Hello Joomshaper-Team
Unfortunately, I can only agree with all the other posts in the various threads on this topic.
About a month ago, I already shared my thoughts here in the forum regarding the – to put it mildly – “leaving room for improvement” handling of the security vulnerabilities in PageBuilder and Helix at that time: https://www.joomshaper.com/forum/question/45651
I received positive feedback from JoomShaper in response, which gave me hope that the handling of such security incidents would be reevaluated in the future.
Now four weeks have passed and unfortunately, NOTHING has changed with the next security incident. I have absolutely no understanding of why version 6.7.2 which would initially address only the security vulnerability hasn’t been released long ago.
I manage more than 60 client websites using SP Page Builder and have been waiting since yesterday by checking for updates nearly every hour for this version to be released. Even more problematic is the announcement that the update was supposed to be released "very soon." Trusting that, I initially refrained from securing all client sites with the manual workaround. I had to catch up on that today, since far too much time has passed by now.
Hence my serious question to JoomShaper: WHY?
Why are you making your customers – including agencies responsible for dozens of client websites – wait in a situation like this, thereby forcing them to leave their websites unprotected despite a known critical security vulnerability for several days?
What if websites have already been compromised? With a known critical security vulnerability, every hour counts! In a situation like this, none of your clients care whether the new version also includes possibly additional features or bug fixes.
Please release the security fix. Immediately. Everything else can come AFTER that.
Following this latest incident, I’ve now reached a point where I’m seriously considering implementing future projects with other providers and gradually phasing out JoomShaper.
After many years of collaboration, this is not a decision I’m considering lightly. But in my view, handling critical security vulnerabilites in this manner is simply unprofessional.
It’s stressful. It takes time. And ultimately, it costs money especially if such handling leads to further and possibly even greater damage.
With disappointed regards,
Steve