Security1 publisher2 min readPublished Updated
Fewer than three in ten of 319 WordPress professionals have a breach recovery plan
Melapress surveyed 319 WordPress professionals about the incidents they had handled. Its numbers say the decisions about isolating, restoring and notifying customers are mostly being made in the middle of the outage.
The Watch · Security desk

What happened
- Melapress, which sells WordPress security plugins, surveyed 319 professionals who build and run WordPress sites for a living, and most of them had dealt with at least one known security incident.
- The most common way respondents learned of an incident was that someone noticed the site behaving strangely, whether a visitor, a customer, a colleague or an administrator.
- Downtime was the most common result, reported by 68.4% of respondents who had been hit and described the impact.
- Logging tools were the monitoring control that caught incidents most often, with hosting provider alerts and malware scanners catching them for other respondents.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision At least 224 of these practitioners will decide who isolates, who restores and who calls the customer while the site is already down.
- cost Restoring a site does not restore its search position, so the owner keeps paying in lost traffic after the incident is closed.
- exposure A site owner who hands security to an agency or freelancer can be the last party to hear about an incident, because the alert routing sits with the contractor.
- constraint These percentages bound what 319 people in a security plugin vendor's survey pool report; they are not a measurement of the WordPress installed base.
Late discovery shows up in the damage. Among incidents that a search engine warning helped surface, 46% involved lost search rankings; among incidents found some other way, 14.5% did [5]. That is about 3.2 times the rate [12]. The Help Net Security writeup argues the warning is not the cause, and that an incident lasting long enough, or doing enough damage, to catch a search engine's eye has probably already progressed by the time anyone looks at it [6].
Run the proportion against the sample. Fewer than three in ten of 319 means at most 95 respondents have a recovery plan and at least 224 do not [2][13]. Melapress says the plan settles in advance who responds, where the clean backups are and who needs to be told [2]. Without one, those calls get made during the incident [14].
The recommendation in the report is to write the plan before it is needed and test it: who isolates the damaged systems, who restores the site, who tells customers [10]. Melapress puts the backup in the same category, since one that has never been restored is an assumption until someone tries it [11].
One ecommerce site owner found out through Google Search Console that traffic had cratered after a hack. "Unfortunately, the rankings never fully recovered," the owner said [8].
Melapress sells WordPress security plugins, and the 319 respondents are its own survey pool [1], so the percentages describe practitioners who answered a plugin maker's questions. The company also treats training as a core control, because content editors and administrators make choices that affect a site's security [9]. Its other recommendation concerns routing: the person who owns a site should know who receives the security alerts, even when an agency or freelancer handles security [9].
What to watch
- Whether Melapress publishes recruitment and response-rate detail, so the 319-respondent figures can be compared with the wider WordPress installed base.
- Whether a follow-up survey separates respondents who have a written plan from those who have actually run a restore from backup.
- Whether the ranking-loss gap between search-engine discovery and other discovery holds in a second, non-vendor dataset.