Hackers know that many websites are not secure and are easy targets. In 2019 the number of hacked websites rose by 32 percent. This is alarming and shows how risky websites can be. Google believes that this number will continue to grow.
There are many different ways in which hackers can get into your website.
Uninstalled Security updates
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
The lack of essential updates to your website may put your site at risk. Always be on the safe side by making sure that you have updated your web server software, CMS, plugins, and all the software that is being used by your website.
Vulnerable themes and plugins
Some developers do not continue to maintain plugins and themes. These themes and plugins become obsolete when they are not updated regularly.
This is very dangerous and will likely lead to a website compromise. Be sure that all of your website components are actively being updated. If you see a theme or plugin that has not been updated for months, then you can assume that the developer is no longer supporting it. Be sure to remove it from your site!
Some free plugins are created by hackers who want you to install them on your website. The hackers use those installed plugins as an access point to your site. So be careful what you use on your website.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Shared hosting
Your site could be vulnerable when it is being hosted on shared hosting. Other websites that are hosted on the same server may not be patched and may be vulnerable to hackers. Hackers could use one of the vulnerable website to get into the server that is hosting your website. This risk can be mitigated by hosting providers through the isolation of resources within the server.
Passwords
Make sure that you change the default usernames and passwords in your site or your server. Some people forget to change the password and continue to use the default password. You need to create a strong password that is not easy to guess and is not predictable. Adding two-factor authentication is recommended.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
How to Stay Secure Managing End-of-Life Software
Legacy software often operates under the "if it isn't broken, don't fix it" mentality until a security crisis forces action. However, managing...
Best 6 Tools to Eliminate CVEs in Container Images
Key Takeaways Container image CVEs often come from inherited base image packages, not only application code. The strongest tools reduce vulnerabilities before...
8 Best Virtual CISO Companies of 2026
The virtual CISO market has changed. A few years ago, many companies hired a vCISO mainly to prepare for SOC 2, satisfy...
The 5-Minute Cyber Brief: September 1, 2026
The fastest way to catch up on what changed after this article was published.