Why does my website keep getting hacked?

by Kevin Kahn

If you're asking why does my website keep getting hacked, the answer is usually not that malware showed up. That's the symptom. The real problem is that nobody owns the site closely enough to notice what changed, what got installed, or where the alerts went.

A client called me after his website was offline for sometime over at name.com. Twelve years old, and it held decades of columns he'd written for trade publications. One morning it was a suspension notice from his host. His webmaster had stopped answering. He didn't know who to call or whether his work was gone. The panic isn't technical. It's personal.

The suspension notice that explained nothing

The host's email said the account had been filled with exploits and malware. That was the whole explanation. No filenames, no dates, no clue whether the problem was one file or fifty.

Then it offered a one time courtesy unsuspension if he agreed to change every password and clean up the account himself. If your only involvement with your website is logging in to post, that isn't advice. It's a liability handoff. He forwarded it to me weeks later still not knowing what it meant. That's normal. Hosting notices get written like legal disclaimers, not explanations.

A malware alert without context is not a diagnosis. It's a warning light on the dashboard. People waste time solving the wrong problem because of it.

He thought decades of work was gone

His actual fear was that thirty years of writing had disappeared. That was reasonable. Suspended accounts do get purged eventually. The good news took about ten minutes to confirm: nothing had been deleted. The files were exactly where they had always been. The site was stuck behind a wall he had no way through.

A site can be unavailable without being destroyed. But if you don't control the hosting, the admin login, or the email on the account, those feel identical from where you're standing.

The malware was already gone before I got there

By the time I had access, the host's scanner had found the malicious files and emptied them six weeks earlier. Two plugin folders were still on the server, but they were empty shells. If I had run another scan and trusted the result, I'd have gotten a clean report and learned nothing.

The evidence was in the PHP error log. 967 entries from one week in December where a plugin named hseo repeatedly contacted a command and control server asking what to do next. That log had been sitting there for nine months. Nobody had read it.

The plugin list had 21 active plugins and nobody had reviewed it in years. Two were fake. hseo was one. The other was wp-helper-70a4e6, a believable WordPress style name plus random characters so it blends into the list.

The malware was already gone before I got there – Kevin Kahn Web Development, Wilmington DE

Neither jumps off the screen unless someone is looking. Notice the timestamps: both fake plugins were emptied at the same minute by an automated scanner, and nobody saw the report.

Here's the detail that stuck with me. wp-helper was still marked active in the database after its code had been deleted. The site was booting up every day trying to load something that no longer existed.

Plugins are not evil. But every plugin is another dependency, and dependencies need someone keeping an eye on them. If your site depends on 21 outside tools, you're depending on 21 separate update cycles and security histories. If someone is actively watching that, fine. If nobody is, a simpler build is the smarter choice.

The thing that actually worried me

The malware was bad. This was worse. In the web root sat a file called .tmb.zip, 351 MB, created in August 2025. A complete backup of the entire site, publicly downloadable by anyone who guessed the filename. I tested it. The server handed it right over. Inside was the configuration file with the database password in plain text.

The thing that actually worried me – Kevin Kahn Web Development, Wilmington DE

It had been sitting on the open web for about a year. Nobody knew it existed. It was almost certainly created by accident by a file manager plugin, which is how this usually happens. Not a movie hacker. Just clutter nobody cleaned up. Don't only ask whether your site was hacked. Ask what else is exposed because nobody has been checking.

The admin account belonged to someone else

There was exactly one user on the site: admin, registered in 2021. The email on it was a personal Gmail belonging to a developer my client had hired years earlier. Password resets went to that address, not to my client.

Then I pulled the login history. Every login from 2023 through 2025 came from overseas mobile carrier IP ranges. That wasn't a dramatic reveal. It was almost certainly the developer doing his job. But that's the point. A third party held the only working admin access, and when he stopped answering there was no path back in.

A business pays to have a site built, assumes the setup details are temporary, and years later finds the domain, hosting, admin account, and recovery emails all point somewhere else.

A hack is usually an ownership problem first

This is not a story about WordPress being bad software. WordPress runs a huge part of the web and runs it fine. What happened here is that a site had 21 active plugins, years of neglect, alerts going to an inbox nobody monitored, an error log full of evidence nobody read, a public backup sitting in the open, and no single person responsible for any of it. Every problem traced back to the same gap. Nobody was in charge.

So if you're wondering why does my website keep getting hacked, that's the question I'd ask first. Not who paid for it. Who actually checks the updates, the user accounts, the logs, the backups, the plugin list, the alert emails. If the answer is nobody, the fix isn't cleaning malware. It's assigning responsibility, or reducing complexity so there's less to manage.

Three things worth checking today

Each of these takes a couple of minutes.

Your domain registrar.Log in and confirm the account is in your name with your email on it.
Your admin email address.Log into your website admin and check who the administrator account belongs to. If it's a developer from years ago, you have a control problem before you have a security problem.
Who would notice.Ask who would spot it first if your site went down tomorrow, and whether that person has the access to fix it.

That last one is the whole article in one sentence.

If nobody would notice, nobody would know what broke, and nobody has clear responsibility, the site is exposed before any attacker shows up.

If you want a second set of eyes on it, reach out. I can usually tell pretty quickly whether you have a malware problem, an access problem, or an ownership problem pretending to be both.

Frequently Asked Questions

Why does my website keep getting hacked even after malware is removed?

Because removing malware is often just cleanup, not a fix. If the old admin account is still wrong, suspicious plugins are still active, alerts still go to an ignored inbox, or backups are exposed, the same conditions are still there. That means the next problem is just waiting its turn. A clean scan does not mean the underlying mess is gone.

Can a WordPress plugin really cause this much damage?

Yes, if nobody is paying attention to what was installed and why. In this case, one fake plugin was repeatedly contacting a command and control server, and another fake one was still marked active even after its files were gone. That doesn't mean all plugins are bad. It means every plugin is another thing someone has to keep an eye on.

What's worse than malware on a hacked site?

The malware got the headline, but the backup file worried me more. A full site backup was sitting publicly downloadable in the web root, and it included the configuration file with the database password in plain text. That kind of exposure can outlast the original infection by months. It's exactly the sort of thing people miss when they only run a scanner and stop there.

How do I know if I actually control my website?

Check your domain account, hosting account, and website admin account today. Make sure your email is on all of them and that password resets come to you or someone at your business you trust. If an old developer's personal email is still attached to the admin user, you do not fully control the site.

How often should someone actually be looking at my website?

A lot less often than people assume. Quarterly is enough for most small business sites: check that plugins and core are current, look at who has admin access, and confirm backups are landing somewhere you can reach. The problem on this site was not that nobody checked monthly. It was that nobody had checked in years, and nobody had agreed to.

My site was hacked. Do I need to start over with a new domain?

Almost certainly not. A compromised hosting account and a compromised domain are different things, and in most cases the domain comes through fine. Check it against Google Safe Browsing and the common blacklists before you decide. Giving up a domain you have had for years throws away every link and citation pointing at it, and those are not things you can go back and fix.

Have questions about your website or want to discuss a project?