Just for the record, they did do an installation of their script onto my account. As part of their installation process, THEY created a password for the admin account (which is not what the FTP account information is - I have the ticket number and email that shows the account they created) which is what I had missplaced and thus created the request asking how to retrieve the admin password. Now, in hind sight, they never told me how to get it, but rather opted “not to waste time”.
Further to this, the FTP details from the server they installed on (a cheap hosting account) was different from my production server, and the FTP information was totally different thus my questioning them about their backdoor (I had created a mirror image from dev to prod).
I don’t have this script installed anymore, but if anybody has it installed, could you check your (I think it was smartway directory) and in there check for a conf subdirectory - I believe that is where they have ALL your information stored in the XML files. Why else, I ponder, would they mandate you (at least they used too) to tell them where this directory is?
It is simply wrong for Webscribble to claim that they don’t (or didn’t) have a backdoor. Just reading their EU agreement stipulates what damage they can do to your site.