A recent survey of 319 WordPress professionals indicates that a significant majority lack a defined breach recovery plan, despite most having experienced at least one security incident. The survey, conducted by Melapress, a developer of WordPress security plugins, included agency staff, developers, designers, site owners, and administrators who build and manage WordPress sites professionally. Fewer than 30% of these professionals reported having a breach recovery plan in place.
A breach recovery plan typically outlines responsibilities for incident response, identifies the location of clean backups, and specifies communication protocols for notifying affected parties. Without such a plan, critical decisions regarding incident handling are often made ad hoc during an active security event.
For those who had experienced an incident and described its impact, downtime was the most frequently reported consequence, affecting 68.4% of respondents. The most common method of discovering an incident was through external observation, where a visitor, customer, colleague, or administrator noticed unusual site behavior. By the time such anomalies are detected, the incident may already be causing significant disruption.
Other detection methods included logging tools, which were the most effective monitoring control for catching incidents, as well as alerts from hosting providers and malware scanners. The timing of discovery appears to correlate with the severity of the impact. Incidents identified via a search engine warning, for instance, resulted in lost search rankings for 46% of those affected, a stark contrast to the 14.5% of incidents discovered through other means. This suggests that incidents severe enough to trigger search engine warnings have likely progressed further by the time they are found. One e-commerce site owner reported discovering a hack through Google Search Console due to a dramatic drop in traffic, noting that their search rankings never fully recovered.
Experts recommend developing and testing a recovery plan proactively. Key components include defining who is responsible for isolating compromised systems, restoring the site, and communicating with customers. It is also crucial to verify backups through restoration attempts, as an untested backup remains an assumption until proven functional. Melapress emphasizes the importance of training for all personnel, including content editors and administrators, whose actions can impact a site's security posture. Site owners should also ensure they know who receives security alerts, even when security management is outsourced to an agency or freelancer.






