Guide · Technical

Nobody is targeting you.
That is not reassuring.

Almost no small business site is attacked deliberately. They are found by automated scanners sweeping the whole internet for known weaknesses — our own server logs show these probes arriving daily, asking for configuration files that would contain passwords if they existed.

Published 2026-09-24 · Formory Group

What actually happens.

A scanner requests a list of common file paths on every domain it can find. If one answers, it takes whatever is inside. Others try administrator logins with lists of common passwords, or exploit a plugin that had a published vulnerability months ago.

The result is usually not dramatic. Compromised small business sites are most often used quietly to host spam pages or redirect some visitors, which continues for months because the owner never looks.

The five things that prevent nearly all of it.

Keep the software patched, or use a platform where there is nothing to patch. Use unique passwords and two-factor authentication on the admin, the host and the domain registrar. Remove plugins nobody uses — each is a separate risk maintained by a separate stranger.

Keep backups somewhere other than the server itself, and test that one restores. Serve everything over HTTPS. That is the whole list for a normal business site, and it prevents the overwhelming majority of what actually occurs.

The registrar and the email are worth more than the site.

A compromised website is an afternoon of restoring from backup. A compromised domain registrar account means someone else controls the name, the website and the email, and recovery is slow and uncertain.

Protect the registrar account and the email account behind it first, with two-factor authentication. They are the keys to everything else and they are the accounts people forget they have.

What gets sold instead.

Monthly scanning services that report the same findings every month. Firewall products on sites that have no admin panel to protect. “Malware removal” plans priced as insurance against a risk the plan does not actually reduce.

None of that is fraudulent, and none of it substitutes for patching, passwords and backups.

Why a static site sidesteps most of this.

A site built as finished files with no database and no login has very little to attack: there is no admin panel to guess a password for, and no plugin to exploit. That is a large part of why we build this way.

It is not invulnerability — the registrar and the host account still matter — but it removes the two most common routes in.

Questions

Asked often.

Do I need a security plugin?

On a maintained platform with few plugins and strong passwords, usually not. A security plugin is not a substitute for updates, and it adds one more thing that needs updating.

How do I know if my site is compromised?

Search Google for site:yourdomain.com and look for pages you did not create. That finds the most common outcome, which is spam pages hidden inside an otherwise normal site.

What should backups cover?

Files and database, stored somewhere other than the same server, kept for at least thirty days, and restored once as a test. A backup nobody has ever restored is a hope, not a backup.

Your turn

Same check,
run on your site.

The check behind this page is the one we ran on every business above. Put your own address in and it will load your site on a phone screen, look at the certificate and the page age, and tell you what a visitor meets. No email, nothing stored.

Check my website free Read the full GTA report

Want the same for
your business?

Tell us what you do and where you work. We will look at what you have now and say plainly whether it is worth rebuilding — including when it is not.

Start a project See our work