Sep 18 / Latest News

Survey Shows Most WordPress Professionals Have Faced Security Incidents but Lack Recovery Plans

A new survey of 319 WordPress professionals shows that security incidents are widespread across the ecosystem, yet most organizations still lack a formal recovery plan to guide their response when a breach occurs.

The study, conducted by Melapress, gathered input from agency staff, developers, designers, site owners, and administrators who build and maintain WordPress sites for a living. Across the group, fewer than three in ten respondents said they have a documented recovery plan. Without one, critical decisions — who responds, where clean backups are stored, and who must be notified — are made in the middle of an incident rather than in advance.

Downtime was the most common impact of a security incident, reported by 68.4 percent of respondents who described the consequences of an attack. Many incidents were discovered not by automated tools but by someone noticing the site behaving abnormally. That “someone” could be a visitor, customer, colleague, or administrator, and by the time the issue is spotted, the disruption is often already underway.

Logging tools were the monitoring control that most frequently detected incidents, followed by hosting provider alerts and malware scanners. But late discovery often correlates with more severe damage. When search engine warnings surfaced an incident, 46 percent of those cases involved lost search rankings, compared with 14.5 percent of incidents detected through other means. The warning itself does not cause the harm; rather, incidents that persist long enough to be flagged by search engines tend to be more advanced.

One ecommerce site owner reported learning through Google Search Console that traffic had collapsed after a hack, noting that rankings “never fully recovered.”

Melapress recommends that organizations create and test breach recovery plans before they are needed. A proper plan defines who isolates compromised systems, who restores the site, and who communicates with customers. The researchers emphasize that backups must be tested — a backup that has never been restored is only an assumption until the moment it is needed.

Training is also highlighted as a core control. Content editors and administrators make daily decisions that affect security, and site owners should know who receives security alerts, even when an agency or freelancer manages the site.

The findings underscore that WordPress security incidents are common, often detected too late, and frequently worsened by the absence of preparation. Recovery planning, monitoring, and training remain some of the most significant gaps across the WordPress ecosystem.