Start a Project

Polyfill.io Vulnerability: How Wibble Rapidly Secured our managed WordPress sites

Paudie – Wibble web design and web development. Belfast
By Paudie Fearon 1 July, 2024 • 5 MIN READ
Pollyfill.io – Wibble's rapid response to the vulnerability

fully managed WordPress websites

At Wibble, we manage hundreds of WordPress websites for a diverse array of web design clients and we understand the importance of protecting their digital assets. Our commitment to security is proactive and constant, ensuring that we stay ahead of potential threats. We continuously monitor for vulnerabilities, conduct regular security reviews and implement best practices to safeguard our clients’ data and online assets. Our recent swift response to the Polyfill.io vulnerability exemplifies our dedication to maintaining the highest standards of security and reliability, ensuring our clients can focus on their core business without worrying about their website’s safety.

This is a prime example of why people rely on Wibble to host and manage their WordPress websites.

Polyfill.io security vulnerability

Recently, the web development community was alerted to a critical vulnerability in Polyfill.io, a popular JavaScript library used to ensure cross-browser compatibility. This security flaw, which became known to us on June 27, 2024, allowed attackers to inject malicious code, posing a significant threat to websites relying on this service. This vulnerability had the possiblity to impact hundreds of our sites and an estimated 4% of all websites in the world.

Timeline of Our Response

June 27, 2024

  • Wibble becomes aware of the Polyfill.io vulnerability through security alerts and industry news
  • Our security team initiates a comprehensive audit of all client websites to identify any use of Polyfill.io
  • After identifying affected sites, we formulate a detailed action plan to mitigate the risk
  • The plan is finalised and communication is sent to our entire dev and support team to ensure a prompt response to the issue

June 28, 2024

  • Our development and support team begins implementing the fixes across all identified sites.
  • All updates are pushed, and references to the compromised version of Polyfill.io are removed.
  • Final security checks are conducted to ensure all sites are secure and functioning correctly.

As you can see above we move promptly and utilised all our web development and support team members to get any references to Pollyfill.io removed and tested.

Further security precautions we have in place by default

By default, we use Cloudflare as our DNS host for all our client websites – security, site speed, accessibility to records and speedy DNS propagation are just some of the features that see us insist on its use for sites. Cloudflare had also moved quickly to mitigate the risk from this security vulnerability.

Cloudflare has introduced a proactive measure to safeguard websites using their services. By using Cloudflare as your DNS, we gained access to an automatic JavaScript URL rewriting service that replaces any Polyfill.io links with a secure mirror hosted by Cloudflare on cdnjs. This mitigates the risk of malicious code injection without disrupting site functionality. We didn’t just rely on this and also removed all references to Polyfill.io in our code to ensure that the fall back security measure by Cloudflare wasn’t actually required – but it’s good to have it there. Also, a small number of our clients, mostly government department or self hosted DNS sites, don’t use Cloudflare so we had to roll their fixes out with speed.

Our Approach to managed WordPress Security

Pollyfill.io – Wibble's rapid response to the vulnerability

Proactive Monitoring: Our team constantly monitors for security vulnerabilities and potential threats. This vigilance allowed us to respond quickly to the Polyfill.io issue.

Comprehensive Audits: As soon as the vulnerability was identified, we conducted thorough audits of all client websites. This step was crucial in assessing the extent of the risk and ensuring no site was overlooked.

Swift Implementation: We understand the importance of rapid response. Within 24 hours, we had a plan in place, communicated with all team members and implemented the necessary fixes.

Client Communication: Transparency with our clients is key. We have been contacted today by a few clients around this vulnerability and it was nice to inform them that the fix was already in place. This blog post forms part of our communication plan to let clients know that we are all over this issue.

Conclusion

The Polyfill.io vulnerability was a significant challenge but it also showcased Wibble’s commitment to security and swift action. Our team’s ability to audit, review and push fixes within 24 hours highlights our dedication to protecting our clients’ digital assets. We continue to prioritise security in all our projects, ensuring our clients can trust their websites are in safe hands.

For more information on our web design and web development services and how we can help protect your website, please contact us.


Share this blog post

Paudie – Wibble web design and web development. Belfast

Paudie Fearon

More from author