This week, a wave of attacks hit WordPress sites across the world. The method was not the old, clumsy sort. It came from AI-driven bots running distributed denial of service tactics that adapt while they run.

I have spent enough years inheriting other people’s websites to know what days like this expose. They do not create the weakness. They find the weakness that was already sitting there, quietly, waiting.

So let me start plainly. A live website is not a finished object. It is an active operating system that decays and gets tested the moment you stop maintaining it.

What Made This Attack Different

Traditional attacks followed scripts. You could write a rule to block them and move on.

These do not behave that way. AI-powered botnets adapt in real time, learn from failed attempts, and rotate user agents and IP addresses to dodge detection. When a firewall rule activates, the traffic mutates to slip past the matching pattern.

The numbers behind the trend are hard to ignore. DDoS attacks targeting login endpoints doubled year on year, and 94% of login attempts are now bots.

There is a detail here that changes how you should think about defence. These precision botnets do not try to flood your bandwidth. They target expensive parts of your application. Login flows. Session checks. Checkout pipelines.

The result is deceptive. Your bandwidth dashboard stays green while the application itself collapses.

Why “Just Keep Your Plugins Updated” No Longer Holds

For years the standard advice was simple. Update your plugins and you will be fine.

I want to interrogate that, because it is exactly the kind of received wisdom that fails quietly.

In 2025, 11,334 new vulnerabilities were disclosed across the WordPress ecosystem, a 42% rise on the year before. Ninety-one per cent of those sat in plugins rather than core software.

Here is the part that undoes the old advice. The median time from public disclosure to active exploitation dropped to five hours. Roughly half of vulnerabilities get exploited within 24 hours.

If you patch weekly, you are statistically patching after the attack wave has already passed through your site.

It gets sharper still. Nearly half of vulnerabilities disclosed in 2025 had no fix available from the developer at the moment they went public. So even a diligent owner, updating the instant a patch appears, has no patch to apply for a good stretch of the danger window.

The Foundation Problem

When I take on a site someone else built, I grade the foundation before I build anything on top of it.

I learned this the hard way. Compounding effort on an unsound base produces the wrong results, no matter how good the work you stack on it.

Security research shows that 86% of hacked WordPress sites were running outdated core software, plugins, or themes. That is not a technology failure. That is a maintenance failure, and maintenance is a discipline, not an event.

Around 13,000 WordPress sites get hacked every day. The attacks are not rare. The unmanaged sites simply present the easiest targets.

Separating What You Control From What You Cannot

You cannot control when a new vulnerability is disclosed. You cannot control when a botnet decides to sweep the web. You cannot control the tempo of AI-driven attack tooling.

Naming that clearly matters, because it stops you pouring energy into things outside your influence.

What you can control is the standard of care applied to your asset. The monitoring. The response time. The backstops that make the next shock land softer.

New attack methods raise the tempo of maintenance. They do not change the underlying truth. Unmanaged assets rot quietly, and they get probed the instant you stop watching them.

What Continuous Management Actually Looks Like

People often ask me for a one-off security fix. The request is understandable, but it is rarely what serves them.

The underlying need is different. It is confidence that the asset holds up while they run their business.

Here is what proper website management involves in practice.

None of this is a magic bullet. I will not promise you a guarantee against a threat nobody fully controls. What I will promise is a defined standard of care, applied consistently, with someone accountable for it.

Why a Service Level Agreement Changes the Equation

This is where a Service Level Agreement earns its place.

An SLA converts protection from something you remember to do into something structurally guaranteed. It sets defined standards for uptime, response times, and the maintenance rhythm your asset needs.

The value is predictability. You get a foundation you can build growth on with confidence, because the care is written down and owned, not left to whoever happens to notice the problem.

For a business running WordPress as a revenue channel or a lead source, this is not abstract. A compromised site gets blacklisted by Google, loses customer trust, and often goes down during the exact campaign it was built to support.

The Practical Path Forward

Yesterday’s attack will not be the last of its kind. The tooling behind it improves every month.

So treat your website the way you would treat any live asset that carries real value. Grade its foundation. Maintain it continuously. Put a defined standard of care in writing.

If you want your site checked properly, and a maintenance and security agreement built around how your business actually operates, that is the work I do. Fast and sound, with someone accountable for the result.

Book a review of your site’s current foundation. I will tell you honestly where it stands and what it needs to hold up under the attacks now in play.

Enquire Now