Outdated plugins and themes
The overwhelming majority. A known vulnerability with a published patch, on a site where nobody applied it. This is a maintenance failure rather than a sophisticated attack.
Almost every compromised site we clean up was running outdated software that nobody was updating. Security here is a process, not a plugin.
Websites are compromised overwhelmingly through known vulnerabilities in outdated plugins, themes and core software, and through nulled or pirated code. Prevention is staged updates, off-server backups, restricted access and monitoring. A security plugin on an unmaintained site is not protection.
The overwhelming majority. A known vulnerability with a published patch, on a site where nobody applied it. This is a maintenance failure rather than a sophisticated attack.
Widespread in this market and frequently carrying backdoors deliberately inserted. The saving on a premium plugin licence is trivial against a compromised site and a Google security warning.
Shared admin accounts, weak passwords, no two-factor, and old accounts belonging to people who left. Every one of these is free to fix and routinely ignored.
On cheap shared hosting a compromise elsewhere on the server can reach you. It is a reason to be careful about the bottom of the hosting market.
Staged updates with a rollback path, off-server backups that have been test-restored, restricted access with two-factor, file integrity monitoring, and someone who notices alerts.
Restore a clean backup from before the compromise, patch the vulnerability that allowed it, remove injected files, rotate every credential, and request a review if Google has flagged the site. Restoring without patching means it happens again within days.
| Relied on | Reality |
|---|---|
| A security plugin, unmaintained | Reports problems nobody reads |
| Backups nobody has restored | A hypothesis, not a backup |
| Obscurity | Attacks are automated and indiscriminate |
| Hosting provider's security | Covers their infrastructure, not your plugins |
| Nulled plugins from a trusted source | There is no such thing |
| Restoring without patching | Reinfected within days |
| Ask them | Good answer | Walk away if |
|---|---|---|
| Who owns the site and accounts? | You do, in your own name | Accounts in the agency's name |
| Can I open three live examples? | URLs you can check yourself | Screenshots and a PDF |
| What is explicitly not included? | A written list with change pricing | Everything is included |
| How will we know it worked? | A metric agreed before work starts | Activity reports |
The exclusions question decides whether the final invoice matches the quote.
Overwhelmingly through known vulnerabilities in outdated plugins, themes or core software where a patch existed and nobody applied it. Attacks are automated and indiscriminate rather than targeted, which is why small sites are hit constantly.
Yes, and they are common in this market. Nulled code frequently contains deliberately inserted backdoors. The saving against a licence is trivial compared with a compromised site, lost customer data and a Google security warning.
No. A plugin on an unmaintained site reports problems nobody reads. Security is staged updates, tested backups, restricted access and someone who responds to alerts. The plugin is one small part of that.
Restore a clean backup from before the compromise, patch the vulnerability that allowed it, remove injected files, rotate every credential and request a review if Google flagged the site. Restoring without patching gets you reinfected within days.
Security patches within days of release, ideally tested on staging first. Regular plugin and core updates monthly. Sites left unpatched for a year are the ones that get compromised.
They secure their infrastructure, not your plugins, themes or passwords. Most compromises happen at the application layer, which is your responsibility regardless of who hosts it.
Send us what you are trying to fix and we will tell you what it takes, what it costs, and whether we are the right people for it. If we are not, we will say so.