44 votes

GoDaddy is sneakily injecting JavaScript into your website and how to stop it

9 comments

  1. meghan
    Link
    Disgusting. If you host with them, having HTTPS wouldn't even help with this... If this is true, I'd immediately switch any and all sites you might run through them.

    Disgusting. If you host with them, having HTTPS wouldn't even help with this... If this is true, I'd immediately switch any and all sites you might run through them.

    20 votes
  2. Vadsamoht
    (edited )
    Link
    I've had a similar issue in the past. I was using a Bluehost plan as a staging server for some webdev work I was doing at the time, and ended up pulling my hair out because some things just...

    I've had a similar issue in the past. I was using a Bluehost plan as a staging server for some webdev work I was doing at the time, and ended up pulling my hair out because some things just weren't working at all.

    Turns out, without notifying me they'd added some plugins to the wordpress part of the site as must-use (so they're forcibly loaded, are stored in a different directory in the filesystem and don't show up on the WP plugins list) - ostensibly for caching to make the site faster and reduce server load (which is BS anyway, because the server capability is part of what you're paying for) but from a quick look at the code there was some other stuff going on (including phoning home) that was causing issues with everything else.

    Never again will I be giving money to a company that pulls shit like that.

    12 votes
  3. annadane
    Link
    I frequently wonder how it is they justify things like this to themselves and I mean any company that engages in unethical behavior, not just GoDaddy. Obviously money. But it's just baffling to me...

    I frequently wonder how it is they justify things like this to themselves and I mean any company that engages in unethical behavior, not just GoDaddy. Obviously money. But it's just baffling to me how they don't just realize it's wrong and stop...

    9 votes
  4. drannex
    Link
    Wasn't this an issue around '08 or '11 as well? This seems to be a tactic they reuse every few years (or use in smaller forms throughout continually).

    Wasn't this an issue around '08 or '11 as well? This seems to be a tactic they reuse every few years (or use in smaller forms throughout continually).

    6 votes
  5. [2]
    Deimos
    Link
    Here's an article that attempts to reverse-engineer the script that GoDaddy is injecting: https://lolware.net/2019/01/14/godaddy-tracking-code.html

    Here's an article that attempts to reverse-engineer the script that GoDaddy is injecting: https://lolware.net/2019/01/14/godaddy-tracking-code.html

    6 votes
    1. Emerald_Knight
      Link Parent
      I find it a little silly that the author can't quite figure out that in a minified JS file, the expression void 0 evaluates to undefined and serves as shorthand accordingly. Though maybe that's...

      I find it a little silly that the author can't quite figure out that in a minified JS file, the expression void 0 evaluates to undefined and serves as shorthand accordingly. Though maybe that's just stuck in my head because of the long-term trauma induced by having to directly modify a minified, deprecated, third-party JS library to fix a bug in iOS in a legacy project.

      1 vote
  6. dblohm7
    Link
    I currently use WebFaction for hosting, but they have been bought out by GoDaddy. Any suggestions for alternatives with similar feature sets?

    I currently use WebFaction for hosting, but they have been bought out by GoDaddy. Any suggestions for alternatives with similar feature sets?

    4 votes
  7. vakieh
    Link
    Surely by now anyone knows not to touch godaddy with a 100ft pole? They're the absolute scum of a scummy industry. I think DigitalOcean is still good? Though at this point it's so easy to spin up...

    Surely by now anyone knows not to touch godaddy with a 100ft pole? They're the absolute scum of a scummy industry. I think DigitalOcean is still good? Though at this point it's so easy to spin up yourself on AWS/Azure or whatever you probably don't need to bother.

    4 votes
  8. taladar
    Link
    Why anyone would use shared hosting at this point is just beyond my understanding? We have container, cloud VMs, easy physical servers to rent,...

    Why anyone would use shared hosting at this point is just beyond my understanding? We have container, cloud VMs, easy physical servers to rent,...