Skip to content

The most common WordPress hacks we see, and how we stop them

Most attacks aren't targeted. They're bots looking for weak passwords and outdated plugins.
A navy front door with a solid deadbolt and brass key, lit by morning light.

When people hear a website has been hacked, they often picture someone deliberately targeting their business. That's rarely what happens. Most attacks are automated. Bots scan thousands of WordPress sites at a time, looking for the same small set of weaknesses. If your site has one, it gets found.

Here are the problems we see most often, and what we do about each one.

Guessed or reused passwords

Bots constantly try common usernames and passwords on the WordPress login page. A short password, or one reused from another site that's been leaked, will eventually be guessed.

How we stop it: strong unique passwords, two-factor authentication for admin accounts, and brute-force protection that blocks repeated failed login attempts.

Outdated plugins and themes

When a security issue is found in a popular plugin, the fix is usually released quickly. The risk is the gap between the fix being released and your site being updated. Bots look for sites still running the old version.

How we stop it: weekly updates to WordPress core, plugins and themes, tested on a staging copy first so problems are caught before they reach the live site.

Abandoned or pirated plugins

Plugins that are no longer maintained never get security fixes. Pirated or "nulled" copies of paid plugins are worse, because they often have malicious code added before they're shared.

How we stop it: we review the plugins on every site we take on, remove what isn't needed and replace anything abandoned or from an untrusted source.

Too many admin accounts

Old staff, past developers and agencies often still have administrator access years later. Every one of those accounts is another login that could be compromised.

How we stop it: we tidy up user accounts and give people only the access they need to do their job.

Spam and injected content

Unprotected forms and comments attract spam, and a compromised site can have hidden links or redirects added that you won't notice until Google flags it.

How we stop it: form protection, malware scanning and daily security log review, with uptime monitoring so we know quickly if something changes.

And if the worst does happen

Nightly backups mean a clean copy of your site is always available. If something does get through, we restore, find the cause and close the gap.

All of this is included in every MyWPWebhosting plan, running on WP Engine's enterprise security at the network edge.

Want us to look after this for you?

Every plan includes managed WordPress hosting, weekly updates, nightly backups, security and time with the MyMarketer team each month.

See plans →

Right then. Shall we?

Pick the plan that suits your site and we'll take it from there. Not sure which one fits? Tell us about your site and we'll recommend one.