WordPress · Security · Small Business
Your WordPress Site Gets Hacked. The Phone Stops Ringing. Plug These Holes Quick.
Wordfence found malware on about 474,000 sites in the first quarter of 2026. The average infected site was carrying 51.8 bad files. Not one file you delete on a Sunday. Fifty-two, scattered through folders you have never opened.

Bob's phone had a quiet week in March.
Not dead. Quiet. Four calls instead of nine. He put it down to the weather, then to the time of year, then to nothing in particular, because that is what you do when one week is soft. He had a busy April lined up and he stopped thinking about it.
His site had been hacked since February.
Nobody called to tell him. There was no message on his dashboard and no email from anybody. His site loaded fine. The pictures of the trucks were still there. What had changed was that Google had quietly stopped trusting it, and a page nobody ever showed him was serving something to strangers in another country.
That is what getting hacked actually looks like for a small business. Not a skull on the screen. A soft month you cannot explain.
And then there is the part after, which nobody has ever described to Bob, because everybody stops the story at "you got hacked."
474,000 sites last quarter. About 52 bad files in each one.
It is not one bad file.
The average infected site was carrying 51.8 of them.
TL;DR (the short answer)
Getting hacked is not one bad file you delete. In the first quarter of 2026, Wordfence detected malware on about 474,000 of the more than 5 million sites it protects, which is roughly 9 in 100. Across those sites it saw 27.4 million unique malware files, and the average infected site was carrying 51.8 malicious files. Cleanup means finding all of them, because leaving one behind lets the site get reinfected. Most of those sites were running software that had a patch available and never got it.
3 Things to Remember
474,000 Sites. Out of More Than 5 Million.

I am going to give you both numbers in the same breath, because one without the other is a scare tactic.
In Q1 2026, Wordfence detected malware on about 474,000 sites. Wordfence protects more than 5 million sites. (Wordfence, 2026)
That is roughly 9 in 100. It is not everyone, and anybody telling you the whole platform is on fire is selling something. It is also not nobody. Nine out of a hundred is one street of shops in your town.
Here is the number that actually changes how you think about it.
Across those infected sites, Wordfence saw 27.4 million unique malware files, and the average infected site was carrying 51.8 malicious files. (Wordfence, 2026)
Fifty-two. On one site. That is not somebody dropping a file and leaving. That is somebody moving in.
sites with malware detected in Q1 2026, out of more than 5 million that Wordfence protects. Roughly 9 in 100. (Wordfence, 2026)
malicious files on the average infected site. Not one. (Wordfence, 2026)
unique malware files seen across those sites in a single quarter. (Wordfence, 2026)
You Find Out From a Quiet Month.

This is the part I want to spend real time on, because it is the part that costs you money before anybody says the word "hacked."
A modern site compromise is not built to be noticed. Whoever did it wants your server, your traffic, or your good name with Google, and all three of those work better if you never look.
So your homepage stays normal. Your form still sends. Meanwhile there are pages on your domain you have never seen, serving whatever the attacker is selling, and Google is reading them.
Then Google does the thing Google does. It stops trusting the domain. Your listings slide. The map pack forgets you. Nobody calls to explain and nothing shows up on your screen. Your phone just gets quieter.
I wrote about how that trust collapse works in what a hack does to your Google standing. The short version is that the traffic damage starts before you know anything is wrong.
The mistake: waiting for something obvious to happen before you check.
The fix: when a month goes soft for no reason, check the site before you blame the season.
The payoff: you catch it in weeks instead of quarters, and there is less to clean up.
Now Go Find the Other 51.

Here is the cleanup nobody describes.
You find one bad file. Maybe your host flags it, maybe a scanner does. You delete it. You feel like you handled it.
The average infected site has 51.8. (Wordfence, 2026) So you handled roughly 2% of it.
The rest are not sitting in a folder called "bad files." Wordfence's own breakdown is useful here: PHP files are often webshells, backdoors, infostealers and skimmers, while JavaScript and HTML files are usually spam. (Wordfence, 2026) That means the pieces are doing different jobs and living in different places. Some are the way back in. Some are the payload. Some are just there so the others survive a cleanup.
That is why "I deleted the bad file and it came back" is one of the most common sentences in this whole business. It came back because you removed the payload and left the door.
And the average infected site carried 2.4 different malware variations. (Wordfence, 2026) It is not one intruder with one tool. It is often more than one thing, layered.
The mistake: treating cleanup as deleting what you found.
The fix: treat it as finding everything, which means a full file scan against known signatures, not eyeballing folders.
The payoff: it stays gone, and you are not doing this again next month.
You found one. Now go find the other 51.
What the Weekend Actually Costs.

Nobody bills you for "a hack." You get billed for the pieces, and the pieces stack up.
- The cleanup. Either you pay somebody, or you spend a weekend learning file structures you never wanted to know.
- The reinfection. If one backdoor survives, you do it again. This is the one that turns a bad weekend into a bad month.
- The passwords and keys. Every credential on that site has to be treated as gone. Database, host, email service, anything the site connected to.
- The Google recovery. Getting the trust back takes longer than getting the files out, and no invoice covers it.
- The quiet weeks. The jobs you never heard about while the phone was soft. That number is real and you will never know what it was.
Not one of those is the file you deleted.
Plug These Holes Quick. Here Is the Short List.

The title promises this, so here it is, plainly. These are the things that put most sites in that 474,000.
- Update everything today, then find out who owns doing it every month. Most infected sites were running something with a patch available that nobody installed. This is the single biggest one.
- Pull the plugins nobody maintains. Anything with no update in over a year, or a red closure bar on its WordPress.org page, is the profile that gets hit. I went through the abandoned-software problem in the post on holes with no patch at all.
- Get two-factor on every admin account. Wordfence blocked 16.0 billion brute force attempts in Q1 2026 alone. (Wordfence, 2026) That is the front door, and it is being tried constantly.
- Cut admin accounts down to the people who need them. The web guy from 2019 does not need one.
- Have a backup you have actually restored. Not "we have backups." A backup nobody has tested is a story, not a plan.
- Run a real malware scan on a schedule, not when you get worried. You are looking for 52 files, not one.
That list is not exciting and it is not new. It is what actually separates the 9 from the 91.
I Didn't Just Write About It. I Left.
This is not a number off somebody's chart. I moved 1,300+ of my own posts off a dying WordPress stack, and one of the reasons was that I had done enough cleanups.
I have built more than 10,000 sites in 25 years, and I have been the person going through somebody else's wp-content folder at 11pm looking for the file that keeps bringing the rest back. I know how that call starts and I know how the week goes.
You are reading one of those rebuilt pages right now. There is nothing on it to infect, so there is no version of that week in my life anymore.
A Site With No Moving Parts Has Nothing to Reinfect.

The reason my builds do not have this problem is boring. There is no code running on the server that a stranger can talk into doing something.
A WordPress site builds every page fresh when somebody visits. It runs code, asks the database a pile of questions, loads every plugin, and hands back a page. Every one of those steps is somewhere a file can be planted and somewhere a backdoor can hide.
The sites I build are already built. The pages are finished files sitting on a fast network. A visitor arrives and there is nothing to run.
That is not me being clever. It is fewer moving parts, and 52 files have nowhere to live. That is the whole idea behind the 100K Website, and it is why I say the old machine is done for real business sites.
And watching it is my job. You go run your business.
Where This Is Not WordPress's Fault.

I will give the other side its full due here, because it is the strongest counterpoint in this whole run.
Most of those 474,000 sites were not hacked because WordPress cannot be secured. They were hacked because they were running software with a patch available that nobody installed. That is a maintenance failure, not a platform failure, and a well-run WordPress site with few plugins, current versions, two-factor on the admin accounts and a real backup is a genuinely hard target.
The detection side is also working hard. Wordfence released 89 new malware signatures in that one quarter and blocked 9.1 billion firewall attacks. (Wordfence, 2026) That is a serious defense operating at a scale most software has no version of.
Now the turn. Every bit of that depends on somebody watching your site every single week, forever, and noticing things a busy owner has no reason to notice. That person exists at big companies. On Bob's site, that person is Bob, and Bob is on a roof.
The worst part of getting hacked is not the files. It is the four weeks before you knew, and the quiet phone you could not explain.
Your website should be the boring part of your week. It should not be a thing you have to go looking for problems in between jobs.
Let me show you what a site with nothing to clean up actually feels like, built on your own market.
You get a real look at your own market. No obligation, and nothing to cancel.
Want the whole playbook first? Plan your attack. Balls Out Marketing.
This is the part nobody warns you about. It goes quiet.
FAQ
Often you do not, at first. The most common early sign is a drop in calls or traffic with no obvious cause, because Google stops trusting the domain before anything looks wrong to you. Check Google Search Console for security notices and run a site:yourdomain.com search to see if pages you did not create are showing up.
In the first quarter of 2026, Wordfence detected malware on about 474,000 sites out of the more than 5 million it protects. That is roughly 9 in 100 of the sites it watches.
The average infected site in Q1 2026 was carrying 51.8 malicious files, with 2.4 different malware variations. Deleting the one file you found leaves almost all of it in place, which is why hacked sites so often get reinfected.
Because you removed the payload and left the door. A compromise usually includes backdoor files whose only job is to let the attacker back in after a cleanup. If those survive, everything comes back.
The file cleanup is the fast part. Rotating every credential, checking for backdoors, and getting your Google trust back takes considerably longer, and the traffic you lost while it was quiet does not come back on a schedule.
Yes. Google drops trust in a domain serving malware or spam, and the ranking damage usually starts before the owner knows anything is wrong. That is why the first sign is often a quiet month.
Update everything and decide who owns doing that every month, remove plugins nobody maintains, put two-factor on every admin account, cut old admin accounts, keep a backup you have actually restored, and scan on a schedule rather than when you get worried.
This is post 6, the last in a run on WordPress security. Post 1 covered the hole in WordPress core that needed no password. Post 2 covered the 30 plugins that got bought and backdoored. Post 3 covered the contact form that let strangers upload files. Post 4 covered the fix that shipped in March and got attacked through June. Post 5 covered the holes with no fix at all. This one is what happens when one of them lands.
Check Out My Last 3 Builds
Real sites, built with this exact system. Tap any one and poke around.