WordPress is the world's most popular website platform — and the world's most hacked
Around 40% of all websites run on WordPress. That popularity is exactly why it's targeted. Automated bots scan the internet looking for WordPress sites with known vulnerabilities — outdated plugins, old themes, unchanged default settings — and they find them within hours of them going live.
This isn't theory. WordPress sites account for more than 90% of all hacked websites. The vast majority of those hacks happen not because the site was specifically targeted, but because bots hit millions of sites automatically and exploit whatever vulnerabilities they find.
How WordPress sites get hacked
The most common attack vector isn't the WordPress core software — it's the plugins. Every plugin you install adds code to your site. Every piece of code is a potential vulnerability. And every plugin has a version history: if you're not running the latest version of every single plugin, you may be running code with known security holes that are publicly documented on the internet.
A typical trades WordPress site might have:
- A page builder (Elementor, Divi, WPBakery)
- An SEO plugin (Yoast, RankMath)
- A contact form plugin (Contact Form 7, WPForms)
- A caching plugin
- A backup plugin
- A security plugin
- Whatever the agency installed to build it
That's potentially seven or more plugins, each needing regular updates, each with its own vulnerability history, each representing a door into your site.
The uncomfortable truth: Most tradespeople's WordPress sites haven't been updated in months — sometimes years. The agency who built it moved on, the client doesn't have access, and nobody is watching. The site just sits there, getting older and more vulnerable.
What happens when a WordPress site gets hacked
The goal of most WordPress hacks isn't to destroy your site — it's to quietly use it. Attackers inject spam links, create hidden pages, or use your server to send phishing emails. From the outside, your site looks normal. You'd never know.
What Google notices, however, is different. Google's crawlers find the spam pages. Google's Safe Browsing service flags the malicious content. And then one of three things happens:
- Google adds a warning to your search result — "This site may be hacked" appears under your listing. Anyone who sees this leaves immediately.
- Google removes your site from search results — not a ranking drop, an outright removal. Your site disappears.
- Your email domain gets blacklisted — if the hack sends spam from your domain, your email address stops reaching people. Quotes you send go to junk. You don't know why.
All three of these can happen and resolve without you ever knowing there was a problem — because the injected content is often invisible to normal visitors. You'd need to check your Google Search Console, run your domain through a blacklist checker, or notice a sharp drop in enquiries.
The SEO cost of a slow WordPress site
Even if your WordPress site never gets hacked, it's likely costing you ranking positions simply by being slow. WordPress generates pages dynamically — every time someone visits, the server queries a database, runs PHP code, processes multiple plugins, and assembles the HTML. All of that takes time.
A typical WordPress trades site on shared hosting scores 35–55 out of 100 on Google's PageSpeed Insights for mobile. That matters because Google uses page speed as a ranking factor. Slow sites rank lower. And the slowest pages in your site — usually image-heavy service pages — are often the pages you need to rank most.
Typical WordPress Trades Site
FSG Static HTML Site
What to check right now
If you have a WordPress site, here's what to do today:
- Check Google Search Console — log in (or ask your agency to log in) and look under Security & Manual Actions. Any warnings there means Google has found something it doesn't like.
- Run your domain through MXToolbox — search "MXToolbox blacklist check" and enter your domain. If you're listed on any major blacklists, your emails aren't reaching people.
- Check when your plugins were last updated — log into your WordPress dashboard and go to Plugins. If any plugin hasn't been updated in six months or more and a newer version is available, you're running known vulnerabilities.
- Google your own business name — look for anything suspicious in the results: strange page titles, spam content, warnings.
The fastest check: Search for your website address on Google. If you see anything other than your own pages in the results — especially pages with strange titles or foreign-language content — your site has almost certainly been compromised.
The bottom line
WordPress is a capable platform used by millions of legitimate websites. It's also the platform that requires the most maintenance, carries the most security risk, and performs worst on mobile — the metrics that matter most for a trades business trying to get found on Google.
For most tradespeople, the site they paid for is quietly working against them. Not dramatically — no dramatic crash, no obvious warning — just slowly losing ranking positions, occasionally getting flagged, running a bit too slow on mobile, and never performing as well as it should.
If you want to know exactly how your current site is performing, request a free audit. We'll check the speed, security, ranking, and Google Business Profile — and give you a straight answer on what it's actually costing you.
Is your site costing you jobs?
We'll audit your current online presence for free and tell you exactly what needs fixing.
Get a Free Audit