WordPress security series · Part 2 of 5
Most hacked small business websites I clean up have something in common. It is rarely a clever attacker. It is usually one or more abandoned WordPress plugins that nobody has touched in years.
How it happens
Your site was built a few years ago. The developer installed 20 or 30 plugins to make it do what you wanted: forms, sliders, galleries, SEO. Then the developer moved on.
Some of those plugins are still maintained. Some are not. Their authors lost interest, sold the product or shut up shop. When a security flaw turns up in an abandoned plugin, nobody fixes it. The hole stays open for as long as the plugin stays installed.
From the front end, you cannot tell. The site looks fine, right up until it redirects your customers to a scam page or starts sending spam in your name.
How to spot one
WordPress.org gives you a free warning sign. Open any plugin’s page in the official directory and look for this notice: “This plugin hasn’t been tested with the latest 3 major releases of WordPress.” That usually means nobody is looking after it.
Other red flags:
- No update from the author in the last twelve months.
- Support forum questions going unanswered.
- The plugin has disappeared from the WordPress.org directory altogether.
Paying for a plugin is no guarantee either. Patchstack’s State of WordPress Security in 2026 found premium components had three times more known exploited vulnerabilities than free ones.
What to do about it
Every abandoned plugin needs one of three decisions: replace it with a maintained alternative, rebuild the feature properly, or remove it. “Leave it and hope” is not a decision. It is a delay.
Deactivating is not enough. A deactivated plugin’s files still sit on the server, and badly written ones can still be reached directly. If you do not use it, delete it.
The question to ask this week
“How many of our plugins have not been updated by their author in the last twelve months?”
The right answer is a number, and a plan for each one.
Next step
A Security Audit (from $1,000 inc GST) lists every plugin on your site, flags the abandoned ones and tells you what to do with each, in plain English. For ongoing cover, see our maintenance plans.
Common questions
How many plugins is too many?
Is deactivating an old plugin enough?
Are premium plugins safer than free ones?
The five-part series
- Five Hours: The Gap Between a WordPress Flaw and an Attack
- Abandoned Plugins: The WordPress Risk You Can’t See — you are here
- When Your Backup Plugin Becomes the Way In (6 October)
- Your Website Isn’t the Target. It’s the Tool. (13 October)
- A Hacked Website Is Now a Compliance Problem (27 October)
Based on the full article: Your WordPress Site Is Probably Already a Problem.