Why no website is 100% secure
A website is not a closed block: it is an assembly. On a WordPress site or a PrestaShop store, you find the CMS itself, about twenty plugins or modules written by different publishers, a theme, PHP, a database and the server. Each of these building blocks can contain a flaw that nobody knows about yet.
The figures show it. According to Patchstack’s annual report, 11,334 new vulnerabilities were recorded in the WordPress ecosystem in 2025, 42% more than in 2024. 91% concern plugins, 9% themes, and only 6 the WordPress core. In other words, the risk comes mostly from what you add to the site.
Another figure that matters: about half of serious vulnerabilities are exploited within 24 hours of being published. Attacks are automated: bots constantly test thousands of sites, with no idea who you are. A small business is not “too small to interest hackers”: it is simply on the list, like everyone else.
The 3 most common entry points
In the hacked sites I have put back in order, one of these three causes is almost always found:
- An outdated plugin or module: the flaw is known, the fix exists, but it was not installed.
- Access that is too easy to guess or shared: a reused password, the account of a former provider that was never deleted, FTP access left open.
- End-of-life hosting or PHP version: no more security fixes are published, so the flaws stay open for good.
None of these causes is a sophisticated attack. That is why website security is played out mostly on regularity, not on a miracle tool.
What really reduces the risk
Update fast, but on a copy first
Updating is the most effective protection, since most hacks exploit flaws that have already been fixed. But an update can also break a theme, a payment module or a form. So I test every important update on a copy of the site before applying it live. That is what lets you move fast without risk.
Tested backups, stored off the server
A backup that has never been restored is not a backup, it is a hope. It must be daily, contain the files and the database, be stored somewhere other than the site’s server (otherwise the hacker encrypts or erases it along with the rest), and be restored for real from time to time.
Fewer plugins, fewer access points
Each plugin is one more door. I remove those that are no longer used, and I prefer one well-maintained plugin to three abandoned ones. The same logic applies to access: one account per person, unique passwords, two-factor authentication on the admin area, and accounts of former providers deleted.
Monitor to react quickly
Since zero risk does not exist, you need to know quickly when something happens: site offline, modified files, suspicious pages indexed by Google, error spikes. A hack discovered within hours is repaired in a day; discovered three months later, it has often damaged search ranking and reputation.
HTTPS is not enough
The browser padlock encrypts exchanges between the visitor and the site. It is essential, but it says nothing about the security of the site itself: an HTTPS site can very well be hacked.
And if the site is hacked anyway?
This is where all the upstream work pays off. With clean backups and monitoring, a hack becomes an incident, not a disaster. For Parismatic Tour, a tour agency in Paris whose site had been hacked, I put the site back online in 2 days, before building a custom booking site (see the Parismatic Tour case study).
If your site is hacked today, the first reflexes are simple: do not delete everything in a rush, change passwords from a clean computer, notify your host, and have the site cleaned while looking for the flaw, otherwise the hacker comes back. I detail the steps on the hacked website repair page.
How much does website security cost?
Much less than a hack. With me, maintenance of a WordPress showcase site starts at €49 excl. VAT per month: updates, backups and monitoring. For a PrestaShop store, the Store plan at €179 excl. VAT per month includes updates tested on a copy and 2 hours of work. The plans are detailed on the website maintenance plans page.
Not sure where your site stands? An express audit at €290 excl. VAT takes stock of versions, plugins, access and backups, with a prioritised and costed list of fixes: see the website audit service.

