forumNew topic

WordPress site got hacked, plugins were outdated — do i always have to update?

ŞŞerife K***Veteran
Job title
Clinic manager
Sector
Electrical-electronics
Organization type
early-stage startup
Joined
Dec 2023
Message
128
#1

our wordpress sites got attacked three times each time the hacker got in via an 'outdated plugin'. currently there are 35 plugins installed, 10 show as outdated. i'm scared to update them all (in case the site breaks). but not updating is risky too. how do i decide?

here's the thing: some plugins haven't had an update in 2 years. i switched to the new version, and the site got blacklisted. the IT manager said 'test it on a staging server' but i don't have a staging server, it's expensive to set up. any other solutions?

another question: should i pay for 'paid support' for plugins? how reliable are free plugins? should i disable ready-made plugins like wp-cache? is it better to use all of them or are minimal plugins safer?

MMelis Ç***Expert
Job title
System support specialist
Sector
Energy
Organization type
two-branch business
Joined
Apr 2025
Message
4
Most Helpful#2

right now: check outdated plugins, delete unused ones, update the rest (do it on a dev site to avoid risk). then install the Wordfence plugin (firewall).

GGürkan A***MemberCommunity member
Joined
Aug 2025
Message
376
#3

Quick summary for newcomers: The real issue isn't the number, but what it's based on.

If permission and scope aren't in writing, don't start that test.

OOzan M***New member
Job title
Music Instructor
Joined
Aug 2024
Message
34
#4

the most overlooked point about wordpress security is this: Everyone rushing into wordpress security gets stukc at the same point.

if you have questions, write them; Ill answer as best I can.

MMelis Ö***Expert
Job title
Social media manager
Sector
E-commerce
Organization type
120-person company
Joined
Feb 2022
Message
14

Doki · Log management setup · 2025

#5

Great work.

RRabia G***VeteranCommunity member
Joined
Sep 2025
Message
75
#6

I think differently. Any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

UUğur G***Member
Job title
General coordinator
Sector
Sports and fitness
Organization type
20-person company
Joined
Oct 2023
Message
11
#7

There are three things to check when doing this. The real issue isnt the number, but what its based on.

Don't hesitate to ask; those who don't ask always pay more. I mean correct me if I'm wrong.

HHüsniye P***MemberCommunity member
Joined
Dec 2024
Message
407
#8

I'm a small business, let me explain from my side. Your time to detect an issue directly determines its cost.

Hope this helps.

GGamze U***Member
Job title
Technical service technician
Sector
Furniture manufacturing
Organization type
family business
Joined
May 2024
Message
255
#9

Noted, thanks. If you get three different answers on a topic, the question was asked wrong.

Start with a small trial; don't commit to everything at once. This is my opinion, I'm not claiming it's absolute truth.

OOsmanMember
Job title
Agricultural machinery dealer
Joined
May 2024
Message
70

Doki · Incident response support · 2023

#10

The answer above hits the nail on the head. Mistakes made on the wordpress security side are usually reversible but expensive.

If you have questions, write them; I'll answer as best I can.

BBeyza B***MemberCommunity member
Joined
Aug 2024
Message
1
#11

The answer above hits the nail on the head. Taking notes for two weeks yields better results than a six-month estimate.

ZZafer D***Member
Job title
Operations manager
Sector
Tourism
Organization type
8-person team
Joined
Nov 2024
Message
15
#12

Let me summarize the topic, since several different answers were given. Everything goes well for the first three months; problems arise in the fourth.

If you post the result here, it will help others too.

SSelin Y***Veteran
Job title
Front office accounting
Sector
Real estate
Organization type
120-person company
Joined
Sep 2024
Message
111
#13

Let me speak from the other side; I'm on the supplier side. People defend habits, not processes. Resistance comes from there.

Hope this helps.

DDoruk T***MemberCommunity member
Joined
Jul 2023
Message
23
#14

Let me summarize the topic since several different answers were given. An untested backup is not a backup.

HHilalMember
Job title
Translator
Joined
Aug 2024
Message
112
#15

The most overlooked point about wordpress security is this: Just because everyone does it doesn't mean it's right.

If you don't write this down from the start, it leads to arguments later. If you have questions, write them; I'll answer as best I can.

SSevilMember
Job title
Educational institution
Organization type
chain store
Joined
May 2024
Message
88
#16

Just a heads-up. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

İİbrahim K***MemberCommunity member
Joined
Apr 2023
Message
204
#17

You're right. Processes without records never improve, because you don't know what to fix.

If you have questions, write them; I'll answer as best I can.

FFerhat A***Member
Job title
Board member
Sector
Advertising and promotion
Organization type
20-person company
Joined
Jun 2024
Message
155
#18

The opposite happened to me that's why I'm writing. Taking measures without an inventory leaves doors you haven't seen open.

This is my opinion, I'm not claiming it's absolute truth.

VVeli D***Member
Job title
Network Administrator
Sector
Education
Organization type
two-branch business
Joined
May 2022
Message
107

Doki · Infrastructure migration · 2023

#19

thanks a lot Ill try it today.

KKadir A***MemberCommunity member
Joined
Aug 2024
Message
99
#20

If I understood correctly, you're saying: The biggest time-waster for us was not knowing who had the final say.

Processes without records never improve, because you don't know what to fix.

Reply