What a Hacked WordPress Site Really Costs You

The risk most business owners get wrong

Most SME owners treat website security as an IT problem. Something for a developer to worry about. A box to tick when the site goes live and then, largely, forget about. If that sounds familiar, you’re not alone, and you’re also sitting on a financial risk that’s easy to underestimate until it bites you.

WordPress websites make up a huge proportion of UK small business sites, and that popularity makes the platform the most targeted on the web. Patchstack’s State of WordPress Security in 2026 counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, a 42% increase over the year before, with 91% of those found in plugins.
Around 13,000 WordPress sites are compromised every single day.
The overwhelming majority of those attacks aren’t clever, targeted operations aimed at your business specifically. They’re automated, opportunistic and indiscriminate. If your site has an unpatched flaw, a bot will find it.

This article isn’t about scaring you. It’s about giving you an honest, itemised picture of what a compromise actually costs, because once you see the full picture, the case for proactive maintenance and security becomes very obvious very quickly.

How WordPress sites get hacked

WordPress core is actually well maintained and regularly patched.
Of all the vulnerabilities discovered in 2025, 91% were found in plugins and 9% in themes. Only six vulnerabilities were reported in WordPress core, and all were considered low risk.
The risk comes from everything bolted on to it.

Forty-six percent of those vulnerabilities weren’t fixed in time for disclosure, meaning nearly half were made public whilst the affected plugin remained unpatched.
Think about that. Nearly half the known flaws had no fix to apply even if you’d wanted to update immediately.

The weighted median time from vulnerability disclosure to first exploitation was just five hours.
That’s the window between a flaw being announced and automated scanners actively targeting every WordPress site running the affected plugin. Five hours is not long.

Other common entry points include nulled (pirated) themes and plugins, which frequently come pre-loaded with hidden backdoors, and inactive plugins that sit unupdated on a site for months because nobody remembers they’re there. Every inactive plugin is an attack surface with zero upside.

What happens in the hours after a breach

The immediate aftermath of a hack often isn’t obvious. Many attacks are designed to be invisible. Malware can sit on a site for weeks, quietly doing its work, before anything visibly wrong appears. Without the technical knowledge to spot the changes, most business owners have no idea anything has happened.

If a site does get infected, there’s a good chance the malware will simply rewrite itself after cleanup.
Attackers inject posts, create hidden admin accounts, plant malicious options rows and schedule rogue cron jobs, all specifically so they can return later.
The Patchstack 2026 report also highlights that highly exploitable vulnerabilities increased by 113% year-on-year, and that attackers are now injecting code into legitimate WordPress core, plugin and theme files rather than dropping standalone malicious files.
That makes detection significantly harder.

In more visible cases, your site gets defaced, redirected to a spam or phishing page, or taken offline by your hosting provider. Compromised sites are routinely used to send spam through the site’s mail server, which gets the sending IP and domain blocklisted. Your email stops working. Customers can’t reach you. And you probably don’t know any of this has happened until someone tells you.

Cost item 1: Emergency recovery fees

The first bill that arrives is the developer’s. Emergency malware removal is specialist work and it doesn’t come cheap, especially when you need it done quickly.

For a simple brochure site, basic clean-up work starts at a few hundred pounds and covers malware removal and getting the site back online, but typically won’t include root cause investigation, backdoor verification or any kind of re-infection guarantee. If your site generates revenue or processes personal data, you’ll need a more thorough forensic package, and the cost rises accordingly. Serious incident response on an e-commerce site can run into several thousand pounds.

And that’s just the clean-up.
If a site does get infected, there’s a good chance the malware will simply rewrite itself after cleanup,
which is why clean backups need to be verified before restoring. Many backups already contain the backdoor. If the only backups you have are from after the compromise started, restoring just resets the timeline without solving anything. If you have no usable backup at all, you may be looking at a full rebuild.

Cost item 2: Downtime and lost revenue

Every hour your site is offline or serving malicious content is an hour you’re not generating enquiries, sales or leads. For a Cardiff plumber who gets ten calls a week from the website, even two days offline during a busy spell is meaningful lost revenue. For an online shop, it can be devastating.

Around 69.6% of hacked WordPress sites contain unauthorised backdoors.
That means detection speed directly affects total recovery cost. A site that’s compromised for weeks before anyone notices accumulates far more damage than one caught on day one, which is exactly why monitoring matters.

Cost item 3: Google blacklisting

This is the one that tends to hurt most, and the one business owners least expect. Google’s Safe Browsing system continuously scans sites for malware, phishing content and deceptive redirects. If your website is found to be hosting something harmful, even without your knowledge, it’s added to the database of unsafe sites. Visitors trying to reach your pages through Chrome, Firefox, Safari or any major browser will encounter a large, alarming warning screen telling them the site may be dangerous.

A blacklisted site can lose the overwhelming majority of its organic traffic overnight. Most visitors see that red warning page and leave immediately. Getting removed isn’t instantaneous either. Malware removal itself can take days, and Google’s review and delisting process can take up to a fortnight. SEO recovery, meaning your rankings and traffic actually bouncing back, can take weeks to months after that.

The knock-on effect for your search engine rankings can persist long after the technical issue is resolved. Rankings you’ve spent months building don’t simply snap back when Google removes the flag. Links shared on social media or sent in email campaigns may also be blocked or flagged whilst the blacklisting is active, effectively killing any marketing activity that drives traffic to your site.

Cost item 4: Reputational damage and GDPR

If your site collects any personal data, whether that’s contact form submissions, customer accounts, newsletter sign-ups or payment information, a hack becomes a data breach. And in the UK, that brings legal obligations on top of everything else.

Under UK GDPR, you must notify the ICO within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk of adversely affecting individuals’ rights and freedoms, you must also inform those individuals without undue delay.
That means writing to your customers to tell them their data may have been compromised. Even if you handle it perfectly, the conversation damages trust.

Think about a local accountancy practice whose client portal gets compromised, or a small online retailer whose customer email list is exposed. The phone calls, the apologies, the lost clients, the reputational dent in a close-knit business community. That’s hard to put a number on, but it’s very real. For smaller businesses with limited resource, the proportional impact is often far worse than the headline cost figure suggests.

Cost item 5: The recurring vulnerability problem

Here’s the part that catches a lot of business owners out. You pay for a clean-up, the developer fixes the visible damage, the site comes back online. Job done? Not necessarily.

With around 70% of hacked sites containing unauthorised backdoors, a surface clean without proper forensic investigation simply resets the clock. The attacker’s access route is still there. Cheap, quick clean-ups that don’t investigate and close the original entry point are money wasted. You’ll be back in the same position within weeks.

This is why the total cost of a hack is so much higher than most people expect. Factor in emergency developer time, downtime, lost revenue, potential GDPR fines, and the months of SEO work required to undo injected spam links and recover from a Google penalty, and what looked like a one-off clean-up bill grows very quickly into something far more serious.

What prevention actually looks like

Basic security hygiene stops roughly 90% of attacks.
Most attackers are opportunistic. A site that looks harder to compromise than average simply gets skipped. Prevention comes down to a few consistent habits:

  • Keep everything updated. Plugins, themes and WordPress core, updated promptly when security releases come out.
    Vulnerable plugins cause 91% of WordPress security issues.
    Staying current closes the most common door.
  • Remove unused plugins. Every plugin you’re not actively using is a liability. If it hasn’t been updated by its developer in over twelve months, replace it.
  • Use strong, unique passwords and two-factor authentication on all admin accounts. Credential stuffing is automated and relentless; 2FA makes it largely irrelevant.
  • Run automated daily backups stored off-site. A clean backup from before the compromise is the fastest way to recover. Without one, you’re at the mercy of however far the damage has spread.
  • Monitor for changes. Activity logging, file integrity monitoring and anomaly alerts are the difference between catching a compromise in hour one and discovering it three months later when Google sends a penalty notice.
  • Use a Web Application Firewall (WAF) built for WordPress.
    Two separate pentesting studies conducted in 2025 found that standard hosting defences blocked only 12% of known exploited vulnerability attacks
    against WordPress sites, so relying on generic hosting security is not enough.
  • Keep your SSL certificate current and make sure your site redirects cleanly from HTTP to HTTPS.

DIY maintenance vs handing it over

If you’re technically minded and genuinely set aside time each week to review and action plugin updates, check security logs and verify your backups, DIY maintenance can work. Most business owners are honest with themselves about whether that actually happens.

The reality for most SMEs is that maintenance tasks drift. A plugin update gets skipped because the site owner is busy. An alert goes unnoticed. A backup stops running silently and nobody checks. When that happens, a site that was well configured the day it launched quietly accumulates risk month by month.

Professional maintenance removes the human error from the equation. It also means that if something does go wrong, there’s someone already familiar with your site who can respond quickly, rather than you scrambling to find a developer at short notice and paying emergency rates.

How we can help

At Cardiff Web, keeping websites secure, updated and performing is a core part of what we do. Our web development and maintenance service covers plugin and theme management, security configuration and backup monitoring, so that the sites we build don’t become liabilities the moment we hand them over.

If you’re running a WordPress site and you’re genuinely unsure when it was last properly updated, or you don’t know where your backups are stored, it’s worth having a conversation sooner rather than later. A quick audit of your current setup costs far less than an emergency recovery. And unlike a hack, it doesn’t come with weeks off Google.

If you’d prefer to start fresh with a new website built with security baked in from day one, we’re happy to talk that through too. Get in touch and we’ll give you an honest assessment of where things stand.

NO CALL CENTRES

Talk To A Developer

The person who answers is a person who builds. Ask us anything about your project – no scripts, no obligation, no hard sell.

CALL US ON

Mon – Fri, 9:00 – 17:30

Out of hours? Email  contact@cardiffweb.co.uk
and we’ll reply first thing.