What the 1.2 Million WordPress Site Breach Can Teach You About Website Security

The recent supply chain attack that affected more than 1.2 million WordPress websites may no longer be making headlines, but it offers some valuable lessons for website owners and hosting resellers.
The biggest one is simple: a deactivated plugin isn’t always a safe plugin. Many website owners believed they were protected because the affected plugins had been disabled.
This incident proved that leaving unused plugins installed can still expose a website to serious security risks.
If you manage WordPress websites or run a reseller hosting business, now is a good time to review your security practices, and encourage your clients to do the same.
How the Attack Worked
The attack targeted three popular WordPress marketing plugins:
- OptinMonster
- TrustPulse
- PushEngage
Instead of attacking the plugins directly, the hackers compromised external scripts loaded by them.
When a WordPress administrator logged in, those scripts ran with administrator privileges, allowing the attackers to take control of the website.
What the Attackers Left Behind
The attackers weren’t interested in simply defacing websites. Their goal was to maintain long-term access.
Investigations found that compromised websites often contained:
- Hidden administrator accounts (such as developer_api1 and wpsecurebot)
- Fake system plugins
- Hidden MU plugins
- Malware hidden from the WordPress dashboard
- SEO spam, fake browser update pages, and sometimes cryptocurrency miners
How to Check а Website
If а website had OptinMonster, TrustPulse, or PushEngage installed – whether active or inactive, it’s worth performing a full security review.
Simply deleting the affected plugins won’t remove any backdoors that may already have been installed.
1. Review Administrator Accounts
Don’t rely only on the WordPress Users page, as malicious accounts may be hidden.
Instead, check the wp_users table (or use WP-CLI) and look for administrator accounts you don’t recognize.
2. Inspect Plugin Folders
Review the following directories:
- wp-content/plugins/
- wp-content/mu-plugins/
Look for unfamiliar plugins or folders, and scan your files for known signs of compromise.
3. Change Your Credentials
If you find any evidence of a compromise:
- Reset all administrator passwords.
- Generate new WordPress Secret Keys (Salts).
- Change your database password.
- Replace any API keys connected to the website.
4. Rebuild the Site if Necessary
If the website has been heavily compromised, reinstalling WordPress from a clean copy is often faster and more reliable than trying to remove every hidden backdoor manually.
How to Better Protect Your Website
This incident also shows why it’s important to monitor changes made to а website.
A WordPress activity log plugin can alert the website owner whenever a new administrator account is created, a plugin is installed, user roles change, or suspicious login attempts occur.
One of the most popular options is WP Activity Log, while Melapress Login Security adds free two-factor authentication and brute-force protection.
Most importantly, remember this simple rule:
If you no longer use a plugin, delete it.
Disabling a plugin is not the same as removing it.
A Reminder for Hosting Resellers
Hosting resellers provide more than server space – they also help customers keep their websites secure.
Many clients may never hear about attacks like this, or they may assume that disabling a plugin is enough.
A short email explaining the incident and encouraging customers to remove unused plugins can prevent future problems.
It’s also a great opportunity to strengthen your relationship with your clients by showing that you’re actively looking after their security.
A Simple Security Checklist
Following incidents like this, it’s good practice to:
- Scan hosted WordPress websites for the affected plugins.
- Notify clients in simple, non-technical language.
- Encourage customers to remove unused plugins and themes.
- Offer security audits or malware cleanup services when needed.
The Web Host’s Role in Website Security
Website security doesn’t stop with WordPress. The web hosting provider also plays an important role.
We have created a secure hosting platform that blocks many known attacks at the server level.
We have also added the Jail Host option for each host, which isolates each website from interacting with others in the same account.
We regularly apply OS security patches, and we offer automatic daily backups if something goes wrong.
Even so, the responsibility is shared. While we protect the server, it’s up to the customer to keep WordPress, plugins, and themes updated – and to remove software no longer in use.
***
This attack may be over, but the lessons are just as relevant today.
Regular security reviews, deleting unused plugins, monitoring administrator accounts, and keeping clients informed are simple steps that can significantly reduce the risk of future compromises.
For hosting resellers, these best practices do more than improve security – they demonstrate expertise, build trust, and help create long-term customer relationships.
Originally published Tuesday, July 7th, 2026 at 9:57 am, updated July 7, 2026 and is filed under Web Hosting Platform.
Leave a Reply