Why WordPress sites get hacked
Almost every WordPress hack falls into one of four buckets:
- Outdated WordPress core, themes or plugins
- Weak or reused passwords
- Vulnerable or abandoned plugins
- Poor hosting with no isolation between accounts
If you address all four, you remove around 95% of the realistic risk. Everything else is bonus. You don’t need to be a security expert to do this, you just need to actually do it.
Keep everything updated (the boring one that matters most)
The single most common reason small business sites get hacked is out-of-date software. A vulnerability is found in a plugin, a patch is released, and weeks later half the sites using that plugin still haven’t updated. Bots scan the web looking for unpatched versions and exploit them automatically.
What to do:
- Turn on automatic updates for WordPress core, themes and plugins
- Check your site at least monthly for any updates that didn’t apply automatically
- Remove any plugin or theme you’re not actively using (deactivated isn’t enough: delete it)
- Avoid plugins that haven’t been updated in over a year
If automatic updates make you nervous because something might break, the answer is staging. A good host gives you a one-click staging environment where updates can be tested before they go live.
Get your passwords and accounts in order
The second most common cause of compromise is weak or reused passwords. The fix is simple but most businesses skip it.
Use a password manager
1Password, Bitwarden, Dashlane, whichever you prefer. Generate strong, unique passwords for every account. This applies to WordPress, your hosting, your domain registrar, your email and your payment provider.
Turn on two-factor authentication
For WordPress, plugins like Wordfence, Solid Security or Two Factor Authentication add 2FA for admin logins. Turn it on for every administrator account. The extra five seconds at login time is worth it.
Audit your user accounts
Most sites accumulate old accounts from former staff, freelancers and agencies. Delete anything you don’t need. Demote anything that doesn’t need admin access. The fewer admin accounts, the smaller the attack surface.
Don’t use “admin” as a username
It’s the first thing every brute-force attack tries. If you do, create a new admin account with a different username and delete the original.
If your WordPress login uses a memorable password, no 2FA, and a username of “admin”, you’re not running a website. You’re running an open audition for hackers.
Choose plugins (and themes) carefully
Every plugin is code running on your site. The more plugins you have, the bigger your attack surface. A few simple rules:
- Only install plugins you actually need
- Prefer plugins from well-known developers with frequent updates and a large active install base
- Avoid “nulled” or pirated premium plugins, these are a common source of malware
- Check the changelog before installing, a plugin that hasn’t been updated in 18 months is a red flag
- Audit your plugin list every six months and uninstall anything you don’t use
This is one of the biggest reasons we recommend simple, well-maintained themes for most clients. We touched on theme choice in our piece on effective web design.
Pick decent hosting
Cheap shared hosting is one of the biggest hidden risks. If your hosting provider doesn’t isolate accounts properly, a breach in one site on the same server can spread. If they don’t keep server software up to date, vulnerabilities sit unpatched. If they don’t offer real backups, recovering from an attack becomes a nightmare.
A good host gives you:
- Automatic daily backups stored off-server
- Free SSL certificates (Let’s Encrypt or equivalent)
- A staging environment
- Account-level isolation
- Server-level firewall and malware scanning
- Easy WordPress core updates
We talk about why this matters in our post on why website speed matters.
Add a security plugin (one is enough)
You don’t need three competing security plugins fighting each other. Pick one well-maintained one and configure it properly. Reasonable choices include Wordfence, Solid Security and All In One WP Security.
Whichever you choose, the settings that matter most are:
- Login attempt limiting
- Two-factor authentication
- File integrity monitoring
- Malware scanning on a schedule
- A firewall (web application firewall, or WAF)
Backups: the thing you only think about when it’s too late
If your site does get hacked, the difference between a 30-minute restore and a week of disaster is whether you have working, recent, off-site backups.
What “good” looks like:
- Automatic daily backups
- Stored somewhere other than your hosting account (cloud storage, another provider, or a backup service like UpdraftPlus)
- Tested at least once a year: an untested backup is just a hope
HTTPS, SSL and the basics that everyone notices
Every page of your site should be served over HTTPS. Browsers warn visitors about non-secure sites, and Google quietly ranks them lower. Most hosts offer free SSL via Let’s Encrypt; if yours doesn’t, change host. We covered SSL briefly in our post on how to conduct a website audit.
What to do if you do get hacked
Don’t panic. Don’t delete things at random. The right order:
- Take a snapshot of the current state for evidence
- Restore from a known good backup if you have one
- Update WordPress core, all plugins and themes immediately
- Change every password (admin, hosting, FTP, database, email)
- Run a full malware scan
- Identify how the attacker got in and close that hole
- If it’s serious or you can’t find the entry point, get professional help
A simple monthly checklist
- Run all available updates
- Check your security plugin’s scan log
- Verify your latest backup actually exists and isn’t empty
- Skim the user accounts list for anything unexpected
- Take a quick look at Google Search Console for any security warnings
That’s about ten minutes of work, once a month. It’s the difference between a site that quietly hums along and a site that becomes a lesson in disaster recovery. If you’d rather hand this off entirely, our managed WordPress care plans cover all of it. Get in touch.