Your Plugins Are the Attack Surface, and You Cannot Patch Fast Enough
Most small business owners believe their website is safe because someone updates it. That belief rests on an assumption worth testing: that a patch exists when the attack starts. For nearly half of the holes found in the WordPress ecosystem last year it did not, and for the ones that mattered the first exploit arrived in about five hours. An update schedule is a good habit. On those numbers it cannot be the whole defense.
The WordPress attack surface is the total set of code an attacker can reach on your site. For almost every small business site the large majority of that surface is not WordPress itself but the plugins added on top of it, which is why patching cadence and attack timing matter more than the platform choice.
The Number That Should Change Your Maintenance Plan
The weighted median time to first exploit is five hours, and about half of high impact vulnerabilities are exploited within 24 hours of disclosure (Patchstack, 2026). No small business maintenance window is shorter than that, which means the race is lost before anyone reads the notification.

Start with the timing, because it reframes everything else.
The weighted median time from public disclosure to the first observed exploit is five hours, and roughly half of high impact vulnerabilities are exploited within 24 hours (Patchstack, 2026). That is the window you are actually operating in.
Now compare it to how the work really happens. A vulnerability is disclosed on a Tuesday afternoon. Your maintenance runs monthly, or weekly if you are diligent, or whenever somebody notices the little red circle in the dashboard. Even a same day response measured in hours is often too slow, and for a business whose website is not anybody’s actual job it is not close.
This is not an argument that updates do not matter. They matter. It is an argument that a defense whose response time is measured in days cannot be the only thing standing between an automated scanner and your site.
WordPress Core Is Not What Gets You Hacked
Of 11,334 new vulnerabilities found in the WordPress ecosystem in 2025, 91 percent were in plugins and 9 percent in themes, with only 6 in WordPress core and those low priority (Patchstack, 2026). The platform is not the exposure. What was installed on top of it is.
There were 11,334 new vulnerabilities recorded across the WordPress ecosystem in 2025, a 42 percent increase on the year before (Patchstack, 2026). That number sounds like an indictment of WordPress until you look at where the holes actually were.
Ninety one percent of them were in plugins and nine percent in themes. WordPress core accounted for six, and those were low priority issues (Patchstack, 2026).
That distribution is the single most useful fact in this article, because it tells you where the risk lives and therefore what to do about it. Core is maintained by a large project with a security team and an automatic update mechanism. A plugin might be maintained by one person who lost interest in 2023, and the average small business site is carrying somewhere between fifteen and forty of them, most installed years ago for a reason nobody remembers.
Every one of those is code you did not write, cannot review, and are trusting with the same database that holds your customer enquiries. The question worth asking about your own site is not whether WordPress is secure. It is how many plugins are installed, who maintains each one, and which of them you could remove today without anybody noticing.
Updating Cannot Be the Whole Plan, Because Often There Is Nothing to Install
Forty six percent of vulnerabilities did not receive a fix from the developer in time for public disclosure (Patchstack, 2026). For nearly half of them, the day the world learns about the hole there is no patch to apply, so a perfect update process still leaves the site exposed.
Here is the part that breaks the mental model most owners are working from.
Forty six percent of the vulnerabilities disclosed did not receive a fix from the developer in time for that public disclosure (Patchstack, 2026). Sit with that. It means for nearly half of known holes, on the day attackers learn about them, there is nothing for you to install. Your update process can be flawless and it changes nothing, because the update does not exist yet.
Combine the two findings and the conclusion is not really arguable. Nearly half the time there is no patch, and when there is one the first exploit lands in a median of five hours (Patchstack, 2026). A strategy built entirely on applying patches is a strategy that is late in the best case and helpless in the common one.
What has to exist instead is something that blocks the attempt regardless of whether a patch is available. That is a different layer of defense from updating, it sits in front of the site rather than inside it, and it does not care whether the plugin author has shipped a fix yet.
Most of What Hits Your Site Is Not a Person
Bots are more than 53 percent of all web traffic, up from 51 percent the year before, and human traffic is down to 47 percent (Imperva, 2026). The scanning that finds a vulnerable plugin on a small business site is automated, indiscriminate and continuous.
Owners often assume that being small is protection. Nobody is targeting a plumbing company in Collier County specifically, so why would anyone bother.
Nobody is targeting you specifically. That is the point. Bots now account for more than 53 percent of all web traffic, up from 51 percent the year before, while human traffic has fallen to 47 percent (Imperva, 2026). The majority of what arrives at your website is automated, and a meaningful share of it is looking for a known vulnerable version of a known plugin.
That scanning does not evaluate whether you are worth attacking. It checks whether a path exists, and it checks continuously. Attack patterns are also moving deeper into the application: 27 percent of bot attacks targeted API endpoints (Imperva, 2026), which is a shift away from poking at the surface of a page.
The practical consequence for a small site is that the defense has to be automatic too, because the attack is. Anything requiring a human to notice, decide and act is operating on the wrong timescale.
If Your Business Runs on Search, a Compromise Costs Twice
A hacked site loses the immediate business and the search position that was producing it. Recovery means cleaning the site, getting any warning lifted, and then waiting for rankings and trust to return, which takes far longer than the cleanup.
For a business whose phone rings because of Google, a compromise is not one loss, it is two.
The first is immediate and obvious. The site is down, defaced, or quietly serving something it should not, and enquiries stop. The second is slower and more expensive. Search engines can flag a compromised site with a warning that appears before anyone reaches it, and even after the cleanup the position that took a year to build does not come back on the day the malware comes off.
The timing makes it worse in seasonal markets. A trades business in Southwest Florida earns a disproportionate share of the year in a narrow window, and a compromise inside that window is not an IT inconvenience, it is a lost season. The same logic runs through the seasonal timing arguments in our HVAC and plumbing articles: the calendar does not move to accommodate you.
This is the honest reason a search agency ends up talking about security at all. There is no point engineering a page into a position it cannot hold, and everything that makes a site rank is worth exactly nothing on the week it is serving somebody else’s content.
If you want to know where your own site stands before deciding anything, our free audit reports what is actually reachable and readable on your domain, and it costs nothing. If the answer is that the plugin stack is the problem, moving off it is our site migration service.
Turn on what makes AI recommend you.
AI recommends the businesses it can read, trust and quote. Flip on the four signals we engineer, and watch your visibility climb and the answer rewrite itself.
Illustrative · the four signals are the real system we build
This article, answered.
The questions readers ask about this topic, answered the way an answer engine would. No forms, no sales pitch.
Pick a question on the left and you’ll get the direct answer, the way an answer engine would give it.
PUBLISHED August 17, 2026 · WRITTEN BY JAMIE KLONCZ, FOUNDER · SEO ELITE AGENCY, NAPLES FL
Enter a path and click verify.