A WordPress site isn’t a thing you build once and leave alone. It’s software, running in public, made mostly of parts written by other people. In 2025 alone, over 11,000 new security holes were found in those parts.
Most business owners think of their website the way they think of a signboard: you pay for it, it goes up, it stays up. WordPress isn’t like that. It’s a live application built from a core platform plus a stack of plugins and a theme, all of which get updated, and any of which can develop a security hole.
Leaving it alone doesn’t keep it the same. It just means nobody’s watching while it drifts.
The Numbers Behind Why This Matters
WordPress runs 41.1% of all websites on the internet, and 59.1% of all sites whose content management system is known. That scale is the reason it gets so much attacker attention: finding one flaw in a popular plugin gives you a key that fits an enormous number of doors.
Patchstack, which tracks WordPress security vulnerabilities, recorded 11,334 new vulnerabilities across the WordPress ecosystem in 2025. The breakdown is the important part:
| Where the vulnerabilities were found | Share of the total |
|---|---|
| Plugins | 91% |
| Themes | 9% |
| WordPress core | 6 issues total, all low priority |
WordPress itself is not the weak point. The add-ons are. And the average small business site is running somewhere between fifteen and thirty of them.
Patchstack also found that 46% of vulnerabilities did not receive a patch from the developer in time for public disclosure, meaning for nearly half of them, there was nothing to update to when the flaw went public. Clicking “update all” is necessary, but it is not the whole job. Someone has to notice when a plugin has been abandoned by its developer and replace it.
What Regular Maintenance Actually Involves
“Maintenance” sounds vague, so here’s what it means in practice:
- Apply updates, carefully. Core, plugins and theme, applied in a controlled way rather than automatically at 3am with nobody checking whether the site still works afterwards
- Audit the plugin list. Remove what isn’t used, replace what’s no longer maintained. Every plugin you don’t need is attack surface you’re carrying for free
- Verify the backups actually restore. A backup nobody has ever tested is a hope, not a plan
- Check the site still works. Forms submitting, checkout completing, pages loading on a phone, the things that break silently and cost you enquiries
- Watch performance and uptime. Sites get slower over time as content, images and plugins accumulate
- Renew the certificate and keep an eye on the domain. An expired SSL certificate throws a browser warning that stops visitors dead
What Happens When Nobody Does It
The failure mode is rarely dramatic. It’s usually one of these:
- The contact form quietly stops sending. A plugin or mail setting changes, nothing errors visibly, and you assume business is slow for weeks
- A plugin update breaks the layout. Auto-updates ran, something conflicted, and the site looked wrong to every visitor until someone happened to check
- The site gets compromised. Usually through a known vulnerability in an out-of-date or abandoned plugin, the exact category that makes up 91% of the total
- The site gets slower and slower. No single cause, just accumulation, until pages take five seconds to load and visitors leave before they arrive
Cleaning up a hacked WordPress site costs far more than maintaining it, not in the fix itself, but in the downtime, the lost enquiries, the reputational hit if visitors got redirected somewhere unpleasant, and the scramble to work out what was taken. Maintenance is the boring version of that money.
How We Handle It
Every Twilight I.T. managed WordPress plan includes the maintenance work as standard, not as an add-on: WordPress updates, security protection, daily backups kept off-site, site health monitoring, website down monitoring, and a monthly maintenance report so you can actually see what was done.
Backup retention runs from 1.5 months of weekly restore points on the Managed plan up to 6 months on Dedicated, which matters, because the problems you most need to roll back from are the ones nobody noticed at the time.
Frequently Asked Questions
How often does a WordPress site need maintenance?+
Monthly is a sensible baseline for a typical small business site, with security updates applied more promptly than that when something significant is disclosed. Sites that take payments or handle customer data warrant closer attention, because the consequences of a compromise are larger.
Can’t I just turn on automatic updates?+
Automatic updates help, and they’re better than nothing. What they don’t do is check whether the site still works afterwards, notice that a plugin has been abandoned by its developer, or handle the roughly 46% of vulnerabilities that had no patch available when they were disclosed. Updates are one part of maintenance, not a substitute for it.
Is WordPress itself insecure?+
No. The evidence points the other way, in 2025 there were only six vulnerabilities reported in WordPress core, all low priority, against thousands in plugins and themes. WordPress core is well maintained. The risk lives in what gets bolted onto it, which is why keeping the plugin list short and current matters so much.
How would I know if my site had been hacked?+
Often you wouldn’t, which is the problem. Modern compromises tend to be quiet, injected spam links that only show to search engines, redirects that only fire for visitors arriving from Google, or a hidden admin account left for later. Monitoring catches these; casually looking at your own homepage usually doesn’t.
Do I need maintenance if my site never changes?+
Yes, and arguably more. Your content isn’t changing, but the software underneath it is, and so is the threat landscape around it. A brochure site that hasn’t been touched in three years is a very typical starting point for a compromise, precisely because nobody is looking at it.
Not Sure When Your Site Was Last Updated?
Twilight I.T. will look over your WordPress site, tell you what’s out of date, what’s abandoned, and what’s actually at risk, and then keep it maintained from there if you’d like us to.
Terms Explained
Not a tech person? No problem. Here’s what these concepts actually mean in plain English.
Sources





