Behind the Scenes: A Security Review of Unpause
Behind the Audit

Behind the Scenes: A Security Review of Unpause

4 min read
Jorg

Jorg

Founder & CEO

When we build or review websites, we don't just look at design or performance. We also pay close attention to security.

Sometimes, being curious pays off.

When Unpause launched, we spent some time exploring the website. Partly because we're fans of what they're building, and partly because we can't help looking at websites through a technical lens. Design, performance, accessibility, security... it's simply how our brains work.

During that review, we noticed something that deserved immediate attention. Instead of publishing it or keeping it to ourselves, we contacted the team directly. They resolved the issue, and only now, months later, are we sharing the story.

Not because of the vulnerability itself, but because it shows how responsible disclosure should work.

A Recently Discovered Vulnerability

While reviewing the website, we noticed it was running a version of JetEngine that had recently been linked to a publicly disclosed Reflected XSS vulnerability. On its own, that was already worth addressing. Combined with an exposed WordPress administration endpoint, it created an unnecessary security risk for a website that had only just launched.

These situations are more common than most people realise. New vulnerabilities are discovered almost every week, and even well-maintained websites can briefly become exposed before updates are available or applied. That's exactly why keeping an eye on security advisories is just as important as keeping your website up to date.

Giving People Time to Fix Things

The moment we found the issue, there was never any question about publishing it. The only responsible option was to contact the team privately and give them the opportunity to investigate and resolve it first.

That's exactly what happened. They responded professionally, confirmed that the reported issues had been addressed, and thanked us for reaching out. Only after everything had been resolved did we decide to share this story. Responsible disclosure isn't about exposing mistakes. It's about helping prevent them from becoming real incidents.

It Was Never About Selling a Website

The email we sent wasn't a sales pitch. In fact, we even mentioned that if they wanted to keep their existing website, we'd happily help secure it free of charge. As fellow enthusiasts, seeing the platform succeed was more important than winning a project.

At the same time, we couldn't resist imagining what Unpause might look like if it were built from the ground up. So, purely for fun, we created a concept to explore that idea. It wasn't requested, and there were no expectations attached. Sometimes it's simply enjoyable to build something for people whose work you've followed for years.

unpause mockup

WordPress Isn't the Problem

Whenever a WordPress website gets hacked, the platform itself usually gets the blame. In reality, WordPress is one of the most actively maintained content management systems in the world. The problems almost always start elsewhere.

Themes, plugins, outdated software, and poor maintenance create the vast majority of security risks we encounter. A single vulnerable plugin can expose an entire website, regardless of how secure the core platform is.

Security isn't something you install once and forget about. It requires regular updates, monitoring newly disclosed vulnerabilities, and acting quickly when something needs attention. A secure website is rarely the result of luck. It's the result of consistent maintenance.

Jorg's 2 Cents

We didn't write this article to highlight a vulnerability or to criticise the choices behind Unpause. In fact, we deliberately waited until the reported issues had been resolved before sharing anything publicly. Responsible disclosure only works when the website owner gets the opportunity to fix the problem first.

What stood out to us wasn't the vulnerability itself, but the response. We reached out privately, the team replied professionally, and the necessary changes were made. That's exactly how these situations should be handled.

We also enjoyed creating a concept for the platform simply because we're fans of what they're are building. Sometimes contributing doesn't mean sending money or asking for work.

Sometimes it simply means sharing your expertise and hoping it helps someone build something even better.

More Articles.

Let's Build
your legacy

Start

Articles.