Key takeaways

  • Attacks are mostly automated: bots scan the whole internet for known weaknesses, so every site is in scope.
  • AI-assisted tools shorten the time between a vulnerability being published and it being exploited.
  • Plugin supply chain attacks and nulled plugins deliver malware through software you chose to install.
  • Shared hosting and multi-site servers let one infected site spread to all its neighbours.
  • The answer is faster patching, server-side scanning and continuous monitoring, not a single security plugin.

Why are malware attacks on websites increasing?

Malware attacks on websites are increasing because attacking has become cheap, fast and automated. Bots scan the whole internet continuously, AI-assisted tools help attackers find and weaponise flaws faster, plugin ecosystems create a large supply chain to exploit, and shared servers let one compromise spread to many sites. Meanwhile, websites hold more valuable data than ever.

None of these forces is new on its own. What has changed is that they now reinforce each other. A vulnerability disclosed in a popular plugin can be turned into a working exploit, loaded into a scanning tool and fired at huge numbers of sites in a short space of time. The sites that get hit are not chosen; they are simply the ones that had not yet updated.

Well-known sources point in the same direction. The Verizon Data Breach Investigations Report has highlighted the growing role of vulnerability exploitation as a way in, and the UK Government's Cyber Security Breaches Survey continues to find cyber attacks a routine experience for UK businesses. For a closer look at the evidence, read what the malware statistics actually show.

How has automation changed website attacks?

Automation means attackers no longer choose targets by hand. Scripts scan IP ranges and domain lists around the clock, fingerprint the CMS and plugin versions each site runs, and launch exploits against anything that matches. A single operator can attack enormous numbers of sites, so every website with a known weakness is effectively a target.

You can see this in almost any server's access log. Within minutes of a site going live, requests start arriving for files that do not exist on it, testing for common weaknesses:

203.0.113.24 - - "GET /wp-login.php HTTP/1.1" 200
203.0.113.24 - - "POST /xmlrpc.php HTTP/1.1" 200
198.51.100.7 - - "GET /wp-content/plugins/old-slider/upload.php HTTP/1.1" 404
198.51.100.7 - - "GET /.env HTTP/1.1" 404
198.51.100.7 - - "GET /wp-content/uploads/2024/05/cache.php HTTP/1.1" 404
# 404s are probes for plugins, secrets and existing webshells

Note the final probe: attackers routinely check whether a site already has a known webshell installed by someone else. Compromised sites are traded and re-used, which is why one infection so often leads to several.

Automation also lowers the skill needed to attack. Ready-made webshell kits, such as the ALFA and KINGSMAN families we regularly find on compromised servers, come with file managers, database tools and one-click options to spread to neighbouring sites. Credential-stuffing tools try passwords leaked from other breaches against login pages at scale. The result is that attacks which once required an experienced operator can now be run by almost anyone, continuously and cheaply, against every reachable site at once.

Is AI making website attacks worse?

AI is making website attacks faster rather than fundamentally different. AI-assisted tools help attackers read vulnerability disclosures and code changes, draft working exploits, generate convincing phishing emails and vary malware so it is harder to fingerprint. The main effect is a shorter window between a flaw being published and it being exploited at scale.

In practice this compresses the timeline that website owners used to rely on. A monthly update routine once left a reasonable margin; now it can leave weeks of exposure. AI also helps with the less technical side: phishing emails aimed at site owners, developers and hosting customers are better written and more personalised, which leads directly to stolen admin and hosting credentials.

The same technology works for defenders too. PatientZero's platform uses AI-assisted analysis alongside forensic rules to triage findings across every site on a server, so that suspicious files, cron jobs and accounts are prioritised quickly and reviewed by a human.

Tip: turn on automatic updates for plugins you trust, and review the rest weekly. Speed of patching now matters more than almost any other single control.

What is a plugin supply chain attack?

A plugin supply chain attack is when malware reaches your site through software you trust, rather than through a flaw you left open. It happens when a developer's account is compromised, a popular plugin is sold to a new owner who adds malicious code, or an abandoned plugin is taken over. Your site updates normally and installs the malware itself.

These attacks are especially hard to spot because the malicious code arrives through the official update route, signed off by the normal process and installed by your own site. Signs include a plugin that suddenly changes ownership or support address, new outbound connections to unfamiliar domains after an update, or new administrator accounts appearing with no explanation.

  • Keep the number of plugins to what you genuinely need.
  • Remove plugins that have not been updated by their developer in a long time.
  • Watch for ownership changes on plugins you depend on.
  • Use file integrity monitoring so that unexpected changes after updates are flagged.
  • Scan outbound connections and scheduled tasks on the server, not just files.

Security triage

Is your site showing any of this?

Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.

Start the triage

Why are nulled plugins and themes so dangerous?

Nulled plugins and themes are pirated copies of premium software with the licence check removed, and they are one of the most common sources of website malware we see. Whoever "nulled" the software can add anything they like, and many include backdoors, hidden admin creation, spam link injection or code that downloads further malware later.

The appeal is obvious: a premium theme or page builder for nothing. The cost comes later. Nulled software cannot be updated through the normal route, so even if it arrived clean it quickly becomes vulnerable. And because the malicious code is part of the plugin itself, security plugins often treat it as legitimate.

RiskLicensed pluginNulled plugin
Source of codeOriginal developerUnknown third party
Security updatesDelivered automaticallyNone, or via the same untrusted source
Hidden backdoorsNot expectedCommon
Support if hackedDeveloper can helpNone

If a site you have inherited uses nulled software, treat it as compromised until a forensic scan shows otherwise, and replace the software with licensed copies. The same applies to plugins or themes supplied as ZIP files by a previous developer without a clear source.

How does shared hosting spread infections?

Shared hosting spreads infections because many sites often run under the same system user or account, so any site that is compromised can read and write the files of every other site alongside it. An attacker who exploits one outdated WordPress install can plant webshells in all of them and read every wp-config.php for database passwords.

The same applies to agency and business VPS servers hosting many client sites. We regularly see a single forgotten staging site or old microsite become the entry point for a whole server. Cleaning only the site that showed symptoms leaves the others infected, and the malware returns within days. Our guide on why one hacked site infects the rest covers how to isolate sites properly.

This is why PatientZero scans every site on the server as standard, and why our server malware removal covers the operating system level: cron jobs, systemd services, rogue users and fake system binaries as well as website files.

What should website owners do about rising attacks?

Website owners should respond to rising attacks by patching faster, reducing what can be attacked, protecting credentials, scanning on the server and monitoring continuously. None of these is expensive or complicated, but together they remove the easy weaknesses that automated tools depend on and make sure an infection is found in hours rather than months.

  1. Update promptly. Enable automatic updates where you can and review the rest weekly.
  2. Reduce the attack surface. Delete unused plugins, themes, staging sites and old admin accounts.
  3. Harden the server. Block PHP execution in uploads, use SSH keys and isolate each site. See our Harden playbooks.
  4. Scan server-side. Plugins inside WordPress cannot see the whole server.
  5. Monitor 24/7. Catching an infection early keeps it small.

PatientZero does all of this for you from £99 a month per site, including unlimited malware removal and no contract. Get protected, or talk to our team.

Frequently asked questions

Why would anyone hack my small website?

Usually nobody chose your site. Automated tools scan for known weaknesses and compromise whatever they find. Once in, attackers use your search reputation for spam, your visitors for redirects, your server for sending email or attacking others, and any customer data for fraud. Small sites are attractive because they are often less closely monitored.

Are AI tools really being used to hack websites?

AI tools are widely available and are used by attackers, as they are by defenders, to speed up routine work such as understanding vulnerabilities, writing scripts and producing convincing phishing emails. The main practical effect for website owners is that the time between a flaw being published and it being exploited is shorter.

Is it safe to use nulled WordPress plugins?

No. Nulled plugins come from unknown third parties, cannot be updated safely and frequently contain backdoors or spam injections. Any saving on the licence fee is usually far outweighed by the cost of cleaning a compromised site. Replace them with licensed copies from the original developer.

Does moving to a VPS make my site safer?

A VPS gives you more control, but it is only safer if it is configured well. Many VPS servers host several sites under one user with no isolation, so one infected site can still reach the rest. Separate users per site, hardened SSH and server-side scanning are what make the difference.

PatientZero Incident Response Team · Digital forensics and incident response

Written by the PatientZero incident response team: the engineers who investigate and clean compromised WordPress sites and Linux servers every week.