Big cybercrime headlines sell fear. Site owners need smaller, boring truths that change what you do on Monday. These seven facts are WordPress-specific enough to act on today, with deeper guides linked where you need them.

1. Small sites get hit
Attackers do not hand-pick famous brands first. They scan IP ranges and run credential lists against every wp-login.php they find. A low-traffic site is still a useful spam relay, SEO redirect host, or staging ground for attacks on neighbors on shared hosting.
What to do: Stop assuming obscurity is a control. Run updates, limit admin accounts, and use a firewall that blocks known bad traffic. Background: why small sites still get attacked.
2. Most breaches start with weak access
Reused passwords, shared “team” admin logins, and missing two-factor authentication beat exotic zero-days for raw volume. Bots try admin / password and pairs from old breach dumps (credential stuffing).
What to do: Unique long passwords in a manager, 2FA on every privileged role, and login protection so failed guesses get capped. Walkthrough: WordPress login security guide. Dictionary: brute force.
3. Phishing targets people, not only servers
Fake “your site is hacked” emails, forged hosting invoices, and “click here to verify SSL” links still work because they target the person with wp-admin access. A phished admin session bypasses a perfect firewall.
What to do: Verify URLs before you log in. Bookmark your real wp-admin URL. Train staff who handle client sites. If someone clicked a suspicious link, rotate passwords from a clean device and review users. Term: phishing.
4. Unpatched plugins are a top WordPress entry point
One abandoned extension with a public vulnerability is enough. Deactivated plugins still sit on disk and often still load code. “We do not use that plugin anymore” is not the same as deleted.
What to do: Update or remove flagged components the same day. Run the free vulnerability scanner after every big install. Hub: WordPress vulnerabilities database. Risks: plugin security.
5. Malware often comes back if you only delete one file
Deleting a single suspicious PHP file without closing the entry point is how “it came back overnight” stories start. Attackers leave multiple droppers, cron jobs, or rogue admin users.
What to do: Find how they got in (plugin, password, upload), rotate credentials, compare core files, and scan themes and uploads. Guide: WordPress malware removal. Term: malware.
6. Backups are a control, not a nice-to-have
A backup you never restored is a hope. Ransomware, bad updates, and hack cleanup all get cheaper when you can roll back to a known-good copy.
What to do: Automate offsite backups, store them outside the web root, and run a restore test on staging once a year. Guide: WordPress backup tips. Plan: backup plan after an attack.
7. Security and SEO meet when a site is infected
Spam injections, malicious redirects, and Safe Browsing warnings trash rankings and trust faster than most marketing campaigns build them. Google does not wait for you to notice in Analytics.
What to do: Monitor Search Console security messages. After cleanup, follow SEO recovery after a hack. Background: why website security matters for SEO.
What to do next
Facts without a routine do not protect anything. Pick one weekly habit:
- Review failed logins and new admin users
- Patch vulnerability scanner hits
- Confirm backups still run
Then work through the WordPress security checklist and hardening guide. Security Ninja Free covers tests and vulnerability checks; Pro adds firewall, malware scanning, and login hardening when you want active blocking. Start on WordPress.org or pricing.