Why small business WordPress sites get hacked (and how to avoid it)
Short answer
Most small business WordPress sites aren't hacked through WordPress itself. They're hacked through outdated plugins and themes, weak or reused admin passwords, and abandoned sites nobody updates. Keep everything updated, remove unused plugins, use strong passwords with two-factor login, and back up regularly. If your site rarely changes, a static site removes most of these risks entirely.
Why are plugins the biggest risk?
WordPress's core software is well maintained. Security researchers consistently find that the large majority of reported WordPress vulnerabilities are in plugins and themes, often small ones maintained by a single developer. Every plugin you install is more code that can have a flaw, and attackers scan the internet for sites running vulnerable versions.
Why would anyone hack a small local business?
It's rarely personal. Automated bots attack thousands of sites at once to send spam, host phishing pages, redirect visitors to scams, or mine your server's resources. A small site with an old plugin is simply an easy target.
How do I know if my site was hacked?
- Google shows a “This site may be hacked” warning, or your search results show strange pages or spam text.
- Visitors get redirected to other websites, especially on phones.
- New admin users appear that you didn't create.
- Your host warns you about malware or suspends the site.
How do I protect a WordPress site?
- Update WordPress, themes, and plugins promptly, or turn on automatic updates.
- Delete plugins and themes you don't use, not just deactivate them.
- Lock down logins: unique strong passwords, two-factor authentication, and no shared “admin” account.
- Back up automatically to somewhere outside your hosting account, and test restoring once.
- Use reputable hosting that includes a firewall and malware scanning.
When should I skip WordPress entirely?
If your site is mostly the same month to month, like services, hours, photos, and a contact form, a static site is often the better fit. There's no admin panel, no database exposed to the internet, and no plugins to patch, so most common attacks simply don't apply. That's how every Hardline WebWorks site is built. See the security page for details.
Common questions
Is WordPress itself insecure?
No. WordPress core is actively maintained and reasonably secure. The risk comes mostly from outdated plugins and themes, weak passwords, and sites nobody maintains.
How often should I update my WordPress site?
Check at least weekly, or enable automatic updates for plugins and minor releases. Security fixes are most valuable when applied quickly.
Can a hacked website be cleaned up?
Usually, yes, from a clean backup or by a security professional. Afterward, change every password and find out how the attackers got in, or it often happens again.
