Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

matt819

(10,749 posts)
Fri Jul 6, 2012, 06:17 PM Jul 2012

Question for web developers/managers

I have a business website, with the info portion on WordPress and the shopping cart on Pinnacle (site developed 3 yrs ago).

Site was hacked a month ago, resulting in "site compromised" search results on Google. Site visits down by half, web sales down to almost zero - never were high, but now close to zero.

Site is now malware-free (tim thumb hack), but search results still showing site compromised, despite Google's assertion that once they know a site is clean, they will clean up their search results. It's been 3-4 weeks, still showing up as site compromised.

My developer is charging me about $675 for the clean up, despite the fact that neither WP nor Pinnacle had been updated. The claim is that I must have uploaded content on an unsecure Wifi connection (I didn't). This is on top of my monthly cost of $179 for hosting, e-mail, etc.

Are these charges standard in the event of a hack, i.e., cost of doing business?

I am looking for a new developer, who will undoubtedly build on another platform - he's mentioned OpenCart. I'm afraid to see what that's going to cost. By the way, site has about 30 "static" informational pages, and the store has several hundred products, and will probably remain under 500.

Any thoughts on platform?

Thanks.

7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Question for web developers/managers (Original Post) matt819 Jul 2012 OP
Spam deleted by EvolveOrConvolve (MIR Team) Expertsfromindia Jul 2012 #1
$179/mo seems high DaveJ Jul 2012 #2
Spam deleted by pinto (MIR Team) Expertsfromindia Aug 2012 #3
That $179 a month seems high for the size and traffic of your site Merlot Aug 2012 #4
Website, DB, & Software Developers trishnikolic Aug 2012 #5
What to do joojooba Aug 2012 #6
Spam deleted by hlthe2b (MIR Team) sbglobal2013 Sep 2012 #7

Response to matt819 (Original post)

DaveJ

(5,023 posts)
2. $179/mo seems high
Wed Jul 18, 2012, 09:54 AM
Jul 2012

I'm not sure how much traffic you have, and maybe others will disagree. I wonder what others think about a $179/mo plan vs a $12/mo plan. If you have less than 10,000 hits per month it seems high to me.

Have you communicated your concerns with your developer, prior to dropping him? $675 seems fair if your developer needs to spend 15+ hours on the cleanup. But I would expect the developer to communicate with you in a more professional manner. If that's not happening then get someone who will. If that's possible... I don't know any developers who communicate well, personally.

I don't know how to get the Google issue fixed, or anything about tim thumb. I hope the Google issue has been fixed, that's horrible.

Response to matt819 (Original post)

Merlot

(9,696 posts)
4. That $179 a month seems high for the size and traffic of your site
Mon Aug 6, 2012, 06:17 PM
Aug 2012

If you're paying that to your developer they've got quite a markup. Maybe that includes maintenance or troubleshooting?

OTOH, the $675 to put your site on a new platform sounds reasonable to me. But unless your developer can explain to you why you got hacked and what safeguards they are putting into place, it seems kind of useless. Also, if you tell them that you didn't upload on an unsecure wifi, and they are still trying to blame you, that does not sound good.

I'm not a big fan of open cart, they charge or their service and are not very flexible. How much work are you doing yourself on the site? do you work with the CMS? I usually set up static pages and shopping carts through the same platform, and let the shop owner add the products to the back end. If a developer sets up a site for you and you hire an assistant to manage the products you'd probably do better than having the developer do the whole thing, unless of course, you just want it done with as little activity on your part as possible.

To set up a new site, probably $1500 to 2500 depending on a lot of variables.

trishnikolic

(20 posts)
5. Website, DB, & Software Developers
Thu Aug 23, 2012, 05:01 AM
Aug 2012

i would like to suggest you generate a new webmaster code and sitemap for your site. Submit a code into the website and sitemap.xml into Google Webmaster. You need to verify your site also on Google Webmaster once the code get installed

joojooba

(2 posts)
6. What to do
Sun Aug 26, 2012, 06:38 AM
Aug 2012

my wordpress blog was also once hacked... I checked my logs and what I see on daily basis that some script kiddies are trying to find every possible hole in my system by guessing, (like checking for online viewable passwd files.. trying to upload stuff) unformtunately some plugins are not secure and they are not updated so they might be a security risk - one plugin was insecure and someone uploaded a php virus to my blog and they changed the front page for googlebot only to display viagra stuff, for normal users the page was clean. the purpose for this was to get some backlinks.


at first I didnt know what to do, but then I did the following:
- check if all of your php files have a web only group. (not root!)
- chmod 777 or 775 only for files you really are sure they are secure and need the rights.
- you could write a script which works in the background and deletes files which are uploaded by the hackers.
- install "anti virus" plugin so it can check if some of your files on your blog are infected.

Latest Discussions»Retired Forums»Website, DB, & Software Developers»Question for web develope...