Most website attacks are not aimed at you. Automated scripts scan thousands of sites a day for known weaknesses, and yours is either on the list or it is not. These five signs suggest it might be.
1. The browser shows "Not secure"
Look at the address bar. If you see a padlock, your connection is encrypted. If you see "Not secure", or the site starts with http:// instead of https://, visitors' form entries travel in plain text. Google also ranks these sites lower. Fix: install an SSL certificate (free from Let's Encrypt) and redirect all traffic to https://.
2. Nobody has updated it in six months
Outdated WordPress core, themes and plugins are the number one way small sites are compromised. If you cannot remember the last update, assume you are behind. Log in to the dashboard: any red update badge older than a month is a risk.
3. You have plugins you do not recognise
Every plugin is code someone else wrote and you must trust. Check the list. If you find plugins you do not use, or ones that have not been updated by their authors in over a year, remove them. A typical business site needs four to eight plugins, not twenty.
4. There is no recent backup you have tested
Ask your web team or host: when was the last backup, where is it stored, and when did anyone last restore from it? A backup on the same server as the site disappears in the same attack. Good practice is daily, off-site, and a test restore each quarter.
5. Your admin login is the easy one
If the login page is at /wp-admin, the username is admin, and there is no two-factor code, you are giving scripts an easy job. Fix: use a unique username, a long password from a password manager, two-factor authentication, and limit login attempts.
What to do next
If you failed two or more of these, treat it as urgent. You can request a free security and speed check and we will send a plain-English report within two working days, or explore our Care Plans if you would rather hand the job over.


