Risk Note
Common Reasons
Why WordPress Sites
Get Hacked
and How to Prevent It
Secure today,
Safe website
tomorrow.
Outdated
Software
Risk: Known vulnerabilities can be exploited.
Prevention:
- Update WP core
- Update plugins and themes
- Enable auto updates
- Remove unused items
- Take backup first
Weak
Passwords
Risk: Easy to guess. Brute force attacks can break in.
Prevention:
- Use strong, unique passwords
- Enable 2FA
- Avoid admin username
- Change regularly
Unvetted
Plugins & Themes
Risk: Unsafe or abandoned items may contain malicious code.
Prevention:
- Use trusted sources
- Check updates and reviews
- Remove unused items
- Use fewer plugins
Lack of
Security Monitoring
Risk: Attacks and malware may go unnoticed.
Prevention:
- Install security plugin
- Block brute force
- Scan for malware
- Enable alerts
No SSL
Certificate
Risk: Data can be intercepted. Trust is lost.
Prevention:
- Install SSL
- Force HTTPS
- Fix mixed content
- Renew before expiry
Table of Contents
- Common WordPress risks
- Prevention checklist
- Daily security habits
- SLA service note
- Malaysia compliance note
SLA Service Note
Server uptime SLA normally covers server and network availability based on the subscribed hosting plan. WordPress level hacking, weak passwords, unsafe plugins, infected themes and website coding issues are normally outside standard uptime SLA coverage.
Malaysia Compliance
If a website collects customer data, website owners should handle security seriously under Malaysia related requirements such as Personal Data Protection Act 2010, Computer Crimes Act 1997, Communications and Multimedia Act 1998 and Cyber Security Act 2024 where applicable.
Responsibility Breakdown
| Customer | iCoreHosting |
|---|---|
| Update WordPress, plugins and themes | Provide hosting platform according to plan |
| Use strong passwords and 2FA | Maintain server tools and access platform |
| Choose safe plugins and themes | Advise on hosting compatibility where possible |
| Keep clean backup for important data | Provide backup service based on subscribed plan |
Important Service Boundary
Hosting support can help check server and service status. Website issues such as hacked site, bad plugin, custom code problem, theme bug or malware cleaning may need developer support or chargeable recovery work.
FAQ Quick Answers
Q1. Can a site be hacked after SSL?
Yes. SSL is not full website protection.
Q2. Should I update immediately?
Yes, especially security updates. Backup first.
Q3. Are free plugins safe?
Some are safe if trusted and actively maintained.
Q4. First step after hack?
Change passwords, scan, update, check users and restore clean backup.
Summary
Good WordPress security is a habit, not a one time action. Keep everything updated, use strong passwords, choose safe plugins and themes, monitor regularly, enable SSL and keep clean backups.
Good security
is a habit,
not a one time
action.
