WordPress Security

Why WordPress Sites Get Hacked — And Why Nobody Chose Yours

Most owners assume they are too small to be a target. That misunderstands how attacks actually work. Here is why WordPress sites get hacked, and what genuinely prevents it.

Get Shielded
19 Jul 2026 5 min read
Why WordPress Sites Get Hacked — And Why Nobody Chose Yours

"Why would anyone target us? We're a small business."

We hear that in almost every conversation after a site has been compromised. It is a completely reasonable assumption, and it is the single biggest reason small sites stay vulnerable. Understanding why WordPress sites get hacked starts with letting go of the idea that someone chose you.

Nobody picked your website

The overwhelming majority of attacks are automated. Software scans enormous ranges of the internet looking for one specific weakness — a plugin at a version with a known flaw, a login page that accepts unlimited password attempts, an outdated PHP version.

It does not read your homepage. It does not know what you sell or how much you turn over. It checks for the flaw, and if the flaw is present, it acts.

Being small does not make you invisible to a scanner. It usually makes you easier.

A new site with no traffic will start receiving login attempts within days of going online. That is not evidence of interest in your business. It is background noise on the internet.

What they actually want

Attackers are rarely after your customer list. Compromised sites are useful as infrastructure, and that is what makes every site worth taking:

  • Spam hosting. Hidden pages selling counterfeit goods, riding on your domain's reputation.
  • Traffic theft. Redirecting your visitors to sites that pay per click.
  • Phishing. Hosting fake bank or login pages on your hosting, so the scam is not traced back to them.
  • Sending email. Using your server to send spam, which gets your domain blacklisted.
  • Server resources. Crypto mining or joining a botnet.
  • SEO manipulation. Injecting links to boost other sites in search results.

Notice what these have in common. None of them require you to be big, wealthy or interesting. They require a working website.

The five ways they get in

1. Outdated plugins and themes

By a distance, the most common cause. When a plugin vulnerability is patched, the details become public. Attackers then scan for sites still running the unpatched version — and there are always plenty, because most sites are updated in weeks or months rather than days.

The gap between patch and update is the entire attack window. Shortening it is the highest-value security work most sites can do.

2. Weak passwords and brute force

Automated tools try common passwords against wp-login.php continuously. If your admin account uses a reused or guessable password and there is no rate limiting, it is a matter of time.

Two-factor authentication ends this category of attack almost entirely.

3. Nulled themes and plugins

Pirated premium plugins from file-sharing sites frequently ship with backdoors already built in. That is the business model — the software is free because you are the product.

There is no safe way to use nulled code on a site that matters.

4. Weak hosting

On cheap shared hosting with poor isolation, a compromise on a neighbouring account can spread. You did everything right and still got hit, because someone on the same server did not.

5. Abandoned code

A plugin the developer stopped maintaining three years ago will never be patched again. Deactivated plugins still sit on the server and can often still be executed. Anything you are not using should be deleted, not just switched off.

Why it goes unnoticed for so long

Modern infections are built to stay quiet. A defaced homepage is rare now, because a visible hack gets fixed quickly and the access is lost.

Instead, the code hides itself from logged-in administrators, shows spam only to search engines, or redirects only first-time mobile visitors arriving from Google. The site looks perfectly normal to the one person who would remove it.

Typical discovery routes are all indirect: a customer mentions a strange redirect, Google flags the site, the host suspends the account, or rankings quietly collapse. By then the infection has usually been present for weeks.

What actually prevents it

Security is not one product. It is a short list of habits, and most of the value sits in the first three.

  1. Update promptly. Days, not months. This closes the largest attack window there is.
  2. Strong passwords plus two-factor on every administrator account.
  3. Delete what you do not use. Every inactive plugin and theme is code that can be exploited.
  4. Run a firewall that filters malicious traffic before it reaches WordPress.
  5. Monitor for file changes, so an infection is caught in hours rather than discovered by a customer.
  6. Keep off-server backups you have actually tested restoring.
  7. Choose hosting properly. The cheapest plan is rarely the cheapest outcome.

The real cost is not the clean-up

Removing malware is the small part. The expensive parts are the days of lost traffic while Google shows a warning, the customers who saw the redirect and did not come back, the rankings that take months to recover, and the emails that stop arriving because your domain got blacklisted.

Prevention costs a fraction of that, and it is predictable.

The honest summary

Why WordPress sites get hacked usually comes down to something ordinary: a plugin that needed updating, a password that was too simple, or a site nobody was watching. Not sophistication. Not bad luck. Just an open door found by software that checks millions of doors a day.

Our security monitoring service handles the watching — continuous malware scanning, a firewall, file-change alerts and prompt updates — so problems are caught while they are small.

If you think something is already wrong, our WordPress security and error fixing service cleans the site properly, backdoors included. Send us your web address and we will tell you what we can see, usually the same day.

Get Shielded

We build, host, secure and monitor business websites — cleaning up hacks and keeping sites online for clients across the UK, USA, Australia and the UAE.

Keep reading

Chat on WhatsApp