WordPress powers a huge share of the websites on the internet, and that popularity is exactly why it is such a common target. Attackers don't usually pick a small business website on purpose. They run automated tools that scan thousands of sites for known weaknesses and break into whatever they find.

We regularly rebuild hacked WordPress sites for businesses in Durban and around South Africa. The causes are almost always the same, and most of them can be prevented.

The most common reasons WordPress sites get hacked

1. Outdated plugins and themes

Plugins are the biggest risk. Each one adds code written by a different developer, and security researchers find new vulnerabilities in popular plugins all the time. Once a flaw is made public, attackers start scanning for sites that haven't updated. A site with 25 plugins that hasn't been updated in a year is an easy target.

2. Abandoned or "nulled" plugins

Some plugins stop being maintained, so security holes never get fixed. "Nulled" themes and plugins, meaning pirated copies of paid ones downloaded for free, are even worse. They often come with hidden malicious code already built in.

3. Weak or reused passwords

Bots constantly try common usernames such as "admin" with lists of leaked passwords against the WordPress login page. If an admin password is weak, or has been used on another site that was breached, it will eventually be guessed.

4. Cheap or poorly managed hosting

On some low-cost shared hosting, one compromised site can affect others on the same server. Old PHP versions, no firewall and no monitoring make things worse, and when something goes wrong there is often nobody to call.

5. No updates, no backups, no one watching

Many small business sites are built, launched and then forgotten. Without someone responsible for updates, backups and security, it is only a matter of time.

Signs your website has been hacked

  • Visitors, especially on mobile, are redirected to spam, gambling or fake prize pages.
  • Google search results show strange titles, foreign-language text or pages you didn't create.
  • Google or your browser shows a warning such as "This site may be hacked" or a red "Deceptive site ahead" screen.
  • Your hosting provider suspends the site or warns you about malware or spam being sent.
  • There are admin users you don't recognise, or you can't log in any more.
  • Your site suddenly becomes very slow, or your emails start landing in spam.

What to do if your site has been hacked

  1. Don't panic, and don't just delete things. Deleting random files can make recovery harder.
  2. Change every password: WordPress admin users, hosting control panel, FTP, database and email accounts.
  3. Take a copy of the site as it is. This helps work out what happened.
  4. Clean or restore. Restore from a known clean backup if you have one, or have the site professionally cleaned. Hacks often leave hidden back doors, so a quick clean-up frequently leads to the site being reinfected.
  5. Update everything and remove any plugins or themes you don't use.
  6. Ask Google to review the site through Google Search Console once it is clean, so warnings are removed.

How to prevent it

  • Keep WordPress, plugins and themes up to date, every month at least.
  • Use as few plugins as possible, and only well-maintained ones from reputable developers.
  • Never install nulled themes or plugins.
  • Use strong, unique passwords and two-factor authentication for admin accounts.
  • Choose managed hosting with backups, a firewall and people who respond.
  • Keep automatic, off-site backups you have actually tested.

Does your business website even need WordPress?

For many small businesses, the honest answer is no. If your website is mostly about who you are, what you do and how to contact you, and it only changes a few times a year, a hand-coded HTML or PHP website is faster, cheaper to maintain and far harder to break into. There is no admin login for bots to attack, no plugins to exploit and nothing that needs updating every week.

That is how we build most of our websites today, including this one. When a client comes to us with a hacked WordPress site, we often rebuild it this way, keep the content and look they want, improve the search engine optimisation, and move it onto our own managed hosting so it stays safe.

Website hacked or running slowly? We clean up and rebuild compromised websites, and host them securely on our own servers. WhatsApp us your website address and we'll take a look.