A compromised system, security disaster...
A lesson in how not to deal with a compromised website! Their system gets compromised and sends out an email notifying of a critical update (Jetpack advised of critical vulnerability the day before so an update was expected!)... the link in the email was to a third party website which was very close to theirs (extra i in the name - monsteriinsights.com) easy to miss, very close to original and from a valid inbound email at a time when a security update was due - fortunately the website had been disabled or I could have easily installed the compromised update... when it didn't load - I fixed the URL (I assumed it was a typo on their end in a rush to get out the email) only to see their "we're down for maintenance due to compromise" website message and a warning not to install updates from third party sites (nothing to indicate THEIR email included that third party link!), and if you didn't visit their site during that period you wouldn't know. No followup email to advise of the issue or check that you hadn't downloaded the compromised update. And still no patch for the critical vulnerability after almost a week. So a compromised plug-in, no update, no communication and their system gets compromised and they don't advise or follow up with anyone. Very difficult to trust these guys ever again. Incredibly poor handling.








