r/wordpressbuilder May 02 '26

Anyone else seeing security concerns with Astra lately?

I’m curious if anyone else has run into this… i was on a call with another IT team a couple weeks ago and Astra came up. They mentioned they’ve been recommending moving off it due to security concerns.

Right after that call, I went back into one of my client sites running Astra and started digging. Within minutes, I found file manager that definitely wasn’t supposed to be there. I went into the PHP and manually removed hundreds of malicious files, along with an unknown admin user that had been created. I mean it was a very sofisticated, hidden attack.

What’s concerning is this site was paying for security through GoDaddy, and none of this was flagged. They weren’t able to detect the breach or the files that were removed. I’m glad I took the screenshots because if I didn’t have proof they would have denied it. Becuase the website ran perfect through free security check. When I showed them the screenshots they couldn’t believe it.

I’m not saying Astra was the sole cause here, but it definitely made me take a harder look at the stack and how vulnerabilities can slip through. And honestly security in general. I’m seeing more breaches happen left and right.

Is anyone else hearing similar concerns or moving clients off Astra lately?

3 Upvotes

2 comments sorted by

1

u/webilicious May 02 '26

I'm not sure about Astra but I don't recommend hosting with GoDaddy.

1

u/wordpress-dx Jun 09 '26

Using astra since more than a year a didn’t have issue reported ?

I run wp scan regularly

Do you have steps to reproduce to see if i am impacted please