Rescan Remote Storage
-
For years I used updraftplus as my go-to for client backups. The plugin was synced with Google Drive and it saved me several times, especially when clients would use subpar hosts prone to issues or crashes. I always considered this to be an essential plugin for ANY wordpress install.
A while back, they added a free feature to rescan remote storage. Using this plugin with multiple client websites, any website can see every single backup. Website A can grab the SQL file for Website B and download it locally. A few people on the support forms have complained about this feature but it has always be discussed as an issue on the Google Drive end. However, the feature could just an easily be removed completely from the updraft core. Maybe other users have found this to be useful, but on my end it’s a massive security concern. The amount of data that could be exported through these databases in massive.
If a single website was hacked, or a ex-employee with admin login uses the rescan remote storage, the damage would be overwhelming. I’ve spent the last two days moving every single client website off of Updraftplus and to a seperate backup system that doesn’t have this feature.
I understand that the paid Google Drive addon allows you to create seperate folders and that’s fine. I’m just not a big fan of adding features like this that suddenly require you to purchase a plugin for multiple websites or in my case, hundreds.
Hopefully this gets adjusted in the future as the plugin authors have created a great plugin, and you can tell they take great pride in their work.
- The topic ‘Rescan Remote Storage’ is closed to new replies.