WP Engine

Solutions
AgencyEnterpriseSmall & Medium BusinessMarketer
How WP Engine supports marketers.Benefits for marketers.Features that help you innovate.
Developer
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Explore Our Platform
Insights
Thought LeadershipTopics

Read articles, trends, and insights on these topics from leaders in marketing and technology.

Creative AgilityEnterprise PerformanceActionable IntelligenceEcosystem Integration
Resources

Access ebooks, whitepapers, webinars, and other knowledge from our ecosystem of digital experts.
Visit Resource Center.

Delivering a Slam Dunk Experience on WordPressEbook: The Ultimate Guide to WordPress Plugins15 Common WordPress Mistakes Agencies and their Clients Make
Case Studies
About
Our CompanyOur PlatformLatest News

Access the latest news from inside WP Engine.
Visit the Newsroom.

WP Engine Secures Strategic Growth Investment From Silver LakeWP Engine Unveils First WordPress Digital ExperienceWP Engine Expands Global Presence with New Office in Brisbane
Media Center

Get announcements and resources about WP Engine.

Press Releases
Careers at WP Engine
Pricing
Sales Questions?

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Compare Plans
Need Support?
Support DocumentationBilling HelpSupport

We offer support 24 hours a day, 7 days a week, 365 days a year. Log in to get expert one-on-one help.

Log in for support

Sales Questions

Contact Sales

Discover why organizations of all types and sizes choose WP Engine — and how it can benefit you.

Chat

1

I'm available right now to answer any of your questions!

Reply

Call

+1-512-201-4819

Contact

Send a message

Sign in
Sign in
Search

Search

Compare Plans
Call Sales +1-512-201-4819
Menu
AgencyEnterpriseSmall & Medium BusinessMarketers
How WP Engine supports marketers.Benefits for marketersFeatures that help you innovate.
Developers
How WP Engine supports developers.Benefits for developers.Features that help you move faster.
Our PlatformPricingResource CenterOur CompanySolution CenterThought LeadershipDocumentationCareers

The Heartbleed Bug is Not Affecting Sites Hosted by WP Engine

Jason Cosper 4.8.2014

Heartbleed bugWe want to reassure our customers that the current version of the Heartbleed bug, a recently discovered high priority security vulnerability, is not affecting sites hosted by WP Engine.

At WP Engine we take WordPress security very seriously.  We conduct regular security assessments and work to address security vulnerabilities to protect our customers and their data. We also conduct ad hoc tests if a security threat, such as the Heartbleed bug, is brought to our attention.  Accordingly, our security engineers have tested for Heartbleed and confirmed that customer sites and our User Portal are not vulnerable as of the date of this post.

The Heartbleed bug is currently impacting the open source software OpenSSL, which is used to encrypt web communications. The vulnerability can allow attackers to access encrypted data and communications. Fortunately, the version of OpenSSL we use here at WP Engine is not either of the versions impacted by the vulnerability.

You can use this tool to check whether your site is vulnerable to the Heartbleed bug. If you have reason to believe your site is vulnerable, you can contact our Support Team via Live Chat in the User Portal.

Please rest assured that our security team is monitoring the situation.

More WordPress news from WP Engine

We’re Updating All WP Engine Sites to WordPress 3.8.2An Important Jetpack Plugin Security Update

Comments

  1. Conor Gilsenan says

    April 9, 2014 at 9:55 am

    Can you please provide more details for the tech community who will understand them? For example, which specific version of OpenSSL do you actually use? If you used any compromised version from “Apr 18 13:21:31 2012 GMT” onward, then you must assume that your private key was compromised at that point even if you switched to a patched version after the fact. Your SSL cert is 2 years old and that is the same timeframe which the Heartbleed Bug has been in the wild. Without knowing which versions of OpenSSL you have used within the last 2 years with that certificate, you should be cautious and regenerate your certificates now as a precaution.

    Please follow up with another blog post saying that the certificates have been regenerated as a precaution.

    https://lastpass.com/heartbleed/?h=wpengine.com

    Reply
    • Jason Cosper says

      April 9, 2014 at 11:33 am

      Our current and all previous customer facing versions of nginx have been compiled against a fully patched and secure version of OpenSSL 0.9.8. At no point has the Heartbleed bug been an issue, so certificates do not need to be regenerated.

      Thanks for the concern, Connor!

      Reply
  2. Cody says

    April 9, 2014 at 12:09 pm

    Just wanted to tell you that you did a great job staying out in front of this! I started a live chat only to look at your twitter account/this blog and see my concern was unnecessary! Excellent proactive work as always 🙂

    Reply
    • Jason Cosper says

      April 9, 2014 at 12:33 pm

      Glad you appreciate it, Cody! Just trying to do our best to look out for everyone who places their trust in us.

      Reply
  3. Jason says

    April 10, 2014 at 12:50 pm

    Sorry for being uninformed on this, but what if our SSL cert is from a 3rd party (such as verisign/symantec)? Is my site on WPengine still secure?

    Thanks for helping me understand.

    Jason

    Reply
    • Jason Cosper says

      April 10, 2014 at 6:58 pm

      Because our servers weren’t leaking any information to begin with, your certificate should be totally fine!

      Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Subscribe

    Subscribe to our blog to get great tips for your WordPress site.

  • Favorite Tweets by @wpengine
  • Sign In

    Solutions

    • Agency
    • Enterprise
    • SMB
    • Marketer
    • Developer

    Insights

    • Blog
    • Torque
    • Velocitize

    About

    • Our Company
    • Leadership Team
    • Our Platform
    • Careers
    • Affiliates
    • Contact
    • Legal
    • Newsroom
    • Privacy Policy

    Resources

    • Resource Center
    • Documentation
    • Solution Center
    • Find an Agency

    WP Engine

    504 Lavaca Street, Suite 1000
    Austin, TX 78701

    Sales

    +1-512-201-4819
    [email protected]
    7am–7pm CST

    Billing

    [email protected]

    • Facebook
    • Twitter
    • LinkedIn
    • YouTube
    • Instagram
    • RSS
    © 2013—2025 WPEngine, Inc. All rights reserved.
    WP ENGINE®, VELOCITIZE®, TORQUE®, EVERCACHE®, and the cog logo service marks are owned by WPEngine, Inc.