So I had to give the plugin company admin access to my WordPress site to diagnose a problem. Weeks passed by and I was looking around and realized, they also made a SFTP account credentials and had access to the kingdom through the back end. Make sure when you give someone access you also revoke any FTP or SFTP credentials as well. When you are done with their assistance. I should have known better and it is amazing how critical things we can overlook sometimes. (The plugin maker is a top plugin with close to 200k PURCHASES, they did not do anything nefarious, but based on stories I have heard, there are a lot of bad apples out there.
[ad_2]