How to secure a website: why 100% secure does not exist, and what really works

No website is 100% secure, and a provider who promises you otherwise is mistaken or misleading you. Securing a site means reducing the risk and limiting the damage: here is how I go about it for my clients’ sites.

The essentials in 30 seconds

  • 11,334 new vulnerabilities were recorded in 2025 in the WordPress ecosystem, 91% of them in plugins: zero risk does not exist.
  • About half of serious vulnerabilities are exploited within 24 hours. Attacks are automated and also target small businesses.
  • What really reduces the risk: fast updates tested on a copy, daily off-server backups, controlled access and monitoring.
  • HTTPS protects exchanges with visitors, not the site itself.
  • Maintenance costs less than a hack: from €49 excl. VAT per month for a WordPress showcase site, €179 excl. VAT for a PrestaShop store.
Read the full article

Why no website is 100% secure

A website is not a closed block: it is an assembly. On a WordPress site or a PrestaShop store, you find the CMS itself, about twenty plugins or modules written by different publishers, a theme, PHP, a database and the server. Each of these building blocks can contain a flaw that nobody knows about yet.

The figures show it. According to Patchstack’s annual report, 11,334 new vulnerabilities were recorded in the WordPress ecosystem in 2025, 42% more than in 2024. 91% concern plugins, 9% themes, and only 6 the WordPress core. In other words, the risk comes mostly from what you add to the site.

Another figure that matters: about half of serious vulnerabilities are exploited within 24 hours of being published. Attacks are automated: bots constantly test thousands of sites, with no idea who you are. A small business is not “too small to interest hackers”: it is simply on the list, like everyone else.

The 3 most common entry points

In the hacked sites I have put back in order, one of these three causes is almost always found:

  • An outdated plugin or module: the flaw is known, the fix exists, but it was not installed.
  • Access that is too easy to guess or shared: a reused password, the account of a former provider that was never deleted, FTP access left open.
  • End-of-life hosting or PHP version: no more security fixes are published, so the flaws stay open for good.

None of these causes is a sophisticated attack. That is why website security is played out mostly on regularity, not on a miracle tool.

What really reduces the risk

Update fast, but on a copy first

Updating is the most effective protection, since most hacks exploit flaws that have already been fixed. But an update can also break a theme, a payment module or a form. So I test every important update on a copy of the site before applying it live. That is what lets you move fast without risk.

Tested backups, stored off the server

A backup that has never been restored is not a backup, it is a hope. It must be daily, contain the files and the database, be stored somewhere other than the site’s server (otherwise the hacker encrypts or erases it along with the rest), and be restored for real from time to time.

Fewer plugins, fewer access points

Each plugin is one more door. I remove those that are no longer used, and I prefer one well-maintained plugin to three abandoned ones. The same logic applies to access: one account per person, unique passwords, two-factor authentication on the admin area, and accounts of former providers deleted.

Monitor to react quickly

Since zero risk does not exist, you need to know quickly when something happens: site offline, modified files, suspicious pages indexed by Google, error spikes. A hack discovered within hours is repaired in a day; discovered three months later, it has often damaged search ranking and reputation.

HTTPS is not enough

The browser padlock encrypts exchanges between the visitor and the site. It is essential, but it says nothing about the security of the site itself: an HTTPS site can very well be hacked.

And if the site is hacked anyway?

This is where all the upstream work pays off. With clean backups and monitoring, a hack becomes an incident, not a disaster. For Parismatic Tour, a tour agency in Paris whose site had been hacked, I put the site back online in 2 days, before building a custom booking site (see the Parismatic Tour case study).

If your site is hacked today, the first reflexes are simple: do not delete everything in a rush, change passwords from a clean computer, notify your host, and have the site cleaned while looking for the flaw, otherwise the hacker comes back. I detail the steps on the hacked website repair page.

How much does website security cost?

Much less than a hack. With me, maintenance of a WordPress showcase site starts at €49 excl. VAT per month: updates, backups and monitoring. For a PrestaShop store, the Store plan at €179 excl. VAT per month includes updates tested on a copy and 2 hours of work. The plans are detailed on the website maintenance plans page.

Not sure where your site stands? An express audit at €290 excl. VAT takes stock of versions, plugins, access and backups, with a prioritised and costed list of fixes: see the website audit service.

Sources

Frequently asked questions

Can a website be 100% secure?

No. New vulnerabilities are discovered every week in CMSs, plugins and servers. You can greatly reduce the risk and limit the damage, but not remove it.

My site is small, are hackers really interested in it?

Yes. Attacks are automated: bots test thousands of sites looking for known flaws, whatever the size of the business.

Is WordPress less safe than other CMSs?

The WordPress core is rarely affected: 6 vulnerabilities in 2025, all of low severity. The risk comes mostly from plugins and themes, and from sites that are not updated.

Is HTTPS enough to secure a website?

No. HTTPS protects exchanges between the visitor and the site, not the site itself against a vulnerability or a stolen password.

How often should a website be updated?

Security fixes as soon as they are released, ideally within 24 to 48 hours, since serious flaws are often exploited the same day. Major updates, after a test on a copy of the site.

How much does website security maintenance cost?

At DataPet, from €49 excl. VAT per month for a WordPress showcase site and €179 excl. VAT per month for a PrestaShop store.

Read next

Let’s talk about your project

Write to me: I reply within one working day, with a first opinion or an offer of a 30-minute video call, even if we never work together.