← All articles

Nobody targeted your website. That is the whole problem.

When a small business site gets compromised, the owner’s first question is almost always some version of “why us?”

Usually the honest answer is: nobody chose you.

How it actually happens

A vulnerability gets found in a plugin. It gets written up publicly, because that is how disclosure works and it is the right thing to do. Within hours, that write-up includes enough detail to identify which sites are vulnerable and how.

From there it is automated. Scanners walk the internet asking every site a cheap question: are you running this plugin, at a version below this number? Most sites say no. Some say yes. The ones that say yes get a second visit.

Nobody looked at your business, decided you were worth attacking, and researched you. A script checked a version number. Your site said yes.

This is why “we are too small to be a target” is the wrong frame. Being small does not make you invisible to something that is checking everyone.

Why the version number is public

Most site software announces itself. A plugin loads a stylesheet at a path containing its version. Your CMS may add a generator tag to the page source. Even without those, the specific combination of files a plugin loads is a fingerprint.

You cannot really hide this, and trying to is a distraction. The fix is not to conceal the version number. It is to not be running the old one.

The unglamorous fix

There is no clever part to this:

  • Apply updates promptly. Not eventually. The window between a vulnerability being published and being scanned for is short, often the same day.
  • Remove what you do not use. Every deactivated-but-installed plugin is still on disk and still reachable. The cheapest vulnerability to fix is one you deleted a year ago.
  • Have backups you have actually restored from. A backup nobody has tested is a hope, not a plan. Restore one to a staging address occasionally and confirm the site comes up.
  • Put a firewall in front. It will not save a badly outdated site, but it filters the automated traffic, which is most of it.

What it costs when it goes wrong

The cleanup is rarely the expensive part.

Search engines detect compromised sites quickly and flag them. Once your listing carries a warning, traffic stops, and getting the flag removed is not just deleting the malicious code. It is cleaning the site, proving it is clean, and requesting a review, which takes as long as it takes.

Meanwhile your site is either offline or actively warning people away from your business.

Keeping a site patched takes minutes a month. That asymmetry is the entire argument, and it is why we offer ongoing security and maintenance rather than only building sites and walking away.

The one thing to do today

Log in and look at your plugin list. Count how many have updates waiting, and how many you do not recognise or no longer use.

If that number surprises you, that is the finding. You do not need a security audit to act on it.

Book a call / 15 minutes

Want this for your business?

Fifteen minutes, no pitch. Tell us what's wrong with your site and we'll tell you whether it's worth fixing.

Open the calendar

Opens the booking calendar on this page.