Five hours. That’s all it takes now.
A flaw is found in a popular WordPress plugin. The details go public in the morning. By lunchtime, bots are already scanning the web for sites that haven’t updated.
That isn’t a worst-case scenario. According to Patchstack’s State of WordPress Security in 2026 report, the median time to mass exploitation for heavily targeted WordPress vulnerabilities is just 5 hours. Around half of high-impact flaws are being used in attacks within 24 hours of disclosure.
Most business owners still treat WordPress maintenance as a chore for “sometime this month.” In 2026 that gap between disclosure and your next update is exactly where websites get hacked.
Here’s what changed, why the old approach no longer holds up, and what your website needs instead.
What changed: more holes, found faster
WordPress itself is solid. The risk lives in the plugins and themes built on top of it, and there are more holes than ever.
- 11,334 new vulnerabilities were found in the WordPress ecosystem in 2025, a 42% jump on the year before.
- 91% of them were in plugins. Only 6 affected WordPress core, and all of those were low priority.
- 46% had no patch available when they were made public. Updating alone can’t protect you from those.
AI has joined both sides
Artificial intelligence has changed the pace. Attackers now use AI tools to scan plugin code at scale, spot exploitable patterns and build working attacks far faster than a human could.
The WordPress project has noticed. On 1 September 2026 it launched the WordPress Core Security Initiative, promising faster patch releases and AI-powered code analysis to find flaws before criminals do.
That’s good news, but it has a side effect for every site owner. Expect more updates, more often, with less time to test them. A site that isn’t watched continuously will fall behind.
Why “we’ll update it this month” no longer works
The window is weeks wide
If a critical plugin flaw goes public on the 3rd and your updates run on the 30th, your site is exposed for nearly four weeks. Attackers need five hours.
Auto-updates aren’t a safety net
Switching on auto-updates feels like the answer, but it swaps one risk for another. An untested update can clash with your theme, break a checkout or take the site down, often with no one watching and no recent backup to roll back to.
Your host’s firewall can’t catch everything
Many owners assume their hosting company handles security. Patchstack’s testing found that hosting-level defences blocked only 26% of vulnerability exploits. Hosts protect the server. They don’t know how your particular plugins are configured.
A hack costs far more than prevention
A compromised site means lost sales, spam redirects, blacklisting by Google and a cleanup bill. Then there’s the damage to your customers’ trust, which is harder to fix than any code.
What your website needs instead: continuous care
Keeping a WordPress site safe in 2026 is an ongoing process, not a monthly task. Use this checklist to see how your current setup compares:
- Round-the-clock monitoring of uptime, security settings and file changes, so problems are caught in hours, not weeks.
- Daily checks for new updates, with critical security patches applied fast.
- Updates tested before they go live, especially for custom or complex plugins, so a fix doesn’t break your site.
- A fresh backup before every change, stored off-site, so you can always roll back.
- Hardening beyond updates: malware scans, brute-force protection, two-factor login and file-change detection, to cover flaws that don’t have a patch yet.
- Clear reporting so you know exactly what was done and when.
- A real team to call when something looks wrong.
If you can’t tick at least five of these, your site is relying on luck. Most small teams simply don’t have the hours to do all of this in-house, every single day.
How WordPromise closes the window
WordPromise is an AI-assisted WordPress maintenance service built for this faster threat landscape. Our tools watch your site continuously, and our experts act on what they find. Every site runs on the same disciplined schedule:
| How often | What we do |
|---|---|
| Every hour | Monitor uptime, security parameters and key site vitals |
| Every day | Check for available updates and take full off-site backups (Amazon S3 and Dropbox) |
| Every week | Upgrade plugins, themes and WordPress core, with in-depth validation for custom plugins |
| Every month | Send a full report of every action taken and its result |
| Within 24 hours | Answer every support ticket |
Security that goes beyond updates
Because nearly half of new flaws have no patch at first, updating alone isn’t enough. Every WordPromise plan includes:
- Daily malware scans, and malware removal if something gets through
- Brute-force protection, two-factor authentication and strong-password enforcement
- File change detection, core inspection and plugin and theme scans
- IP and host banning, 404 detection and SSL set-up
We work with trusted partners, including Kadence Security Pro and WPMU DEV.
Safe by design
A backup is taken before any work begins. If an update ever causes a problem, we roll it back, so your site stays up and your data is never lost.
More than security
The same plan covers speed optimization, backup management and unlimited small edits through general support. It’s one team looking after the whole site.
Simple pricing
All of this costs $129 a month, or $1,250 a year. That’s less than most businesses spend cleaning up after a single hack. See the full details on our pricing page.
Don’t wait for the next five-hour window
The next major plugin flaw is a question of when, not if. Whether your site is ready depends on what you do before it happens.
Already with us? Log in to your WordPromise dashboard to see your site’s latest report and what we’ve done for it this month.
Or hand it over now. Sign up for WordPromise and our team starts monitoring, backing up and securing your site straight away, so you can get back to running your business.
Managing sites for clients? See how WordPromise for Agencies helps you look after your whole portfolio.