We take measures to maintain the best possible security and performance on your Wordpress sites. These measures include ensuring the themes and plugins being used on sites are kept up-to-date and create no vulnerabilities.
Below we explain what is considered in determining whether a theme or plugin should be disallowed.
Allowed Themes
Nearly all WordPress themes are compatible, however, some cache-intensive themes may need modifications to work as expected.
Allowed Plugins
We discourage the use of cache plugins on our platform as we already handle caching via NGINX. Beyond caching, we also disallow a small list of plugins that can pose performance problems for our servers, such as high disk and/or database usage.
There are a few other situations which may cause a plugin to be disallowed, such as:
- Ambiguity in developer oversight and/or the plugin’s function.
- We already provide a secure way of doing what the plugin intends to, making the plugin redundant and problematic for our platform.
- It has been revoked on wordpress.org due to unpatched security vulnerabilities.
Aside from being disallowed in the list below, safeguards in our hosting configuration make some plugins incompatible if they are using disabled PHP functions. Things such as proc_open, shellexec, etc. are not allowed for web transactions.
You can view the current list of banned plugins below.
Banned Plugins
Stats Plugins
***These plugins are resource hogs and we suggest using Google Analytics instead.
counterize
firestats
gosquared-livestats
newstatpress
simple-stats
statpress
statpress-reloaded
statpress-visitors
stats
track-that-stat
visitor-stats-widget
vsf-simple-stats
wassup
wp-postviews
wp-slimstat
wp-statistics
Backup Plugins
***These plugins conflict with our own robust nightly backups to Amazon S3.
akeebabackupwp
automatic-wordpress-backup
backup
backupbuddy
backupbuddy2.2.33
backupcreator
backup-db
backup-to-dropbox
backupwordpress
backupwp
backwpup
dbc-backup
pressbackup
simple backup
simple-wordpress-backup
snapshot
snapshot-backup
the-codetree-backup
total-archive-by-fotan
total-backup
vm-backups
wordpress-backup
wordpress-backup
wordpress-backup-to-dropbox
wordpress-database-backup
wp-complete-backup
wp-db-backup
wponlinebackup
wponlinebackup
wp-s3-backups
wp-time-machine
xcloner-backup-and-restore
Database
adminer
portable-phpmyadmin
wp-database-optimizer
wp-dbmanager
wpdbspringclean
wp-optimize
wp-phpmyadmin
Caching Plugins
cache-images
db-cache-reloaded
hyper-cache
wp-file-cache
Miscellaneous
backjacker
broken-link-checker
delete-all-comments
disable plugin updates
display-widgets
exploit-scanner
facebook
google-sitemap-generator
hcs-client
hello.php
pipdig (p3)
repress
search-unleashed
sendpress email marketing
smestorage-multi-cloud-files-p
timthumb-vulnerability-scanner
updraftplus
viberspy-pro
wp-mailinglist
wp-maintenance-mode
youtube-sidebar-widget
xml-sitemap-feed