Summary: Most small-business websites run on WordPress, and the biggest WordPress website security risk is almost always old plugins nobody has updated. Attackers scan the web for those known weak spots and use the sites they find to spread malware, post spam, or steal what visitors type into forms. Keeping the site updated — and knowing whose job that actually is — prevents most of it.
Your website is one of those things you set up once and then stop thinking about. It sits there doing its job, so there’s no reason to touch it. That’s exactly why a neglected site is one of the most common ways a small business gets hacked.
Most small-business sites run on WordPress, which powers more than 40% of all websites according to W3Techs. WordPress itself is solid. WordPress website security problems almost always come from the plugins and themes bolted onto it — the ones that haven’t been updated in years.
Here’s how sites actually get taken, how to tell whether yours is exposed, and the eight WordPress website security fixes that close most of the gap.

How attackers find a WordPress website security hole
Attackers don’t usually pick your business by name. They run automated tools that scan huge numbers of websites looking for known weak spots — a plugin with a security hole that hasn’t been fixed. When the tool finds one, it breaks in. It’s all automatic, and none of it is aimed at you personally.
That’s why old plugins are the problem. When a plugin maker finds a security flaw, they publish an update to fix it — and in doing so, they publish the existence of the flaw. Until you install that update, the hole stays open and the scanners know exactly what to look for. Security researchers who track WordPress flaws consistently find that the large majority sit in plugins and themes, not in WordPress core.
It’s the same logic behind running vulnerability assessments on the rest of your systems: the attacker is working from a public list. The only question is whether you got there first.
What a hacked WordPress site is actually used for
A hacked WordPress site rarely announces itself. Shutting your site down would end the attacker’s access, so they usually keep it running and quietly use it:
- Serving malware. Your site gets modified so visitors are infected or pushed to a page that tries to install something.
- Spam and scam pages. Attackers add hidden pages selling fake goods or pushing scams, riding on your site’s good standing with search engines.
- Stealing form data. If your site has a contact or checkout form, a compromised site can copy what people type into it — including personal or payment details.
- Redirects. Visitors who click your link land somewhere else entirely, usually a scam or malware page.
- Sending mail as you. Your domain gets used to push spam, which is a fast way to wreck email deliverability for everyone in the business.
The damage lands on you even though the attacker was after your visitors. Search engines flag hacked sites with warnings and drop them in the rankings, and browsers may block them outright — so customers get a red “this site may be dangerous” screen instead of your homepage. Recovering that ranking takes far longer than the cleanup does.
Is your website a security risk? Three questions
It depends almost entirely on how your site is built and who touches it.
If you use a hosted builder
Wix, Squarespace, Shopify and similar platforms handle most of the security and updates for you behind the scenes. Your risk is genuinely lower. You still own the admin login, so a strong unique password and MFA are on you — but you’re not responsible for patching plugins.
If you have a self-hosted WordPress site
This is the setup a web designer or agency builds on your own hosting, and it’s where WordPress website security becomes somebody’s job. Keeping WordPress, the plugins, and the themes current takes ongoing attention. The question is whose. On a lot of small-business sites, the honest answer is that nobody has touched it since launch day.
Three questions that tell you where you stand
- Can you name the person or company responsible for updates? If you have to think about it, nobody is doing them.
- When was the site last updated? A year or more is a warning sign. Two years is an open door.
- Do you know what’s installed on it? Plugins from developers who have since vanished are among the worst offenders, because they will never be fixed.
Three uncertain answers doesn’t mean you’ve been hacked. It means you’d have no way of knowing if you had.
8 simple WordPress website security fixes

None of this is expensive, and none of it needs a developer. Most WordPress website security work is habit and ownership rather than technology:
- Keep everything updated. WordPress, plugins, and themes all need updating as new versions land. Most sites can be set to update automatically, which removes the “someone forgot” failure mode entirely.
- Remove plugins you don’t use. Every extra plugin is another thing that can go wrong, and a deactivated plugin can still be exploitable. If you’re not using it, delete it.
- Stick to well-known plugins. Popular, well-reviewed, updated recently. The same five-minute check we’d apply to any browser add-on or micro-SaaS tool works here: who makes it, when did they last ship, and how many people rely on it.
- Watch for abandoned plugins. Sometimes a plugin stops being updated, or gets pulled from the plugin directory over a security problem. When that happens it stops getting fixes. Check periodically that everything on your site is still supported, and replace what isn’t.
- Lock down the admin login. A strong, unique password on the website admin account, and multi-factor authentication if your setup supports it. Also delete old accounts belonging to people who no longer work on the site.
- Add a security plugin or web firewall. A reputable one blocks common attacks and warns you when files change. Your web host or IT provider can recommend something that fits your setup.
- Keep backups you’ve actually tested. A recent backup turns a disaster into an afternoon. An untested backup turns it into a surprise. The same thinking applies as with backups elsewhere in the business: restore-tested, and stored somewhere an attacker can’t reach.
- Decide who’s responsible — in writing. Your web designer, your IT provider, or your hosting company. Any of the three works. “We assumed the other one was doing it” is how most sites end up two years behind.
What to ask whoever owns it
Four questions settle who actually owns your WordPress website security: Who applies updates, and how often? Where are backups stored, and when were they last restore-tested? Who gets alerted if the site changes unexpectedly? And who do I call at 9pm on a Saturday? If the answers are vague, the arrangement is vague.
Signs your WordPress website security has already failed
Because a compromise is designed not to be obvious, it’s usually something outside the site that tips you off first:
- A warning from Google Search Console, or a browser blocking your site.
- Search traffic dropping without an obvious explanation.
- Pages, pop-ups, or redirects nobody on your team added.
- Admin users in the dashboard you don’t recognize.
- Your web host getting in touch about resource usage or outbound spam.
- The site looking normal to you while logged in, but different to a visitor in a private window. That one is deliberate — plenty of attacks hide from logged-in administrators.
If any of that is happening, treat it as real until someone proves otherwise.
What to do about a hacked WordPress site

Once WordPress website security has failed, moving quickly is what limits the damage:
- Get help straight away. Cleaning a hacked site properly is a job for your web host, IT provider, or a website security service. Most hosts have handled this many times.
- Take the site offline. A simple “down for maintenance” page stops visitors being harmed while it’s cleaned.
- Change the passwords from a clean device. Hosting account, website admin, and database. Turn on MFA while you’re in there.
- Restore a clean backup. If you have one from before the compromise, restoring is usually the fastest fix. If you don’t, the site has to be cleaned by hand — slower, costlier, and less certain.
- Update and tidy up before it goes back live. Update WordPress, plugins, and themes, and remove anything you don’t recognize. Otherwise the same hole gets used again within days.
- Ask Google to review the site once it’s clean, so the warning comes down and your rankings start recovering.
- Tell anyone whose data was affected. If the site handled customer details or payments, check what was exposed and notify the people involved. Depending on your state and industry, this may not be optional.
Take the next step
If you can’t say for certain who’s keeping your site updated, that’s worth sorting out before something goes wrong rather than after. It’s a short conversation, not a project — we’ll look at how your site is built, what’s exposed, and what’s worth fixing first, the same ground we cover in a security posture review.
Frequently asked questions about WordPress website security
How do I know if my website has been hacked?
Common signs are a warning from Google or your browser, a drop in search traffic, pages or pop-ups you didn’t add, admin users you don’t recognize, or your web host getting in touch. If you’re not sure, your IT provider or web host can check.
Do I need to update my website if it works fine?
Yes. A site can look completely normal to you while an out-of-date plugin leaves a door open. Updates close those holes, which is exactly why they matter when nothing looks wrong.
I use Wix or Squarespace. Am I at risk?
Much less so. Hosted builders handle updates and most of the security for you. Use a strong admin password and MFA, but you’re not responsible for patching plugins the way a self-hosted WordPress site is.
Who should be responsible for WordPress website security?
Someone should own it clearly: your web designer or agency, your IT provider, or your hosting company. Which one matters far less than it being written down and actually happening.
What is a security plugin or web firewall?
A tool that sits on your website, blocks common attacks, watches for file changes, and alerts you to problems. On WordPress, a reputable security plugin is a common, low-cost way to add that layer.
How often should the site be updated?
Security updates should go on within days of release, not months. For most small-business sites, automatic updates plus a monthly check that nothing broke is the right balance between safe and low-maintenance.
Is a cheap hosting plan a security risk?
It can be. Budget shared hosting often means older software versions, no automatic backups, and slow support when something goes wrong. It isn’t the price that matters so much as what’s included — ask what gets patched for you and what doesn’t.
Keeping a site secure sits alongside the other quiet maintenance jobs most businesses put off, like making your site digitally accessible. Neither shows up as urgent until it suddenly is.
Sources and further reading
- W3Techs: WordPress usage statistics — the share of websites that run on WordPress.
- Patchstack: WordPress vulnerability report — research showing most WordPress security holes are in plugins and themes.
- NCSC: Small Business Guide — guidance on keeping software updated and patched.
—
This Article has been Republished with Permission from The Technology Press.
