Most small business owners figure hackers have bigger fish to fry. Why would anyone bother with a plumber's website in Katy or a CPA's site in the Heights? That's the right question with the wrong conclusion. Nobody picks your site out. A program finds it.
Small business sites rarely get hacked because someone chose them. They get hit by automated bots that scan the whole internet for known weak spots, like outdated plugins, reused passwords and forgotten admin accounts. The fix is steady, boring upkeep that closes the doors those bots check first.
You're not a target. You're a match.
Picture someone walking down every street in Houston at night, trying every front door. They don't care whose house it is. They care which doors are unlocked. That's how most attacks on small sites work. Software does the walking, all day, against millions of sites at once.
Google says it plainly in its guide on how sites get hacked: "Attackers actively seek out old software with vulnerabilities." A vulnerability is a known flaw in software that lets someone do something they shouldn't, like log in without a password or slip in their own code. Once a flaw is public, bots start checking for it.
So forget "would anyone want my site?" The useful question is whether your site matches what the bots are looking for today.
The threats that actually hit sites like yours
Outdated plugins and themes
If your site runs on WordPress, this is the big one. A plugin is an add on that gives the site a feature, like a form, a gallery or a booking calendar. A theme controls how the site looks. Both are software written by someone else, and both get security fixes.
Patchstack, a company that tracks WordPress security flaws, put it this way in its latest annual report: "91% of new vulnerabilities were found in plugins, and 9% were found in themes." In the same report, only a handful were in WordPress itself. The core software is rarely the problem. The add ons are.
Google's guidance lines up: "Remove themes or plugins that are no longer maintained." I see this a lot: a site with a dozen plugins, three of them switched off but still sitting on the server, one of them abandoned by its developer years ago. Switched off isn't the same as gone.
Weak or reused passwords
Bots guess passwords all day. They also take email and password pairs leaked from other sites and try them everywhere. Google's advice: "Avoid reusing passwords across services." If your website login matches the password on some old shopping account, you've handed out a spare key.
Abandoned admin accounts
The web designer from 2019. The intern who updated the blog. The marketing agency you stopped paying. Their logins often still work. Every extra admin account is another password you don't control and can't vouch for.
Cheap hosting and bad neighbors
On the cheapest shared hosting, your site lives on a server with hundreds of others. If the setup keeps those accounts poorly separated, a hacked site next door can become your problem. Old server software is the other risk. Your site can be up to date while the server under it isn't.
Form spam and junk sign ups
Bots also fill out contact forms by the thousands. Some of it is just annoying. Some of it tries to sneak links or code through the form, and heavy spam can bury the real leads you need to see. If your inbox is full of junk from your own site, the form needs better protection. More on that in Is your contact form actually sending?
A practical security basics checklist
None of this makes a site safe forever. Nothing does. These steps close the doors bots try first and make recovery much easier if something slips through.
- Update on a schedule. WordPress, theme and plugins, with security fixes applied promptly. Test the site after, because updates can break things.
- Delete what you don't use. Remove unused plugins and themes completely, not just switch them off.
- Audit your users. List every admin account. Remove anyone who doesn't need access today. Give everyone else the lowest level of access that lets them do their job.
- Fix passwords. Long, unique passwords stored in a password manager. Turn on two step login, where a code from your phone is needed too, for every admin.
- Limit login attempts. Block repeated failed logins so bots can't guess forever.
- Keep backups off the server. Daily copies stored somewhere else, with a restore actually tested.
- Check your hosting. Ask your host what PHP version your site runs on and whether it's still supported. PHP is the programming language WordPress runs on.
- Protect your forms. Add spam filtering and confirm real messages still arrive.
- Keep the padlock working. Your SSL certificate, which encrypts traffic between visitors and your site, should renew automatically, and someone should confirm it did.
- Own your keys. Your domain, hosting and admin logins should be in your name. See who should own your website.
What doing it yourself really takes
You can absolutely do this yourself. Plenty of owners do. Here's the honest cost.
Time. Updates aren't a once a year job. Plugins release fixes all the time, and a serious one can't wait for a slow week. Figure on checking at least weekly, plus time to test after each round.
Skills. Clicking "update" is easy. Knowing what to do when an update breaks your layout or your form at 9 p.m. is the hard part. You'll want to be comfortable with backups, restores and your hosting control panel.
Tools. A password manager, a backup system that stores copies off the server, a way to know when your site goes down and a security plugin or firewall you've set up properly.
The risk. When DIY goes wrong, it usually goes wrong quietly. A skipped update, an old login nobody removed, a backup that turns out to be empty. You find out when Google warns visitors away from your site or your host shuts it off. If that happens, here's what to do in the first 24 hours.
If you enjoy this kind of work and have the hours, go for it. If you'd rather spend those hours on your business, that's a fair call too.
What we handle, and what we don't promise
Our care plan takes the checklist above off your plate. We handle updates and security patches, monitor for downtime and broken forms, run a monthly check that everything still works, and keep daily backups with restores we actually test. Our hosting runs on servers we manage ourselves, with SSL certificates set up and renewed for you.
What we won't do is tell you your site can't be hacked. Nobody honest can. What good care does is make problems less likely, catch them sooner and make recovery routine. If your site runs on a pile of old plugins, a cleaner WordPress build can remove a lot of that risk at the source. For the wider picture, see what website maintenance should include.
If you'd rather not be the one checking the doors every week, ask us about a care plan.



