Your WordPress Site Is Attacked About Once a Minute. Here’s What That Looks Like.

Most site owners picture hacking as something that happens to someone else — a bank, a big retailer, a company with something worth stealing. The numbers from our firewall tell a different story.

According to our firewall logs, the average WordPress site we manage is hit by more than 1,300 malicious requests every single day — one attack attempt roughly every 65 seconds, around the clock.

That isn’t a bad day. That’s a normal one.

Nobody is too small to be a target

Nobody is “too small to be a target.” These aren’t people picking your site — they’re automated scanners sweeping the entire internet for a way in.

The moment your site goes live, it’s on the list.

An automated scanner is just a program that visits thousands of sites an hour, tries the same list of known weak spots on each one, and records which sites respond. No person is involved until something answers back.

A scanner doesn’t know or care whether you’re a dentist in Phoenix or a bakery with three employees. It sees a WordPress site, and WordPress sites all have the same doors.

It tries every one of them, moves on, and comes back tomorrow.

Tired of dealing with this yourself? That's exactly what we handle.

See our plans →

They know exactly what they’re looking for

Over 35% of what our firewall blocks is the same handful of attack signatures: scanners hunting for known-vulnerable plugins, trying to plant hidden backdoors, and checking whether someone already got in before them.

They know exactly what they’re looking for.

That last part is worth reading twice. A meaningful share of the traffic we stop is one attacker checking whether another attacker already succeeded.

A compromised site isn’t broken into once — it gets traded.

AI didn’t create this. It made it cheap.

AI hasn’t invented new attacks — it’s made the old ones cheaper, faster, and tireless.

A newly disclosed plugin vulnerability can be weaponized and sweeping the web in hours, not weeks.

Five years ago, a site owner who missed a plugin update had a window of days or weeks before anyone came looking. That window is closing.

By the time the plugin’s update notice shows up in your dashboard, the scanners have often already been by.

What “blocked” actually means

Every number above is a request that was stopped at the edge. “The edge” just means out in front of your site — the request was turned away before it ever reached your site, your database, or your login page.

Your site never had to defend itself, because the request never arrived.

That’s the whole point of a firewall that sits in front of the site, before traffic reaches it, rather than inside it. A security plugin can only act on traffic that already made it through the front door.

Even when the plugin does its job, there’s a cost to that. Every one of those 1,300 daily requests has to wake up WordPress, run code, and check the database before the plugin can turn it away.

That’s server time your real visitors are competing for — and on most hosting plans it’s exactly the kind of load that gets a site slowed down or flagged for using too many resources.

Blocked at the edge, the request never reaches the server at all. The attempt costs your site nothing: no load, no risk, no cleanup.

Ours isn’t a generic, off-the-shelf rule set. It’s built around what actually hits the sites we manage, and actively updated as that changes. The scanners change what they’re looking for. The firewall adapts in response.

Every week, the attack traffic across the whole fleet is reviewed — which paths the scanners are probing, which plugins they’re hunting for, which tricks are new this week — and the rules are strengthened to match.

When a fresh campaign shows up on one site, the block goes out to every site we manage. One client’s bad week becomes everyone else’s non-event.

That’s the difference between a firewall that ships with a fixed list and one that learns from the traffic it’s actually seeing.

What this means for you

If your site is on WordPress, this traffic is hitting it right now. The only question is whether something is standing in front of it.

If you’re an OnsiteWP client, it already is — these are your numbers.

If not, we’d be happy to take a look at your site
and tell you honestly where it stands.
No pressure, no commitment.

Frequently asked questions

How often is a WordPress site attacked?

Constantly. Across the sites we manage, the average site is hit by more than 1,300 malicious requests a day — roughly one every 65 seconds. Most of that is automated scanning, not a person targeting your business.

My site is small. Is it really a target?

Yes. Scanners don’t choose targets — they sweep every reachable site and try the same list of known weak spots on each one. A small site with an outdated plugin is easier to get into than a large one that’s maintained, so small sites get hit just as often.

Doesn’t my security plugin already handle this?

A security plugin can only act on traffic that has already reached your site. It still has to wake up WordPress and check the request before turning it away, which costs server time and can slow the site down. A firewall in front of the site stops the request before it arrives at all.

What is a firewall “at the edge”?

It’s a firewall that sits out in front of your site rather than inside it. Malicious requests are blocked before they reach your server, your database, or your login page — so your site never has to defend itself and spends nothing on the attempt.

Hassle-Free Managed WordPress Hosting Since 2016
© 2026 ONSiteWP