As a fellow shared hosting engineer I pretty much agree with [1] and [2], and for [3] I also feel your pain, but we don't mess about any more arguing the toss.
We now scan for egregiously out of date WordPress installs and warn customers that their site will be at risk of being disabled if they don't upgrade to the latest version. If after a couple of days we see no action then we pull the site.
If we detect sites serving dodgy links then they're instantly shut down until the customer can prove they've secured the site.
In 99.9% of cases our customers are happy we do this because they're mostly businesses and serving malware damages their brand and reputation. We do get the occasional user who refuses to co-operate, and if they do we serve them notice to take their business elsewhere.
If we detect sites serving dodgy links then they're instantly shut down until the customer can prove they've secured the site.
We have a similar approach to this actually. The exception being that we clean the malware ourselves, sadly. I tried to say is a bad idea multiple times, but no luck. What makes things worse, we have a few "spoiled" clients that keep getting their websites hacked (there's 3 such WordPress and Joomla development resellers) and they started expecting us to clean their websites. Sigh
Also, I tried to argue a few times that we do the scan-and-warn thing, but I got turned down with the counter argument that it would generate more backscatter on our support department than it would be worth it.
Comments
As a fellow shared hosting engineer I pretty much agree with [1] and [2], and for [3] I also feel your pain, but we don't mess about any more arguing the toss.
We now scan for egregiously out of date WordPress installs and warn customers that their site will be at risk of being disabled if they don't upgrade to the latest version. If after a couple of days we see no action then we pull the site.
If we detect sites serving dodgy links then they're instantly shut down until the customer can prove they've secured the site.
In 99.9% of cases our customers are happy we do this because they're mostly businesses and serving malware damages their brand and reputation. We do get the occasional user who refuses to co-operate, and if they do we serve them notice to take their business elsewhere.
We have a similar approach to this actually. The exception being that we clean the malware ourselves, sadly. I tried to say is a bad idea multiple times, but no luck. What makes things worse, we have a few "spoiled" clients that keep getting their websites hacked (there's 3 such WordPress and Joomla development resellers) and they started expecting us to clean their websites. Sigh
Also, I tried to argue a few times that we do the scan-and-warn thing, but I got turned down with the counter argument that it would generate more backscatter on our support department than it would be worth it.