Your small business website is a realistic hacking target, but probably not for the reason you think. Almost nobody is sitting down and deciding to target your plumbing company or med spa by name. Automated bots scan the entire internet around the clock looking for outdated software and weak passwords, and they hit whatever they find, regardless of how big or small the business behind it is. I build custom websites for service businesses, and this question comes up almost every time I explain why I do not build on WordPress.
I have been doing this for over 20 years, and I have seen the aftermath of a lot of hacked small business sites that were never anyone's specific target. They just happened to be running old, unpatched software that a bot found before anyone noticed. Let me walk through what actually causes this, and what actually stops it.
Is My Small Business Website Actually a Hacking Target?
Yes, statistically, whether or not anyone would ever "target" you personally. Attackers do not manually browse the web looking for small businesses to pick on. They run automated tools that scan millions of sites for a handful of known weaknesses: an outdated plugin with a published vulnerability, a login page with no rate limiting, a password that shows up on a leaked credentials list. Your site gets scanned the same way a bank's site does. The difference is what happens next, since a bank has a security team watching for exactly this, and most small businesses do not.
That is the real risk. It is not a person with a grudge, it is an automated process that does not care who you are and will absolutely exploit a gap if one exists.
What Actually Gets Small Business Websites Hacked?
In my experience, it almost never comes down to one dramatic breach. It is one of a short list of ordinary gaps:
- Outdated CMS software or plugins. WordPress itself gets patched regularly, but a site running plugins that have not been updated in a year is running code with publicly documented holes that anyone can look up.
- Weak or reused passwords. An admin password that is also used on some other site that got breached years ago is often all it takes, especially with no limit on login attempts.
- No two-factor authentication. A stolen or guessed password becomes a dead end the moment a second login step is required, but most small business site logins skip this entirely.
- Nulled or pirated plugins and themes. Free "cracked" versions of premium plugins are a known way malicious code gets planted directly into a site during installation.
- Abandoned admin accounts. A former employee or an old freelancer's login that nobody ever removed is a door nobody is watching.
None of these require a sophisticated attacker. They are the digital equivalent of an unlocked back door, and bots are built specifically to check for unlocked doors at scale.
Why Do WordPress Sites Get Hacked More Often Than Static Sites?
The honest answer is surface area. A CMS like WordPress runs on a database, a login panel, and typically a dozen or more plugins, each one a separate piece of software that needs its own updates and can carry its own vulnerabilities. A static, custom-coded site has none of that.
| Site type | What can be exploited | Who has to keep it patched |
|---|---|---|
| WordPress with plugins | CMS core, database, every installed plugin and theme, the login panel | You, or whoever manages the site, on an ongoing basis |
| Page builder (Wix, Squarespace) | The platform itself, though the vendor patches it centrally | The vendor, mostly out of your control either way |
| Static, custom-coded site | The hosting layer only, no database or plugin library to exploit | Whoever manages hosting, with far fewer moving parts |
This is one of the main reasons I build every site static and custom-coded instead of stacking plugins on a CMS. There is no login panel for a bot to hammer with guessed passwords, no database to inject malicious code into, and no plugin library that needs someone tracking updates every month. It does not make a site invincible, but it removes most of the attack surface bots are actually scanning for.
What Are the Warning Signs My Website Has Been Hacked?
A few things tend to show up together when a site has actually been compromised:
- A Google Safe Browsing warning appears when visitors try to reach your site, or Google Search Console flags a security issue directly.
- Pages you never created suddenly exist, often stuffed with spammy keywords or links to unrelated products.
- Your site redirects visitors to a different website entirely, sometimes only when they arrive from a Google search.
- Your hosting provider emails you about unusual outbound traffic or a suspended account.
- Google's own guidance on hacked sites walks through exactly what these flags look like from the search side, which is often how business owners find out in the first place, from a customer who mentions the warning rather than noticing it themselves.
A site that just looks slightly off, loads slowly, or has a lapsed SSL certificate is usually a different, much smaller problem, not a hack. I cover the SSL-specific version of that panic call in why your website might say not secure, which is worth ruling out first before assuming the worst.
How Do You Actually Protect a Small Business Website?
The fixes are unglamorous, which is exactly why they get skipped:
- Use a unique, strong password for every login, ideally generated and stored in a password manager rather than something you can remember and therefore reuse.
- Turn on two-factor authentication anywhere it is offered, especially for hosting accounts, domain registrars, and any CMS admin panel.
- Keep software current, or better, build on something that does not require constant patching in the first place.
- Back up daily, off the site itself, so a hack cannot take the backup down along with the original.
- Remove access you no longer need, including old employee or freelancer logins that were never cleaned up.
The FTC's cybersecurity guidance for small businesses covers the same fundamentals from a broader angle, since almost none of this is website-specific. It is the same basic hygiene that protects any small business's accounts and data, just applied to the site.
On my $150-a-month plan or the $3,500 one-time build, hosting, backups, and software updates are handled as part of the package, since I would rather build security into the process than have a client discover a gap the hard way. I have covered the maintenance side of this in more depth in what website maintenance actually costs and covers, including why security patching is a real line item and not an afterthought. It matters even more for businesses like med spas collecting client intake information through a contact form, where a breach means more than an embarrassing redirect.
What Should You Do If Your Website Gets Hacked?
Move fast, but in the right order. Take the site offline or put it in maintenance mode first, so it stops serving malicious content to visitors and search engines. Restore from your most recent clean backup rather than trying to manually hunt down and delete every infected file, since a partial cleanup often leaves a way back in. Change every password tied to the site, hosting account, and domain registrar, not just the one you suspect was compromised. Then request a review in Google Search Console once you are confident the site is clean, so any Safe Browsing warning gets lifted.
If there is no clean backup to restore from, that is usually when a full rebuild ends up being faster and cheaper than a manual cleanup, especially on an older site nobody has been maintaining closely.
What Should You Do Next?
- Check who currently owns your logins. If you cannot list every person with admin access to your site, hosting, and domain right now, that is worth fixing today, hack or no hack.
- Confirm you actually have a recent backup. Not "there's probably one somewhere," an actual, tested, recent backup stored separately from the site.
- Run a full site check. My free speed test also flags security and best-practices issues alongside load time, so you can see where things stand in one pass.
- See what a properly maintained site looks like. Browse real client sites in my portfolio to see examples where hosting, backups, and updates are handled as one package instead of something nobody owns.
- Get a free mockup. If you are running an older, unmaintained site and this is making you nervous for good reason, I will put together a free homepage mockup with no cost and no obligation.
Most small business websites do not get hacked because someone decided to target them. They get hacked because an automated scan found an unlocked door that nobody had checked on in a while. Close the obvious gaps, and you have already handled the part that actually matters.
