
The short answer: A company website isn’t a finished object but a running system that degrades without maintenance: an outdated content management system and plugins become the entry point for automated attacks, an expired certificate or domain takes the site down overnight, and the hosting provider’s „backup" often doesn’t survive the very incident you need it for. Website management means four things done regularly: updates after a backup, working backups stored outside the hosting, uptime monitoring, and checks that the site isn’t spreading malware or SEO spam. If you can’t answer today who holds the access credentials to your website and when the last verified backup was taken, nobody is looking after your site.
Most company websites started life as a project: somebody built it, handed it over, invoiced it — and that was that. The site then „works somehow" for years, until one day it doesn’t. It stops sending the enquiry form, it starts offering Japanese replica watches on Google, or it simply disappears along with the hosting. This article describes what actually happens to an unmaintained website, how to tell whether it’s been hacked, and what monthly website management involves when it’s done properly.
A website decays even when nobody touches it
This is the least intuitive part for business owners. A car wears out when you drive it. A website decays even when you do absolutely nothing with it — because everything around it changes.
An outdated WordPress and its plugins
A large share of company websites in the Czech Republic run on WordPress or a similar content management system. The WordPress core itself is maintained decently; the real problem is plugins and themes. A typical company site has ten to thirty of them installed — forms, galleries, a page builder, an SEO plugin, backups, a cookie banner. Each one is code from a different author, with a different standard of maintenance, and each one may contain a vulnerability.
A disclosed vulnerability in a widely used plugin works like a starting pistol. Attackers don’t go through websites by hand — automated scanners sweep the internet looking for sites running the vulnerable version. Nobody „picked" your website. It was simply on a list of addresses where an old plugin version answered back.
Add to that PHP, the language WordPress runs on. Older PHP versions gradually stop receiving security patches, hosting providers switch them off sooner or later — and a website nobody has maintained will at that moment either break or keep running on an unpatched version. Both are bad, they just go wrong at different speeds.
Certificate, domain, hosting
Alongside the code, a website has operational dependencies that are even easier to forget:
- HTTPS certificate. Let’s Encrypt certificates are valid for 90 days and renew automatically — as long as the automation works. When it breaks, browsers start showing visitors a full-page warning and enquiries stop that same day.
- Domain. A domain expiring means the website and the company email addresses cease to exist. Recovery is usually possible, but the grace period isn’t infinite and the registrar account was often set up by somebody who no longer works at the company.
- Hosting. The invoice goes to a former employee’s email address, and the credentials are held by an agency that no longer exists. As long as a card is charged automatically, nobody notices the problem — until the first declined payment.
These aren’t doomsday scenarios, they’re everyday practice. We see it every time we take over IT for a new client: a list of website credentials is the first thing that’s missing. The same pattern — infrastructure where nobody knows who actually administers it — shows up in company networks too, as we describe in our article on auditing a computer network and cabling.
How to tell whether your website has been hacked
The Hollywood image of a hacked website is a blacked-out page with a skull on it. The reality is subtler and worse: today’s attacks are designed so that you notice nothing for as long as possible. A hacked company website is only valuable to an attacker while it keeps working — sending spam, hosting phishing, or feeding off your search rankings.
SEO spam: a parasite you can’t see in your browser
The most common form you’ll come across on small company websites is SEO spam. The attacker injects thousands of generated pages into the site — typically offers of counterfeits, pharmaceuticals or gambling — and uses your domain’s credibility to get them ranking in search. The best-known example is the so-called „japanese keyword hack", where search results for your site fill up with Japanese text.
The insidious part is that the spam is usually masked using a technique called cloaking: the search engine is served the spam content while an ordinary visitor sees a normal page. The owner looks at their website, it seems fine — and meanwhile Google is indexing thousands of fake pages. That’s why a hack is often discovered only through its consequences:
- search results for your site show a foreign language or nonsensical products;
- Google Search Console (assuming somebody reads it) reports a sudden jump in indexed pages or a manual action;
- browsers start blocking the site with a deceptive-content warning;
- company emails land in spam because the domain has picked up a reputation as a spam sender;
- the site slows down noticeably — foreign code and thousands of extra pages cost something.
Why „just delete the odd files" isn’t enough
Cleaning up a hacked website isn’t a matter of deleting a few files. During the breach, an attacker typically sets up a back door — an inconspicuous file in the image directory, a modified theme file, their own administrator account in the database, a scheduled task that restores the infection. If you delete only the visible spam, it’s back within a week.
A proper recovery means: working out how the attacker got in (and closing that hole), comparing files against a clean version, going through the database, invalidating every password and key, and only then asking the search engines for a review. And above all — having a clean backup you can start from. The logic is the same as with an encrypted NAS, which we cover in our article on ransomware on a NAS: without an independent backup you don’t recover from an incident, you negotiate with it.
Website backups: your hosting won’t save you
„But the hosting backs it up" is the most expensive sentence in website management. Hosting backups tend to have three weak points in practice:
- A short history. It’s usually a few days to a few weeks back. SEO spam, meanwhile, typically lives on a site for weeks or months before anybody notices — by which point every available backup is infected.
- The same basket. The backup sits with the same provider, often on the same infrastructure as the website. An incident on the hosting side — or simply a suspended account over an unpaid invoice — takes the site and the backup at once.
- Nobody has ever tried restoring them. A backup nobody has tested is an assumption, not a backup.
A working website backup has two parts: the files (theme, plugins, uploaded images and documents) and the database (text, orders, users). Both have to be backed up together, regularly, with a long enough version history — and at least one copy has to sit outside the hosting, with a different provider or on company storage. It’s the same 3-2-1 rule we go through in the article on an external drive as your only backup — except instead of family photos, what’s at stake is the website that brings the company its enquiries.
And once in a while you need to try a restore for real: take the backup, build a site from it at a test address and verify that it genuinely works. Only then do you know you have a backup.
What monthly website management involves
Website management isn’t „being on hand in case something happens". It’s a recurring routine that can be described as a concrete checklist:
- Updates done with judgement. The core, plugins and theme are updated regularly — but always after a backup and with a check that the update hasn’t broken anything. Blind automatic updates can take a site down just as reliably as no updates at all.
- Backups and checking them. Not just „the backup is running", but spot checks that it can actually be restored from.
- Uptime monitoring. An administrator should hear about an outage from monitoring within minutes, not from a customer the next day.
- Security checks. Scanning files for malware, integrity checks, checking for new administrator accounts, a review of login attempts.
- Watching expiry dates. Certificate, domain, hosting — with a reminder before it turns into an outage.
- Search Console and performance. Checking indexing (which is where SEO spam shows up first), speed and errors.
- Small content changes. New opening hours, an updated price list, current references — the things you otherwise wait weeks for „somebody who knows how to do it".
None of this is difficult on its own. The point is that it happens every month, demonstrably, and with one specific company accountable for it — not „when there’s time". With us, website management is part of our IT services for businesses: we take over the website including its credentials, sort out the backups and updates, and if you don’t have a website at all or the current one isn’t bringing in enquiries, we can build a new one and look after it from day one. The quickest first step is to get in touch — we’ll go through the state your site is in and what’s genuinely putting it at risk.
What a website and its management cost is a topic in itself — the scope for a small company differs depending on whether it’s a business-card site or an e-shop, and it deserves a separate analysis. What matters here is something else: knowing what to actually order when you order website management, so you’re not paying for „maintenance" that never happens.
Five questions you should know the answer to
If you want to check the state of your website in five minutes, try answering these:
- Who holds the credentials to the website administration, the hosting and the domain — and are they kept at the company rather than with a third party?
- When was the last backup taken and when did anybody last try restoring it?
- Who finds out about an outage, and how quickly?
- When were the content management system and plugins last updated?
- Who will fix the site when a browser warning comes up instead of the home page on Monday morning?
If you’re shrugging at two or more of these, nobody is looking after your website — you just don’t know it yet. And yet companies aren’t afraid to spend hundreds of thousands on marketing; how easily money gets funnelled into ads pointing at a website nobody looks after is something we describe in our article on the million we burned through on marketing. Advertising drives people to a website — and an unmaintained website will reliably turn them around at the door.
Frequently asked questions
An agency built my website. Don’t they look after it automatically?
Usually not. Delivering a website and managing it are two different services under two different contracts. If you don’t have maintenance explicitly agreed (and you’re not getting regular reports on it), the website simply runs after handover — without updates and often without working backups.
How do I tell my website is hacked when it looks normal?
Search Google for site:yourdomain.com and go through what’s indexed under your domain. A foreign language, pharmaceuticals, watches or gambling mean SEO spam. Google Search Console also helps (jumps in page counts, manual actions), as does checking whether the browser displays a warning for the site.
Is a WordPress backup plugin enough?
A backup plugin is a good start, but not enough on its own: if it saves the backups to the same hosting, an incident or a suspended account takes them along with the website. What matters is having a copy outside the hosting, a sufficient version history, and a restore verified from time to time.
My website got hacked. Should I delete it and build it again?
Not straight away. First you need to find out how the attacker got in — otherwise you build the new website with the same hole and it ends the same way. Cleaning up means closing the entry route, checking the files and the database, changing every password, and then requesting a review from the search engines so the warnings disappear.
What if I don’t even know where my website runs and who has the credentials?
You’re not alone — it’s the most common starting point we take over. It can almost always be traced: from DNS records, invoices and the domain registrar. That’s exactly why it makes sense to start with an inventory of credentials and the state of the site, rather than waiting for the emergency.