If you’ve received an email warning about a security vulnerability on your website, stay calm. These alerts—often from Netcraft or other security monitoring services—are designed to help. They typically highlight risks from outdated software and suggest fixes. Often, the solution is as simple as updating your WordPress version, which is quick and easy with Ecenica.
Important: Never reply to these emails or provide login details.
Legitimate security services will never ask for your passwords or access credentials.
Never share your Ecenica usernames, passwords, or confidential information.
What Are These Emails?
These emails are automated security alerts, often based on publicly available information. They scan websites for outdated software versions and notify site owners if a known vulnerability exists.
A typical email might:
- Mention a specific security vulnerability (e.g., SQL Injection, Cross-Site Scripting).
- Reference a CVE (Common Vulnerabilities and Exposures) number.
- Suggest updating your website software to fix the issue.
- Provide links to official documentation for resolving the problem.
Step 1: Check If the Email Is Genuine
Before taking any action, confirm the email is legitimate. Follow these steps:
- Check the sender’s email address – Security notifications should come from official sources like
netcraft.com, not random or misspelled domains. Be cautious of emails from free providers like Gmail or Yahoo. - Look for spelling and grammar errors – Many phishing emails contain mistakes or awkward phrasing.
- Check the links – Hover over any links (without clicking) to see the destination URL. Official security emails should link to recognized sites like
wordpress.orgornetcraft.com. - Do not download attachments – Security warnings rarely come with attachments. If one is included, it’s likely a scam.
- Search for the issue online – If the email references a vulnerability (e.g., CVE-2022-21661), verify it on official sources like NIST’s National Vulnerability Database.
Step 2: Be Aware of Fake “Bug Bounty” Emails
It’s important to distinguish between legitimate security alerts and emails from third parties claiming to have found a security flaw and requesting payment for details (often referred to as “bug bounty” emails).
- These emails may come from individuals or organizations claiming they have discovered a vulnerability on your website.
- They often request money in exchange for details of the alleged issue.
- Some even threaten to disclose the “vulnerability” publicly if you do not respond or pay them.
How to Handle Bug Bounty Emails:
- Treat them with caution. Many of these emails are scams or attempts to extort money.
- Do not reply, engage, or make payments. If someone has genuinely found a security issue, they should report it responsibly without demanding payment.
- Forward the email to Ecenica Support. We can investigate and confirm whether there is any real concern.
- Verify your site’s security yourself by checking for updates, scanning for vulnerabilities, and ensuring your hosting protections are active.
Step 3: Keep Your Site Secure
If your site is hosted with Ecenica, there’s a very high chance your site is not vulnerable to the security alert highlighted in the email. This is because as an Ecenica user, your website is protected by Ecenica SiteProtect, which actively blocks attacks like SQL injection, providing strong protection even if a vulnerability exists in outdated software.
That said, following best practices is always recommended:
- Update Your Website – Ensure WordPress, plugins, and themes are up to date. Updating regularly keeps your site secure.
- Enable Automatic Updates – This ensures you always have the latest security patches applied.
- Monitor Your Website – Regularly review your security settings and keep backups in case of issues.
- Use Strong Passwords and 2FA – Ensure admin accounts use strong, unique passwords and enable two-factor authentication.
Step 4: Netcraft Isn’t Always Accurate
While Netcraft is a well-known security monitoring service, its automated system can sometimes generate false positives. These alerts are based on publicly available data, which can be stale, outdated, or incomplete.
Why Does This Happen?
- Old Information: Netcraft may detect a past vulnerability in a website that has already been patched or mitigated.
- Static Site Snapshots: It sometimes flags static HTML versions of previously active WordPress sites, even when no dynamic scripts are running.
- No Context on Active Security Measures: The system does not account for active malware and security protection in place, such as Ecenica SiteProtect, which blocks common attack vectors.
Netcraft Can Retract Reports
Netcraft can sometimes send follow-up emails retracting previous vulnerability notices when they determine a site is not at risk.
If you’re unsure whether a report is valid, feel free to reach out to Ecenica Support, and we can verify your website’s security.