Why We’ve Doubled Our Website Security Update Schedule

From this month, every site on our Security & Maintenance plan moves from monthly to twice-monthly updates. Plus immediate action, outside that schedule, whenever a serious vulnerability affects something running on your site.

There’s no change to what you do or pay. But there is a reason for the change, and it’s worth explaining, because it says a lot about how quickly this corner of the web has shifted.

More attacks, arriving faster

The volume has climbed steadily. New WordPress vulnerabilities were up 42% last year, to over 11,000, with the great majority found in plugins rather than WordPress itself.

But volume isn’t really the story. Speed is. 

The gap between a vulnerability being made public and being attacked at scale is now measured in hours, not days. Around half are being targeted within twentyfour hours of disclosure. That’s what makes a monthly cycle too long. It leaves a window of up to thirty days against a threat that can move in an afternoon.

AI has changed the game for both sides

This is the part that’s shifted fastest, and it’s not the one-sided story it’s usually told as.

For attackers, the work of turning a published disclosure into a working exploit has collapsed. What once needed skill and a couple of days now needs neither.  Further upstream there’s a second effect too, “vibe coding”, developers using AI to generate plugin code and shipping it without being able to audit what the model wrote. When the person shipping the code can’t review it for security problems, vulnerabilities go live silently. More vulnerable code is entering the ecosystem in the first place.

But the security developers have the same tools. Part of the reason those vulnerability numbers look alarming is that far more is being found. Automated review is turning up flaws that would previously have sat undiscovered for years. Detection has improved, response has sped up, and the platform itself has adapted.

Nobody has chosen your business. It’s automated scanning at scale, looking for any site running a known vulnerable plugin. Which is exactly why small business sites are as likely a target as anything else.

Why staying updated was never quite enough

Two things complicate the simple advice to keep everything current.

First, nearly half the vulnerabilities disclosed in 2025 had no fix available at the point they were made public. You can be entirely up to date and still exposed, because there’s nothing yet to update to.

Second, in April an attacker bought a portfolio of around 30 WordPress plugins outright, planted a backdoor, and waited eight months before activating it across some 400,000 sites. Every one of those owners was running trusted, properly updated plugins from the official directory. WordPress has since added a 24-hour review window on all plugin releases; a sensible safeguard, though it also means a genuine security fix can now sit for a day before it reaches your site.

What we actually do about it

Fewer plugins where possible. Every plugin is another door, and with over 90% of vulnerabilities originating there, the cheapest security measure available is not installing things. Where a problem can be solved with clean custom code, we do that instead. The sites we build carry only what’s needed.

Twice-monthly scheduled updates, which is now our baseline rather than our cautious option.

Continuous monitoring on top of the schedule. Because the schedule is the backstop, not the defence. When something is disclosed that affects a site we manage, we act on it then. Not at the next scheduled visit, not on Friday.

Backups we’ve actually tested restoring, because the difference between an inconvenience and a disaster is usually whether the last good copy works.

Why it matters commercially

A compromised site isn’t just a technical problem. It’s lost bookings during the weeks it’s down, a search listing flagged as unsafe at the exact moment people are looking for you, months of ranking to rebuild, and potentially customer data to account for.

The reassuring part is that the overwhelming majority of successful attacks find sites nobody was looking after. A maintained site with minimal plugin exposure is a poor target, and attackers working at scale move on to easier ones.

If your site isn’t on our Security & Maintenance plan and you’d like to know more, get in touch with Liz and we can talk it through.

WhatsApp message Liz 44 7912 083488
Call on  01397 700230
Email  [email protected]