If your website runs on WordPress — and roughly 4 in 10 websites globally do — the security landscape got measurably worse in the past year, and the numbers are worth understanding rather than glossing over.
Patchstack's 2026 State of WordPress Security whitepaper recorded 11,334 new vulnerabilities disclosed across the WordPress ecosystem in 2025 — a 42% jump on the year before, and the highest number ever recorded. The overwhelming majority — around 91% — sit in plugins and themes, not WordPress core itself, which remains comparatively well audited and stable.
The number that should actually change how you think about maintenance: the median time from a vulnerability being publicly disclosed to it being actively exploited at scale is now 5 hours. Not five days. Five hours. Standard hosting-level firewalls block only around a quarter of WordPress-specific exploit attempts, because most of this activity happens at the application layer — inside the plugin's own code — where a generic server firewall simply isn't looking.
The practical result: an estimated 13,000 WordPress sites are compromised every day worldwide. Attackers aren't typically targeting your business specifically — they're running automated scanners that check millions of sites for known, unpatched vulnerabilities, and a small or mid-size business site is just as likely to get swept up as a large one. Recovery from a genuine compromise averages several thousand dollars in cleanup, lost trading time, and reputational cost — against a fraction of that for ongoing proactive protection.
The uncomfortable truth in most of these breaches is that they were preventable. An outdated plugin, a weak or reused admin password, no two-factor authentication, no one actually watching for the patch that came out three weeks ago. None of it is exotic. All of it is routine, ongoing maintenance — which is precisely the kind of thing that gets deprioritised on a site that "just works," until it doesn't.
Where WebAcumen fits in
Our Maintenance retainer exists specifically to close this gap — security patching, plugin and core updates applied on a defined schedule (not "whenever someone remembers"), monitoring, and a documented response process if something does get flagged. If you're not sure where you currently stand, our free Security Audit will tell you.