What happens to a WordPress site nobody maintains?
It gets hacked, or it breaks. Usually within two to three years of the last update.
A WordPress site is not a finished object like a printed brochure. It's software running on a server: a core application plus somewhere between ten and forty plugins, each written by a different developer, each shipping security fixes on its own schedule. Stop applying those fixes and the site becomes a known, publicly documented set of holes.
The scale of that is easy to underestimate. In 2025 alone, 11,334 new WordPress vulnerabilities were disclosed, 91% of them in plugins, and nearly half had no fix available on the day they were made public. We track those numbers every year on the WP Care blog: WordPress vulnerability disclosures in 2025.

We know this because we run a WordPress maintenance service. WP Care looks after WordPress sites for Irish businesses, and most of what's on this page comes from that work.
The realistic timeline of neglect
Months 0 to 6. Nothing visible. The site works. Update notices pile up in an admin area nobody logs into.
Months 6 to 18. Plugins start going stale. One or two are abandoned by their developers entirely. A PHP version upgrade on the server breaks the contact form and nobody notices, because nobody tests the contact form. Enquiries quietly stop arriving.
Years 2 to 3. A hole in an outdated plugin gets found by an automated scanner. Not by a person who targeted you, by a bot that scans the whole internet for that exact version number. Your site starts serving spam pages, or redirecting mobile visitors somewhere else, or sending mail that gets your domain blacklisted.
The discovery. Almost nobody finds this themselves. They find out because Google flags the site as deceptive, or a customer rings to say the site is showing something strange, or their email stops being delivered.
What a clean-up actually costs
Recovering a compromised WordPress site usually costs more than the original build, because you're paying for investigation as well as repair:
- Finding and removing the injected code, which is usually spread across many files
- Working out how they got in, so it doesn't happen again the following week
- Restoring from a backup, if one exists and if it predates the break-in
- Asking Google to review the site and lift the warning, which takes days
- Repairing your domain's reputation if spam went out under your name
And there's the part that never appears on an invoice: the weeks where anyone who searched your business name saw a warning or a page of spam.
"But my site is small. Why would anyone target it?"
Nobody targeted it. That's the misunderstanding at the heart of this.
The overwhelming majority of WordPress break-ins are automated and indiscriminate. A bot crawls a list of millions of sites, checks each one for a specific vulnerable plugin version, and exploits every match. A five-page site for a plumber in Finglas and a national retailer look identical to that bot.
Being small doesn't make you invisible. It makes you likelier to be unmaintained, which is the only thing the scanner is testing for.
What you can do about it
Maintain it properly. Monthly core, theme and plugin updates, tested on a staging copy first, with off-server backups and uptime monitoring. This is real work and it costs real money, typically €30 to €100 a month in Ireland. If your site does a job that needs WordPress, this is the correct answer.
Do it yourself. Viable if you're technical and disciplined. The failure mode isn't ability. It's that maintenance is nobody's favourite hour, and it slips.
Rebuild on something with no moving parts. For a brochure site, meaning pages, photos and a contact form, WordPress is a lot of machinery for a small job. A site with no plugin stack has nothing to patch, so there's nothing for the scanner to find.
Which one is right for you?
If your site takes bookings, sells products, runs a membership, or does anything genuinely dynamic, keep WordPress and maintain it properly. The flexibility is worth the upkeep.
If your site exists so that people can find you, see what you do, and get in touch, you're carrying the maintenance burden of a system you're using at maybe five percent of its capacity.
That second case is what aisites.ie is for. A brochure site with a contact form, €249 for one page or €349 for up to five, then €156 a year to keep it running. Prices are ex VAT. No plugin stack to patch. Hosting, security and backups are our job, not yours, and you get a login to change your own text and photos. Our website cost guide puts that beside the alternatives.
What happens next. Tell us about your business. We build the site inside 48 hours of getting your details, you look at the finished site, and you pay only if you want it.
Common questions
Does a WordPress site need to be updated?
Yes. WordPress core, the theme and every plugin release security fixes on their own schedules. A site that isn't updated becomes a publicly documented set of vulnerabilities, and automated scanners look for exactly those. Most unmaintained WordPress sites are compromised or broken within two to three years.
How often should WordPress be updated?
At least monthly, and security releases as soon as they appear. Updates should be tested on a staging copy first, because an update can break a plugin or a theme as easily as it fixes one.
How much does WordPress maintenance cost in Ireland?
A maintenance plan covering updates, backups and monitoring typically costs €30 to €100 a month from an Irish provider. Recovering a hacked site afterwards usually costs more than the original build, because the work starts with an investigation.
Do I need WordPress for a small business website?
Not for a brochure site. If the site's job is to say what you do, where you work, show photos and give people a way to contact you, a static site with no plugin stack does that with nothing to patch. WordPress earns its upkeep when the site takes bookings, sells products or runs a membership.