The 5-hour window.

Last lesson: what a hack costs. Now: how break-ins actually happen — because once you see the mechanism, the fix makes sense.

THE CLOCK IS REAL A business owner checking her website's security

When a serious hole in website software is made public, attacks typically begin within five hours.

The Question Every Owner Asks

"How would someone even hack MY site?"

It's the question almost every owner asks. And the answer surprises people: nobody's sitting in a basement targeting you personally. The truth is less personal — and more useful — than that.

The Reality

The internet is being scanned. All day. Every day.

Automated bots crawl the web around the clock, checking millions of sites for known holes in WordPress, plugins, and themes. They don't know you. They don't care what you sell. When they find a site with a known hole, the attack just… runs. No human needed.

13,000websites hacked every single day — roughly one every seven seconds
24/7automated scanning, in every country, in every language — bots don't sleep
The Mindset Shift

Your site isn't picked. It's found.

Hackers don't choose small businesses — bots find them. Because small businesses are the ones running outdated software. The most common way in isn't clever. It's an open door that already had a patch.

1

A bot scans millions of sites for known holes

2

It finds one site running outdated software — any site

3

The attack runs itself — no human, no choice, no mercy

The Scale

11,334 new holes were found in WordPress software last year.

In 2025, researchers found over 11,000 new vulnerabilities in the WordPress world — 42% more than the year before. That number will keep growing. This is why "we updated last month" isn't a plan.

+42%year-over-year growth in disclosed WordPress ecosystem vulnerabilities
31/daynew holes disclosed on an average day — weekends included
Where the Holes Live

91% of new holes are in plugins.

And here's the part almost nobody knows: it's not WordPress itself. The core software is well-guarded by a full-time security team. The holes turn up in plugins — the add-ons doing contact forms, SEO, caching, page-building. Every plugin you add is extra code with deep access to your site. That's where the doors are.

WordPress corewell-guarded
Forms
SEO tool
Cache
Page builder
Old gallery

Every plugin = extra code with deep access. That's where the doors are.

The Third Door

Your login is a door too. And you hold the key.

Outdated plugins are one way in. A guessed or stolen password is the other. Bots try millions of common passwords a day — and reusing a password from another site means one leak anywhere hands over your website. The fix is yours to make, today: a long, unique password (three unrelated words beats one clever one) and two-factor login if your platform offers it. Unlike plugins, this door never needs a developer — you can lock it tonight.

The Stat That Changes Everything

When a serious hole goes public, attacks start in 5 hours.

HOUR 0

A researcher publishes a serious plugin flaw

HOUR 5

Bots start exploiting it — median time, across all 2025 disclosures

DAY 2–7

Mass scanning: every site running that plugin gets hit

Often before the developer has even finished the patch. If you update weekly, you're statistically updating after the attack wave passed.

"Can't I Just Update More Often?"

It's not a discipline problem. It's a math problem.

About 36 new WordPress plugin vulnerabilities come out every day. And nearly half of them ship with no fix available at all yet. A person reading update alerts and clicking "update" can't beat that. Nobody's willpower can.

36new WordPress plugin vulnerabilities disclosed per day, on average
46%of them have no patch available at disclosure
Knowledge Check

A critical flaw in a plugin you use is announced publicly. How fast do attacks typically start?

A

About a week — there's time to get to it on the weekend

The 5-hour median kills the "weekend update" plan — half of all exploited flaws are attacked within 24 hours of going public.
B

Within hours — the median is around 5 hours

Correct. Attackers scan the moment a flaw is public. This is why real-time monitoring and fast patching beat a weekly update habit.
C

Weeks — vendors notify everyone first

Vendors need time to write patches; bots don't wait for them. Disclosure and exploitation are nearly simultaneous now.
D

Only if your site is famous or high-traffic

Mass scanning hits every exposed site running the plugin. Traffic doesn't protect you — the bots don't check your visitor count first.
Updates Done Right

The safe update, in one picture.

Updates have to happen, and they have to be fast — but they also have to be safe. Here's the loop, every single time:

1TEST

on a staging copy — a full clone of your site

2BACK UP

before touching the real site

3APPLY

to the live site

4VERIFY

forms, pages, features all working

Skip the testing, and an update can silently break a form for weeks. Skip the backup, and there's no way back. This loop is the whole trick — and it's what we do at WebsiteCare.Direct every single time.

Your roof is being built. Next: the emails.

That's the machine-level threat — and why updates can't be a once-a-month chore. You've also locked the third door tonight: your login. Next lesson, the other big way in: your inbox. That test-then-apply loop in this lesson? It's our entire update process, running on your site, every time. 24/7 monitoring, staging-tested updates, daily tested backups — from $49/month, month-to-month, no contract.