35 plugins installed, 10 show as outdated. i'm scared to update them all (in case the site breaks). but not updating is risky too. how do i decide?
here's the thing: some plugins haven't had an update in 2 years. i switched to the new version, and the site got blacklisted. the IT manager said 'test it on a staging server' but i don't have a staging server, it's expensive to set up. any other solutions?
another question: should i pay for 'paid support' for plugins? how reliable are free plugins? should i disable ready-made plugins like wp-cache? is it better to use all of them or are minimal plugins safer?