Most small business owners find out their website has been hacked from a customer. Not from their host, not from a security alert, from a message saying “your site is doing something weird”. By the time that message arrives, it has usually been days.
If that thought makes your stomach drop a bit, you are in the right place. WordPress security sounds like something that belongs to IT people, and most of the advice written about it is written for them. It does not have to be. The things that actually protect a small business website are boring, repeatable, and well within reach of someone who is not technical at all.
What actually causes most small business website hacks
WordPress security means keeping the software your website runs on up to date, keeping access to it limited, and keeping a backup you could restore from if something went wrong. That is the whole of it.
Most of the small business sites I look after run on WordPress, and that popularity is exactly what makes it a target. Attacks are almost never aimed at a particular business. They are automated, they sweep across thousands of sites at once, and they look for the same handful of openings every time:
- An outdated plugin. Plugin developers release updates that close known holes. An unpatched plugin is a published, publicly listed way in.
- A licence that quietly expired. Premium plugins and themes stop receiving updates when the licence lapses, and nothing on your site announces it.
- A weak or reused password. Automated login attempts run constantly against WordPress sites. A password you use elsewhere has likely already been exposed in someone else’s breach.
- An admin account nobody removed. The web person you used three years ago, the VA who helped for a month, the developer who built the site. Every live admin login is another door.
- Old PHP or an unmaintained theme. The layer underneath WordPress ages too, and hosts do not always upgrade it for you.
Notice what is not on that list. Nothing about being targeted, being famous, or having done anything wrong. It is almost always maintenance that quietly stopped happening.
The warning signs your website has been compromised
You will not usually get a clean alert. What you get is something slightly off:
- Your site loads a page you did not create, often in a language you do not use
- Search results for your business show descriptions that are not yours
- Visitors on mobiles get redirected somewhere else, while it looks fine on your laptop
- Google shows a red interstitial warning before your site loads
- Your host suspends the account for sending spam
- The site is suddenly very slow, for no reason you can find
The mobile-only redirect is the one that catches people out most often, because the owner checks on a desktop, sees nothing wrong, and assumes the customer made a mistake.
Five things you can check today
None of these need a developer. Give it twenty minutes.
- Log in and look at your plugin list. How many say “update available”? If you cannot remember the last time you updated them, that is your answer.
- Check who has an admin account. Users, then All Users, then filter by Administrator. Remove anyone who no longer works with you.
- Test your backup, do not just confirm it exists. Ask your host or your maintenance provider one question: if the site went down today, how long would it take to restore, and when was that last tested? “There is a backup” is not the same as “we could put it back”.
- Change your own password, and turn on two-factor authentication. If your WordPress password is one you use anywhere else, change it now rather than later.
- Google your own business name and look at the description. If the text under your listing is not text you wrote, that is a strong signal something has been injected into your pages.
For anyone who wants the technical version, WordPress publishes its own hardening documentation, and the Australian Cyber Security Centre has small business guidance written in plain English. Both are free. [Karen: I have not opened these links from this session, so please check they resolve before publishing.]
What weekly maintenance actually covers
Website maintenance is the routine that stops all of the above from being your problem. In practice it is three jobs, repeated every week rather than remembered occasionally:
| Job | What it prevents |
| Update WordPress core, plugins and themes | The single biggest cause of small business hacks |
| Take and verify a backup | Turns a disaster into an afternoon |
| Run a security scan and check for unfamiliar admin users | Catches a problem while it is still small |
Done weekly, it takes someone who knows the site about twenty minutes. Done never, it takes days and often costs more than a year of maintenance to clean up.
Do you need help, or can you do this yourself?
Honestly? If you are comfortable logging in, you update things when prompted, and you have tested your backup, you can absolutely run this yourself. Plenty of business owners do.
Where it goes wrong is not capability, it is consistency. Maintenance is the task that always loses to client work, and it stays lost until the week it becomes urgent.
That is the whole reason my website maintenance package exists: weekly updates, weekly backups, weekly security checks, $132 a month, and you never think about it again. If your site has been sitting untouched for a while and you are not sure where it stands, get in touch and I will tell you honestly whether it needs looking after or whether you are fine as you are.
Either way, do the five checks above this week. Twenty minutes now is a great deal cheaper than a rebuild later. You’ve got this.