This past summer, WordPress websites started getting hacked. Not one website. Not one hosting company. Not one unlucky developer who forgot to update a plugin. Websites worldwide were being compromised—and suddenly, those of us who develop and manage WordPress sites had to quickly become cybersecurity experts.

I started building websites more than 20 years ago. Back then, the job was pretty straightforward: build the website. Make it look good. Make it work. Make sure people could find what they needed. I quickly learned HTML, PHP, SEO, SSL’s, SMTP, coding, analytics, hosting, servers, e-commerce, website performance, accessibility, email systems, security, and then slowly became proficient in the approximately 4,782 other things that apparently fall under the phrase “web developer.”

And that’s fine. Technology changes, the job evolves; you’ve got to evolve with it.  I can roll with that.

But somewhere along the way, “web developer” quietly expanded to include code debugger, firewall administrator, malware detective, bot bouncer, password police, server security analyst, and the person who gets the call when some jackass halfway around the world desperately tries hacking into Bob’s Plumbing & Heating.  Awesome. 🤪

Which is quite the evolution, considering website security used to consist largely of telling clients not to use “password123” as their password. Remember those days? How adorable. Those were innocent times.

So, now I fight bots! 

I’ve got firewalls behind firewalls, bots fighting other bots, passkeys, two-factor authentication, malware scanners, Cloudflare, Cloudflare Turnstile, reCAPTCHA, Wordfence, encrypted forms, and enough security layers that I’m approximately one retina scan away from protecting the nuclear launch codes.

And as ridiculous as that sounds, lately I’ve been reminded that none of it is really ridiculous at all.

Because WordPress itself had a pretty bad day.

This past summer, a serious security vulnerability was discovered in WordPress itself.  Not a sketchy plugin that hadn’t been updated since the first Obama administration. Not a questionable theme someone downloaded for free from a website with 17 pop-ups. Not because somebody’s password was password123.

It was WordPress Core.

On July 17, WordPress released an urgent security update addressing two vulnerabilities—one critical and one high severity. Read more about it here. One vulnerability could allow an attacker to run malicious code on an affected website.

In non-cybersecurity language: The hackers could get into places they absolutely do not belong and seriously start messing with things.”

Which, you know…. is generally considered bad.

WordPress urged affected sites to update immediately—and they weren’t being dramatic. Because of the severity of the vulnerabilities, WordPress took the unusual step of enabling forced automatic updates for websites running affected versions.  WordPress security researchers reported that attackers were already attempting to exploit the vulnerability on real websites. Even more concerning, an attacker didn’t necessarily need a username or password to try. Website owners were advised not only to update WordPress, but also to check for unfamiliar administrator accounts and other signs that someone may have already gotten in.

An update can lock the door. It doesn’t necessarily tell you whether somebody already walked through it.

So, If Your Website Got Hacked This Summer…

If you discovered a strange administrator account (yes, I’m looking at you “wp2shell”), malware, unfamiliar files, or other suspicious activity on your WordPress website around this time, this vulnerability could be one reason why. It wasn’t an attack aimed at one particular company, industry, or website. Security researchers warned that vulnerabilities like this can be exploited at scale, with automated attacks scanning the internet for vulnerable WordPress installations. Your website didn’t have to be important, controversial, or particularly interesting to a hacker. It simply had to be running an affected version of WordPress when the bots came looking.

And that’s something I think a lot of business owners don’t realize about website hacking. In many cases, nobody is sitting in a dark room somewhere saying, “Today, we take down Bob’s Plumbing & Heating.” Automated systems constantly scan the internet for known vulnerabilities they can exploit. When they find one, they don’t particularly care whether the website belongs to a Fortune 500 company or a local landscaping business.

Sometimes the only reason your website became a target is that it was there.

This Isn’t a WordPress Problem. It’s a Technology Problem.

Before this turns into a “WordPress is unsafe, and we should all run for the hills article,” that’s not my point at all. A serious vulnerability in WordPress sounds alarming—and obviously, it needs to be taken seriously—but a vulnerability doesn’t automatically mean the technology itself is bad or fundamentally unsafe.

The reality is much simpler: technology has issues.  ALL technology.

Your phone has issues. Your computer has issues. Your car has software recalls. Apps crash. Browsers develop security vulnerabilities. Servers fail. Credit card processors go down. Microsoft releases patches. Apple releases patches. Google breaks things. Software that worked perfectly yesterday occasionally decides it would rather not work at all today.

Anything built by humans, running on constantly evolving systems and interacting with other constantly evolving systems, will need attention. Bugs are discovered. Security vulnerabilities are found. Software changes. Updates are released. One update fixes something and occasionally introduces an entirely new problem just to keep everyone humble.

Websites are no different. And the point of this post is to say, if you are using technology, you have to have someone paying attention to said technology.  LONG GONE are the days of building a website and putting it on the shelf for two years when you decide to make some updates.

What happened with WordPress is actually an example of the process working the way it’s supposed to. A vulnerability was discovered, a fix was developed, an updated version was released, and affected websites were urged to install it.

Technology will have problems, absolutely. You’ve just got to have someone watching when it does

Because discovering a vulnerability and releasing a fix is only half the equation. Somebody still has to know the problem exists, understand whether it affects the website, install the update, make sure the site wasn’t compromised before the fix was available, and then confirm that the update itself didn’t break something else in the process.

And that’s assuming everything goes exactly as planned.

🤖 Sometimes an update conflicts with a plugin.

🤖 Sometimes a plugin that was perfectly safe when it was installed develops a vulnerability years later.

🤖 Sometimes an old administrator account is still hanging around long after that person should have lost access.

🤖 Sometimes a backup hasn’t been working nearly as reliably as everyone thought.

🤖 Sometimes a website looks perfectly normal on the front end while something considerably less normal is happening behind the scenes.

None of those things necessarily mean someone did anything wrong. They’re simply part of owning and operating technology. The difference is whether someone pays enough attention to notice when something changes.

And THAT is where website ownership has changed so dramatically since I started doing this more than 20 years ago.

There was a time when building the website was the bulk of the job. You designed it, developed it, launched it, and, aside from updating the content now and then, everybody pretty much went on with their lives. That’s simply not how websites work anymore. Today’s websites connect to hosting environments, databases, plugins, APIs, payment processors, email systems, analytics platforms, search engines, and dozens of other moving pieces that are constantly updated and changed.

That means launching it isn’t the end of the job. Somebody has to keep an eye on it, maintain it, protect it, update it, and know what to do when one of those moving pieces inevitably causes a problem.  Because eventually, something will.  That’s not a failure of the technology. That’s the reality of using technology.

A Website Isn’t Something You Build, Launch and Forget About

And that, ultimately, is the bigger lesson in all of this. A website isn’t a finished product sitting on a shelf. It’s a living piece of technology operating on an internet that never stops changing. A website is technology, and like every other piece of technology we rely on, it needs maintenance, updates, and occasional rescues when it decides to do something completely unexpected.

The problem is that we’ve gotten very good at making websites look incredibly easy to build.

WordPress templates, Wix, Squarespace, Shopify, drag-and-drop builders, and now AI tools can practically build the damn thing while you make lunch. And honestly, that’s great. For a lot of small businesses, especially when they’re just getting started, building their own website can make perfect sense.

But there’s a pretty significant difference between building a website and knowing how to manage one.

That’s the part nobody puts in the commercials.

They show the cheerful small-business owner drinking coffee, casually dragging a photo into a template, clicking Publish, and admiring her beautiful new website. They don’t show her three years later, still in her pajamas at 11:47 a.m., frantically Googling “WHY IS MY WEBSITE REDIRECTING PEOPLE TO A JAPANESE CASINO?”

And I’m not knocking DIY websites. If you have the time, patience, and willingness to learn, you absolutely can build one yourself. But getting a website online is only the beginning. Once it’s there, somebody still needs to take care of the technology behind it.

Because….Building It Is Only the Beginning

A modern website has a lot happening behind the pretty pictures and carefully chosen fonts. WordPress changes. Plugins change. PHP changes. Browsers change. APIs change. Google changes. Security threats change. Updates need to be installed, but they can conflict with one another or break something that worked perfectly five minutes ago. Backups need to happen, but they’re not terribly useful if nobody knows whether they actually work. Plugins can develop vulnerabilities, user accounts need monitoring, malware needs detection, bots need blocking, and performance needs watching.

Then, every once in a while, something like the recent WordPress vulnerability happens, and suddenly an ordinary update becomes far more urgent.

That’s where having somebody actively managing a website becomes important. It’s not just a matter of clicking an Update button. Someone needs to understand what the vulnerability is, whether the website is affected, what needs updating, whether anything suspicious happened before the vulnerability was patched, and whether the website still functions properly afterward.

That’s a very different job from simply putting a website online.

Which Is How I Apparently Became a Cybersecurity Expert

And this brings me right back to where I started.  Over the years, my definition of “web development” has expanded considerably. I still design and build websites, but managing them has become just as important. The websites I manage now sit behind multiple layers of security, including managed hosting, firewalls, Cloudflare, Wordfence, malware protection, backups, passkeys, two-factor authentication, and bot protection. I manage WordPress, theme and plugin updates, monitor compatibility and performance, pay attention when new security issues are discovered and, on particularly exciting days, have conversations with my hosting company about malicious PHP files that I sincerely wish I knew considerably less about.

Living the dream.

None of that is because I think WordPress is inherently unsafe. Quite the opposite—I still build in WordPress and have no intention of stopping. It’s because WordPress is technology, websites are technology, and technology occasionally has problems. The more important question is whether somebody is there who knows what to do when it does.

So, Do You Really Need a Professional?

Not necessarily to build a website, I guess… I’ll say that even though it’s probably terrible marketing.

Plenty of smart business owners can build a perfectly decent website themselves, and more tools than ever help them do it. But I don’t think whether you can build your own website is really the question business owners should be asking anymore.

The question is: Who’s taking care of it after you build it?

Who knows when an urgent security update has been released and whether it affects your website? Who notices an administrator account that shouldn’t be there? Who monitors the firewall, scans for malware, and makes sure backups are actually happening? Who knows whether it’s safe to install an update—or what to do when installing it causes something else to stop working?

And when some IP address halfway around the world attempts to log into your WordPress dashboard 614 times before you’ve had your first cup of coffee, do you really want to be the person figuring out what that means?

That’s where I think the value of hiring a professional has changed.  It’s not that business owners can’t learn how to do all of this. It’s not that YOU can’t learn how to do all of this. Of course you can. But you’re also supposed to know how to run your business, manage employees, take care of customers, market yourself, pay the bills, and do whatever it is you actually went into business to do. You shouldn’t also have to become a web developer, SEO specialist, server administrator, malware investigator and—apparently—cybersecurity expert just because your company needs a website.

Welcome to Web Development in 2026

I still spend my days designing websites. I still obsess over fonts, spacing, mobile layouts, Google rankings, and whether that button really does need to move down another 10 pixels. The difference is that now I’m doing all of that while keeping an eye on firewalls, security alerts, bots, software updates, and whatever fresh nonsense the internet has decided to throw at us this week.  Twenty years ago, a professional website was largely about having someone who knew how to build it. Today, I think it’s just as important to have someone who knows how to take care of it.

Because technology is going to have problems. That’s not going to change. The difference is having somebody there when it does.

And if you’ll excuse me…

EVERYBODY GET DOWN. I THINK THAT’S A BOT.