Hey @jvanderlinde,
Thank you for reaching out to us here. We take security issues very seriously. We perform consistent security tests including Penetration testing. The plugin also does not have any functionality built in to create administration users (or any user at all). It is unlikely that this situation was caused by our plugin, and I say this based on there being no other report of this type of issue on our end (normally such a security flaw is widespread and malicious attackers will take the opportunity when a free plugin has a security vulnerability.) That being said, if the issue originated in our plugin we will need additional information so we can address this directly and quickly.
The plugin certainly is not abandoned and is recently updated to fit the changes of the Twitter API.
Our plugin being related to your case could be due to:
- There was another type of security breach on the site, and malicious files were added to our plugin, or our plugin files were edited with malicious code.
- The plugin was downloaded from a source other than www.remarpro.com or smashballoon.com (we do not provide any versions of the plugin in any other location and do not approve third-party resale).
- The plugin could have been heavily out of date and may have old undetected security issues.
And of course, undetected security issues in the current version. If you have any further suspicion of the plugin causing these issues, please send us a security vulnerability report here. If you do so, please include as much information as possible such as the plugin version at the time, what event led up to the situation, how they were resolved, and any logs that would show that code in our plugin was responsible for creating administration. In case we can determine that there was a security flaw in our plugin, we will immediately address it and keep our users up to date.
We appreciate your concern here, as our users’ security is of utmost importance. If you would like further assistance or had issues with the plugin itself, let us know in our contact form and we would be happy to dig into other issues with the plugin if you should be so inclined.
Many thanks,
Joel