A website with almost nothing to hack

A lot of people think nobody will attack their website because it’s small. They’re right about one thing: nobody will attack it by hand. It’s done by programs that crawl the internet day and night, without caring whose site is whose.

What those programs look for

They aren’t looking for your site in particular. They’re looking for any site with a door left unlocked: a plugin with a known flaw, a weak password, an old version. When they find one, they let themselves in.

Then they use your site to send spam, send your visitors somewhere else, or hide links that you can’t see but Google can. Often the owner only finds out weeks later, when Google starts warning people that the site isn’t safe.

Why WordPress is the usual target

The reason is simple: it’s everywhere. Four in ten websites in the world run on WordPress. One flaw in a popular plugin opens thousands of sites at once, so it pays to go looking.

The figures from Patchstack, a company that specializes in WordPress security, make it plain. In 2024, 7,966 new flaws were published in WordPress and its add-ons. 96% of them were in plugins, not in WordPress itself. And 43% could be used without logging in.

That’s why updates matter so much. Every plugin on your site is one more door, and each one depends on someone locking it in time.

What there is to attack on a static site

Very little. A static site is a set of files that are already made:

  • No database to steal or wipe.
  • No login page on the public site, so no password to guess.
  • No plugins going out of date.
  • No code running on the server when someone visits.

A program hunting for WordPress flaws passes over your site and finds nothing to try.

What’s still up to you

Almost nothing isn’t nothing. On a static site, what needs protecting is the accounts: the domain, the hosting and the editor. Anyone who gets into those can change the site or take the domain.

The fix is simple and works for any website: a different password on each of those accounts, with two-step verification turned on.

If you already have WordPress

You don’t have to switch tomorrow. But you should be able to answer three questions:

  1. Who updates your site, and how often?
  2. How many plugins do you have, and which ones don’t you use?
  3. Do you have a recent backup stored somewhere other than the site’s own server?

If any answer is “I don’t know”, get in touch and we’ll look at it together.

Keep reading

Back to the blog

Let's talk

Tell me what you need. I reply within one or two working days.