We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 18262
    • 2 Posts
    I am curious how others either discuss with their clients, or put in their contracts, about security updates / software maintenance of Modx after a site has been handed over? Ideally any client that I use modx or other php based tool for would pay me x amount of hours per month to maintain and update the code as needed. But for those clients who do not opt for a monthly maintenance contract I am curious how you let them know they need to keep an eye on security updates. Do you use disclaimers in your contracts?

    Thanks
    Marc
      • 25307
      • 114 Posts
      I’d suggest at the very least you instruct your client to register for email notification of security updates.
        • 6726
        • 7,075 Posts
        You can also have them displayed on the admin home page using the kRSS module

        The security feed is coded directly as one of the default kRSS feed smiley

          .: COO - Commerce Guys - Community Driven Innovation :.


          MODx est l'outil id
          • 20044
          • 33 Posts
          Quote from: marcray at Sep 27, 2007, 10:28 AM

          Do you use disclaimers in your contracts?


          I’d like to rephrase that: If you do offer security updates for a fee, do you guarantee that the site will not be compromised? I don’t have any clients (yet) for whom downtime would be very costly, so I don’t mention any security risks because that would only make them nervous, given their (usually) lack of IT-skills and the "internet==danger" sentiment nowadays. But IMO the only thing you can do with clients who make their money online is to always use a disclaimer and put in writing what exactly you will do (best effort) to help secure the site and that anything else is not your responsibility. Of course you do instruct them about what they should do themselves to keep their site the most secure.