MBX Networks - IT Solutions for a Stronger Tomorrow
Cybersecurity

Your Website Works Fine. Is Anyone Maintaining It?

A business website that nobody updates is a common way small businesses get hacked, usually through outdated WordPress plugins. Here's what to check and who should own it.

A business website is one of those things you set up once and stop thinking about. It sits there doing its job, so there’s no reason to touch it. That’s exactly why a neglected website is one of the more common ways a small business gets compromised.

Most small-business sites run on WordPress, which powers more than 40% of the web, according to W3Techs. WordPress itself is solid software. The risk is almost always the plugins and themes bolted onto it, which on many sites haven’t been updated since the day the site launched.

How a neglected site gets hacked

Attackers don’t pick your business by name. They run automated scanners across enormous numbers of websites looking for one thing: a plugin with a known, already-published security flaw that hasn’t been patched. When the scanner finds one, the break-in is automatic. Nothing personal about it.

That’s why old plugins are the problem. When a plugin developer finds a security hole, they release a fix. Until that fix is installed, the hole stays open, and the scanners know precisely what to look for. Researchers who track WordPress vulnerabilities consistently find the large majority in plugins and themes, not WordPress core.

What a hacked site gets used for

A hacked website rarely announces itself. Attackers usually keep it running and put it to work:

  • Serving malware to your visitors, or redirecting them to pages that do.
  • Hosting hidden spam and scam pages that trade on your site’s standing with search engines.
  • Skimming form data: anything typed into a contact or checkout form, including personal and payment details.

The damage lands on you either way. Search engines flag hacked sites and drop their rankings; browsers may show visitors a red “this site may be dangerous” warning instead of your homepage. Cleaning that up takes far longer than the maintenance that would have prevented it.

Is your site at risk?

It depends on how it’s built:

  • Hosted builders (Wix, Squarespace, Shopify): the platform handles updates and most security behind the scenes. Lower risk; keep a strong admin password and MFA and you’re in decent shape.
  • Self-hosted WordPress (typically set up by a designer or agency on your own hosting): keeping WordPress, plugins, and themes updated is someone’s job, and the honest answer at many businesses is that it’s been nobody’s job since launch.

Warning signs you’re in the second camp: you don’t know who maintains the site, it hasn’t been touched in over a year, or it runs plugins from developers who have since disappeared.

What proper maintenance looks like

  • Update everything (WordPress core, plugins, themes) on a schedule. Much of it can update automatically.
  • Delete plugins you don’t use. Every extra plugin is another door.
  • Prefer popular, actively maintained plugins; replace anything abandoned or pulled from the plugin directory.
  • Lock down the admin login with a strong unique password and MFA.
  • Add a reputable security plugin or web firewall to block common attacks and alert on changes.
  • Keep backups so a compromise means restoring, not rebuilding.
  • Decide who owns this: designer, host, or IT provider. The specific answer matters less than it clearly being someone’s job.

If it’s already been hacked

Move fast: get help from your host or IT provider, put up a maintenance page so visitors aren’t harmed, change hosting and admin passwords from a clean device, restore a pre-compromise backup if you have one, and update everything before the site goes back online; otherwise the same hole gets used again. If the site handled customer data, find out what was exposed and notify the people affected.


Website maintenance often falls into the gap between the web designer and the IT company, where each assumes the other has it. If nobody’s sure who’s watching your site (or your backups of it), that’s worth a conversation.

Want help putting this into practice?

MBX Networks works with businesses across Mid-Michigan on exactly these kinds of decisions.