Skip to content
← All articles
7 min read

Website security: how small business sites get hacked and how to stop it

Small business sites are not targeted individually — bots sweep thousands of addresses looking for outdated CMS installs. Your business is irrelevant to them; your server is not.

Why anyone bothers

A compromised site is a resource in itself: hidden pages with someone else's ads, spam sent from your domain, redirects to dubious destinations, or the server used as a proxy.

The owner usually finds out last. The site looks fine while Google has already flagged it as unsafe and cut off organic traffic; restoring domain reputation takes weeks.

How they get in

Outdated CMS and plugins first. A vulnerability in a popular WordPress plugin goes public and bots start scanning the whole internet the same day — what matters is your patching delay, not the attacker's skill.

Then weak or leaked credentials: reused passwords, FTP access handed to a freelancer over Telegram years ago and never revoked, and unrestricted upload forms used to drop a shell script.

The baseline set

Regular updates, removal of unused plugins, unique passwords in a manager, two-factor authentication on admin, login attempt limits, no 777 file permissions, and a WAF in front.

Automated backups stored off the same server are non-negotiable: a backup sitting on the hosting that got compromised gets encrypted along with the site.

Need a website or ads? Let’s discuss your project.