Article

Your Website Isn't Just Outdated. It's a Liability

If your business runs on WordPress, "everyone uses it" used to be the reassuring part. In 2026, it is the dangerous part. AI has made attacking websites cheap - and the real cost lands on your reputation, your customers, and your ability to trade.
A commercial front door with a solid main lock surrounded by mismatched secondary locks, several left open or with keys still in them - representing a website that looks secure at the surface but is exposed through accumulated third-party entry points

Stuart Totterdell

Technical Director

Your website is not a brochure that sits quietly in the corner. It is where customers find you, where enquiries come in, and where trust is either confirmed or quietly lost. If it goes down, looks compromised, or starts serving something you did not put there, the damage is commercial long before it is technical.

WordPress still powers a huge share of the web, which is exactly why it is now such an attractive target for attackers. Scale used to feel like safety in numbers. For a business owner, it now means your site sits in a very large crowd of similar businesses - all of which can be scanned, sorted, and hit at industrial speed.

Here is why that matters for the business - and what the smartest owners are doing about it before it becomes their problem.

The short-term risk: you are already a target, whether you know it or not

This is not hypothetical. In July 2026, researchers disclosed a serious flaw in the core WordPress software that runs a huge share of business sites - not an optional add-on, the foundation itself. It lets an attacker break in without a password, without tricking a member of staff, and without needing anything unusual installed. WordPress treated it as serious enough to force updates automatically wherever it could. Even so, tens of millions of sites were in the vulnerable version range when the flaw became public - and forced updates do not reach every install.

What that means in practice: downtime while someone cleans it up, customers who cannot reach you, staff time you did not budget for, and the awkward question of whether anything customer-related was touched. If your web designer has not already told you exactly what they did about this, that is worth a phone call today.

The medium-term risk: attacking businesses just got cheap. Defending them didn't

This is the part most owners have not clocked yet, and it changes the commercial equation.

That same flaw was found using an off-the-shelf frontier AI model available via a standard paid subscription. End to end - finding the weakness, combining it with a second one, and turning it into a working attack - took a little over ten hours and cost about twenty-five pounds in computing time. What used to need a skilled, patient specialist can now be done by almost anyone with a laptop and a subscription.

It gets worse for the businesses on the receiving end. A research team built an AI scanning setup in three days and used it to find more than three hundred previously unknown high-severity weaknesses across common WordPress add-ons - in seventy-two hours. Fresh ways into WordPress sites are now being priced at around twenty pounds, because AI has made them that cheap to discover.

Over eleven thousand new WordPress weaknesses were logged in a single recent year - a forty-two percent jump on the year before, and that was before AI-driven scanning fully ramped up. The trend is not flattening. It is accelerating.

Translate that into business language. The cost of finding a way into a site like yours is collapsing. The cost of a messy cleanup - lost enquiries, reputation damage, insurance conversations, forensic work, rebuild time - is not. The forms, booking tools, and marketing extras a developer set up once and nobody has reviewed since are exactly what this new wave of automated attacks is built to find.

The long-term risk: this isn't a bad year. It's the new normal

Some owners will read the above and think: this will blow over, we will patch it, we will move on. That was a reasonable assumption in 2015. It is not anymore.

The deeper problem is not any single incident - it is the way the platform works. A typical business site depends on twenty to thirty third-party extras, each built by a different team, updated on a different schedule, with no one accountable to you for the whole stack. Every one of those is a separate door into your customer-facing presence, maintained by people you have never met, to a standard you have no practical way of checking. This year alone, attackers have shown they do not even need to find a bug - they have bought ownership of trusted add-ons and quietly pushed harmful updates to every business running them, sometimes waiting months before switching anything on.

That is not a one-off glitch you can patch and forget. That is the business model of the platform. And as AI keeps driving the cost of finding new ways in toward zero, the number of businesses that can realistically keep up - permanently, add-on by add-on, forever - gets smaller every year, not bigger.

The honest long-term forecast: the gap between attacker capability and typical small-business defence is going to keep widening. Staying on WordPress does not mean accepting today's risk. It means accepting a risk that compounds every year you stay - to revenue, reputation, and continuity. That is the kind of platform decision independent tech consultancy is meant to force into the open - not after a breach, but while you still have options.

What to do about it

You have two real options.

Option one: stay, and treat website security as a real operating cost. That means proper managed hosting, disciplined updates, active monitoring, and a named person watching for exactly this kind of AI-accelerated threat - not "we will get to it." Done properly, this is an ongoing line item and an ongoing job, not a box you tick once. It also needs to sit inside a clear IT and process strategy for who owns updates, who gets the alert when something looks wrong, and what happens when the next emergency fix lands.

Option two: remove the risk at the root. Rebuilding your site through proper development and build on a modern platform means you are no longer carrying a marketplace of third-party add-ons that can be compromised, and you are no longer exposed every time the shared WordPress foundation has another bad week in the news. You are not managing a smaller version of the same risk. You are simply not carrying it. Your team can still edit content through a familiar CMS - day-to-day marketing does not have to change - while the business stops living with the attack surface that has been making headlines all year.

If a redesign is already on your radar, this is the moment to make that call - not after an attacker makes it for you.

A commercial front door with a solid main lock surrounded by mismatched secondary locks, several left open or with keys still in them - representing a website that looks secure at the surface but is exposed through accumulated third-party entry points

Not sure how exposed your current site is?

We'll run a quick, no-obligation check - plugin count, outdated software, and whether you're carrying the risks covered here - and tell you straight whether it's a patch job or time to talk about a proper rebuild.

Get a website risk check