
It’s Monday morning. A clinic outside Kungsbacka opens as usual, but the phone is quieter than it should be. Nobody has been in touch through the website all weekend. It isn’t until Wednesday that someone works out why: the booking form stopped working after a plugin updated itself on Friday. No alert, no crashed site. Just three days of customers who tried to book an appointment, couldn’t, and went somewhere else.
That’s usually what it looks like when a website breaks. Not a dramatic hacker attack, but something small and quiet that nobody notices until the business has already been lost.
This article is about why it happens, what it costs, and why a maintenance plan is, in practice, cheap insurance. Not scare tactics. Just what actually goes wrong, and what actually protects you.
Sites rarely break dramatically. They just stop working.
WordPress itself is small and well maintained. The problems almost always sit in what’s been built on top of it: plugins and themes. A typical business site often runs 20 to 30 plugins. Every plugin is extra code, and every extra piece of code is something that can clash when it updates.
The most common reason something stops working is exactly that kind of clash. A plugin updates, but it’s no longer compatible with another part of the site. The result is rarely a blank white screen. More often it’s a form that quietly stops sending, a booking button that doesn’t respond, or an image that disappears. The kind of thing you don’t notice until a customer mentions it, or until you happen to test it yourself.
Then there are the plugins nobody maintains any more. Security tools like Wordfence tend to treat a plugin as potentially abandoned if it hasn’t been updated in at least two years. The problem is that your WordPress doesn’t warn you when this happens. A plugin that’s been closed down over a security hole still shows as “up to date” in your admin. Everything looks calm, even though it isn’t.
On top of that comes old PHP, the programming language WordPress runs on. When your server runs an outdated PHP version, plugins start misbehaving and security weakens. And then the most mundane causes of all: a domain that wasn’t renewed in time, or an SSL certificate that expired. Then the site is down completely, or the visitor is met with a red security warning. None of that has anything to do with hackers. All of it is preventable. If you want to understand how the domain, hosting and email fit together, and why an expired domain can switch everything off at once, we’ve written about exactly that.
What you don’t see: old code is an open door
Now to the part people are afraid of. Hacked sites.
Here’s the important thing, and it’s actually reassuring: the vast majority of break-ins don’t happen because someone targeted your business specifically. They happen because a known hole in an old plugin was left open, and automated bots found it. It’s nothing personal. It’s just an unlocked door someone walked past.
And known holes get exploited fast. Verizon’s major 2026 security report, an independent source covering the whole economy and not just WordPress, shows that exploiting vulnerabilities is now the most common way into the data breaches they analysed. It accounts for roughly a third of breaches and has overtaken stolen passwords. And it isn’t the big corporations that are hit hardest. Small organisations made up the overwhelming majority of ransomware victims, precisely because they rarely have anyone keeping watch.
The security industry’s own figures point the same way: the large majority of WordPress break-ins come through plugins, themes or core that weren’t kept updated. Those figures come from companies that sell security services, so take the exact percentages with a pinch of salt. But the direction is clear and confirmed from independent quarters. Old code is the way in. What you can do about it yourself is covered in our guide to WordPress security for business owners.
What it actually costs when things go wrong
What happens if it does go bang? It depends on the business, but the pattern is the same.
The first thing you lose is customers you never even find out about. A clinic or a tradesperson taking bookings through the site loses every enquiry that comes in while something is broken. It shows up in no statistic. People just move on.
If the site gets hacked and Google flags it for malware, it gets worse. Browsers then show a red warning page, and the site is effectively removed from search results. Security firm Sucuri estimates that a blocklisted site loses almost all of its organic traffic for as long as the warning stays up. That’s a vendor’s estimate, not an independent study, but the order of magnitude matches how Google handles flagged sites. Ads to that page get stopped too.
Then comes the cleanup. One Swedish web agency puts the cost of cleaning up a hacked WordPress site at somewhere between 5,000 and 20,000 kronor, and notes that content is sometimes lost for good. Add that it can take weeks or months to climb back up the search results once everything is cleaned. Exactly what it costs you can’t be said in advance. But it’s rarely cheap, and it’s always more expensive than having avoided it.
GDPR: a real obligation, but not scare tactics
This is where a lot of agencies get dishonest, and we don’t intend to be.
If your site is hacked and customer data leaks, that’s a personal data breach. Under GDPR you then have an obligation to report it to the Swedish data protection authority, IMY, within 72 hours of finding out. If the risk to those affected is high, you also have to inform them directly. It’s a real law with a real deadline, and it’s not something you want to be scrambling to handle in a panic in the days after a break-in.
For a clinic it weighs even heavier, because health data and personal identity numbers count as especially sensitive. That’s exactly the kind of thing many small businesses store.
But now to what agencies rarely tell you: how big is the risk of actually being fined? For a small, cooperative business it’s honestly low. IMY issues fines in a small minority of cases. The rest end in reprimands, injunctions or no action at all.
IMY’s own practice points the same way. A reprimand is the milder sanction the authority normally uses for exactly this kind of minor breach, as opposed to the million-kronor sums that make the headlines. It’s the typical outcome in cases where data was exposed for a short time, the business reacted quickly once it was spotted, informed those affected and put new routines in place. Reacting well counts strongly in your favour.
That’s the honest picture. A small business that looks after its site and reacts correctly risks a reprimand, not a ruinous fine. The big fines in Sweden have gone to large organisations that leaked hundreds of thousands of people’s data. The point of GDPR here isn’t fear. It’s that you have a genuine obligation, and one that’s far easier to live up to if the site is looked after before anything happens.
Why “just click update” isn’t enough
At this point you might be thinking: surely I can handle this myself? Log in, click update now and then. And sure, that’s better than nothing. But it isn’t enough, and it’s worth understanding why.
First, there isn’t always an update to click. According to Patchstack, around a third of the WordPress vulnerabilities reported last year had no fix available when they became known. Abandoned plugins never get one at all. Staying updated doesn’t help against a hole nobody has patched.
Second, the update itself can be what takes the site down. That’s exactly what happened to the clinic at the start. An update pushed without first testing it in a safe environment is a gamble.
Real maintenance is therefore more than pressing a button. It’s updates tested before they go live, regular backups so a crashed site is back in minutes instead of rebuilt from scratch, monitoring that catches break-ins early, and alerts when the site goes down or a certificate expires. It’s also someone who actually notices when a plugin has been abandoned and swaps it out before it becomes an open door.
It’s the difference between hoping nothing goes wrong and knowing someone is keeping watch.
A maintenance plan is cheap insurance
So what does it cost to have someone handle all this? It depends on the site and what’s included, but for a small business it’s usually a few hundred to a few thousand kronor a month.
Set that against the other side. A single cleanup at 5,000 to 20,000 kronor. Weeks of lost visibility in search. Bookings that never came in while the form was down. A 72-hour deadline to deal with in the middle of everything else. Seen that way, a maintenance plan isn’t a cost. It’s cheap insurance against having to pay the bigger price.
Frequently asked questions
How often does a WordPress site need updating?
Plugins, themes and core get updates more or less continuously, sometimes several times a month. What matters isn’t a fixed schedule, but that the updates happen regularly and are tested before they go live on the site.
Can’t I just handle the maintenance myself?
You can do parts of it, and clicking update is better than not. But real maintenance also includes testing, backups, monitoring and keeping an eye out for abandoned plugins. That’s the part that’s hard to fit in alongside running a business.
What happens if I never update?
The site often keeps working for a while, which is the tricky part. But every known hole that isn’t patched becomes an open door, and automated bots are constantly looking for exactly those. Sooner or later they find one.
Do I really have to report it if the site is hacked and data leaks?
If personal data is exposed, you have an obligation to report it to IMY within 72 hours, unless it’s unlikely to pose a risk to those affected. A well-maintained site with backups makes that whole situation considerably easier to handle.
Not sure when your site last had any servicing?
Most business owners don’t. The site was built once, it worked, and then it was left to live its own life. That’s usually when the quiet problems start piling up.
If you want to know where your site stands today, we’re happy to take a look. Get in touch, and we’ll go through what needs keeping on top of and what ongoing maintenance would mean for your site specifically.