For twenty years, WordPress has been the default way to build a website, and it still powers a huge share of the web. The software at its center is well maintained. But the way WordPress sites get attacked has changed, and if you own one, it's worth knowing how much time you have when something goes wrong. The answer is about five hours.
The five-hour window
When a security flaw in WordPress software is made public, attackers start scanning the internet for sites that haven't fixed it. According to Patchstack's State of WordPress Security in 2026 report, the median time from public disclosure to the first attack attempts is five hours. Not five days. Five hours.
That changes what "keeping your site updated" has to mean. A monthly update routine, or updates whenever someone gets around to them, leaves a site exposed for weeks after attackers are already at work.
The risk lives in plugins
WordPress core, the main software, is rarely the problem. Patchstack counted 11,334 new vulnerabilities across the WordPress ecosystem in 2025, up 42% from the year before. Only two were in WordPress core. Ninety-one percent were in plugins.
That matters because a typical WordPress site runs dozens of plugins, each written and maintained by a different team, and each able to reach deep into the site. Some are maintained carefully. Some are abandoned. Nearly half of the vulnerabilities in 2025 were made public before the plugin's developer had released a fix.
Plugins can also change hands. In April 2026, it came to light that someone had bought more than thirty established WordPress plugins, quietly added a hidden backdoor in an ordinary-looking update, and waited eight months before switching it on. Site owners who did everything right, installing trusted plugins and applying updates promptly, installed the backdoor themselves.
Core can still surprise you
Core isn't immune. In July 2026, a pair of flaws nicknamed wp2shell let attackers take over unpatched WordPress sites running versions 6.9 or 7.0, with no login and no vulnerable plugin required. Fixes shipped quickly, and Cloudflare added protective rules for sites behind its network, but every site still had to be updated. Exploits were circulating within days.
Your host's firewall probably isn't enough
Many owners assume their hosting company's firewall catches these attacks. Patchstack tested that in 2025: common hosting defenses blocked only 12% of WordPress-specific attacks, and 26% when the test included more general ones. Generic firewalls are built to stop broad, familiar patterns. They usually can't see the flaw in a particular plugin.
Questions to ask about your site
Whoever maintains your website, whether it's you, a staff member, or an agency, should be able to answer these:
- How many plugins does the site run, and does it need all of them? Every plugin you remove is one fewer thing to patch.
- How quickly are security updates applied? Within hours of release, or on a schedule measured in weeks?
- Who watches for vulnerabilities in your specific plugins? A service that monitors your exact plugin list, and can block an attack before a fix exists, closes the gap a firewall leaves.
- Are any plugins abandoned? A plugin without an update in a year or more deserves a replacement plan.
- When was a backup last restored, not just made? A backup you've never tested is a hope, not a plan.
- If the site were compromised tonight, who would notice, and how?
When it makes sense to stay, and when to move
For many businesses, the right answer is to keep WordPress and tighten how it's run: fewer plugins, fast updates, active monitoring, and tested backups. A well-run WordPress site is a reasonable choice.
For others, especially sites that are mostly pages, posts, and forms, the plugin stack has become more risk and maintenance than it's worth. Newer approaches avoid much of that exposure. Sites built with frameworks like Astro, which Cloudflare acquired in early 2026, can run with no plugin folder, no public login page, and far less to patch. If a redesign is on your horizon, that's the natural time to weigh it.
Not sure where your site stands?
We maintain WordPress sites and build on newer platforms, so we can give you a straight answer either way. Book an intro call or email support@alpine.io, and we'll review your plugins, your update routine, and your backups, and tell you plainly what to fix first.