Security & Maintenance

Will My Website Get Hacked?

Nobody is targeting your church. That's the part people get wrong, and it's also why small sites get hit so often.

· Hosting, Security & Uptime · For both

Do small church and business websites really get hacked?

Yes, routinely, and almost never because someone chose you. Most compromises are automated: software scans the whole internet for sites running a plugin with a known, published flaw and exploits whatever it finds. Patchstack, a security company that publishes an annual report on the WordPress ecosystem, counted 11,334 new vulnerabilities disclosed in 2025, with 91% of them in plugins and 9% in themes. The defense is unglamorous and effective: keep software updated, keep the plugin count low, use real passwords with two-factor authentication, and keep tested backups.

The most common thing we hear after a site gets compromised is a version of: “why would anyone target us?”

Nobody did. That’s the whole point, and it’s worth understanding, because the wrong mental model here leads directly to the wrong precautions.

How it actually happens

Picture a program that walks the entire internet, knocking on every door, checking whether that door has a lock model with a published flaw. It isn’t reading your sermon archive or evaluating whether you’re worth the effort. It’s checking a list.

When a security researcher discovers a flaw in a piece of website software, it gets disclosed publicly so people can patch it. Attackers read those disclosures too. Within hours, automated scanners are sweeping for sites that haven’t updated yet.

Your church is not a target. Your out-of-date contact form plugin is.

The numbers, and where they come from

Patchstack publishes an annual report on the WordPress ecosystem. They’re a security company, so they have a commercial interest in this being alarming, and you should read their figures with that in mind. That said, the vulnerability counts are drawn from public disclosures, which makes them checkable.

Their 2026 report counted 11,334 new vulnerabilities disclosed across the WordPress ecosystem in 2025, a 42% increase over the year before.

The distribution is the useful part. 91% were in plugins. 9% in themes. WordPress core itself had six, all rated low risk.

That single fact should shape how you think about your site. The core software is maintained by a large project with a serious security process. The seventeen plugins someone added over eight years are maintained by seventeen different parties of wildly varying diligence, and some of them have quietly stopped.

Two more figures from the same report, both about time. Roughly half of high-impact vulnerabilities are exploited within 24 hours of disclosure. And 46% of vulnerabilities had no fix available from the developer at the moment they became public.

That second number is the one that changes behavior. It means “just keep everything updated” is necessary but not sufficient, because sometimes there is no update to apply. Sometimes the correct move is removing the plugin.

What a compromise actually looks like

Rarely a defaced homepage with a skull on it. That’s the movie version. What we usually find:

  • Spam pages quietly added under your domain, selling counterfeit goods to search traffic you never see. You find out when Google flags your site.
  • A redirect that only fires on mobile, or only for visitors arriving from search, so staff on desktop never notice.
  • Your domain sending phishing email. Your domain had a good reputation, which is exactly what made it worth stealing. Then your legitimate email starts bouncing.
  • A quiet foothold, doing nothing visible, waiting.

The reputational damage is the part that stings. A visitor who gets a red browser warning trying to find your service times has learned something about you that isn’t true and isn’t easily corrected. It also puts your Google listing at odds with your actual site, and Google’s guidelines expect your presence to represent you accurately.

The list that prevents most of it

Not exhaustive. Ordered by how much protection you get per unit of effort.

  1. Update promptly. Core, plugins, themes. Weekly at minimum, and same-day for anything flagged critical. Given how fast disclosed flaws get exploited, “we do it quarterly” is a decision to be exposed most of the time.
  2. Delete plugins you don’t use. Deactivated is not removed. Deactivated plugin code still sits on the server and can still be reachable. Every one you delete is one fewer thing to maintain forever.
  3. Check whether your plugins are still maintained. If the last update was three years ago, it isn’t stable. It’s abandoned, and there will be no patch when a flaw is found.
  4. Real passwords, and two-factor on every admin account. Shared logins are the other common entry point, and churches are unusually prone to them because so many people cycle through.
  5. Remove old accounts. The intern from 2021 does not need an administrator account. Neither does the vendor you stopped working with.
  6. Backups you have actually restored. Keep several restore points, not just last night’s. Test one. A backup nobody has ever restored is a hope.
  7. Keep hosting current too. The PHP version and server software underneath your site age the same way your plugins do.

Who is doing this

That’s the real question, and it’s the one most churches and small businesses can’t answer.

Every item above is straightforward. None of it is technically difficult. All of it has to happen indefinitely, forever, including the weeks when your office manager is on vacation and the month everyone is consumed by VBS.

Software maintenance is the least urgent item on any list until the day it becomes the only item. That’s precisely why it gets skipped, and why the sites we’re called in to clean up are almost never sites where someone was negligent. They’re sites where it was nobody’s job.

So: who on your team owns this, and what happens when they leave? If the answer is uncomfortable, that’s worth resolving before it resolves itself.

Our hosting and support plans exist because this is the part nearly every church and small business underestimates. But the list above works regardless of who runs it. If you do it yourself, do it on a calendar, not on good intentions.

Common questions

Why would anyone bother hacking a small church website? +

They didn't pick you. The overwhelming majority of compromises are automated scans looking for any site running software with a known flaw. Once in, a small site is useful as a host for spam pages, a redirect to a scam, a place to mine crypto, or a springboard for sending phishing email under a domain with a clean reputation. Being small is not protection, and in practice it correlates with being out of date.

What actually gets exploited most often? +

Add-ons, not the core software. In Patchstack's 2026 report, 91% of newly disclosed WordPress vulnerabilities were in plugins and 9% in themes, against six in WordPress core, all rated low risk. The practical lesson is that every plugin you install is a component someone else maintains, and each one is a way in if it stops being maintained.

How fast do I need to apply updates? +

Faster than most people assume. Patchstack reports that roughly half of high-impact vulnerabilities are exploited within 24 hours of public disclosure. Their report also found 46% of vulnerabilities had no fix from the developer by the time the flaw went public, which is why abandoned plugins are a genuine risk and not a tidiness issue.

Aren't backups enough on their own? +

Backups are essential and they are not a defense. They're what turns a catastrophe into a bad afternoon. Two things people miss: a backup nobody has ever restored is a hypothesis rather than a backup, and if your backups run daily but the compromise happened three weeks ago, you may be restoring the problem. Keep several restore points, and test one.

How do I know if my site has already been compromised? +

Common signs are a browser or Google warning when visiting your own site, pages you never created showing up in search results for your domain, sudden redirects on mobile only, unfamiliar admin users, or your email being rejected because your domain landed on a spam list. If you see any of these, take the site offline or into maintenance mode before you start investigating.

Sources

Request Your Free Redesign

We'll handle the design, hosting, updates, and support so your team gets its time back.

Unable to load verification question. Please try again.