I have been doing a lot of website archaeology lately for small businesses around St. Petersburg and Tampa Bay. Sites built somewhere around 2012, never really touched since, and now the owner needs the thing to work again. There's a whole graduating class of them surfacing at once, and they all have the same story.
Plugins accounted for 91% of the 11,334 new WordPress vulnerabilities disclosed in 2025, while WordPress core itself accounted for six (Patchstack, State of WordPress Security in 2026, published February 25, 2026). That's the whole story of these sites in one number. The core software kept up. Everything bolted onto it did not.
The class of 2012 is all graduating at once
The call sounds the same almost every time. "I think I need help with my website. I'm not sure my login works. My web guy stopped answering a while back."
That's not carelessness. The site loaded. Nothing looked broken. There was no reason to log in for eleven years. Then something finally forces the issue: a phone number changes, a service gets added, a customer mentions the contact form is dead, or the owner starts wondering why ChatGPT keeps recommending three competitors and never them.
So we open the hood. What's under there is usually not one problem. It's a decade of small unattended ones stacked on top of each other.
Before anything else, can you get into your own website?
This is the part I want every owner to hear, even if you never hire anybody. Keeping and modernizing your existing site is completely reasonable. But you need to be able to produce these six things.
Credential 01
Your domain registrar login.
Where the domain name itself lives. Usually GoDaddy, Namecheap, or Network Solutions, and often not the same company as your hosting.
Credential 02
Your hosting account login.
The company charging you monthly or yearly to keep the site online. This is the account that gets you to cPanel, which is the back door into everything else when the front door is locked.
Credential 03
A WordPress admin login at Administrator level.
Editor access is not enough to fix anything structural. If you're not sure which one you have, log in and look for the Plugins menu. If you can't see it, you're not an administrator.
Credential 04
The email address attached to all three.
This is the one that sinks people. If password recovery goes to an inbox at a domain you stopped using, or to a former employee, every other credential on this list gets significantly harder to recover.
Credential 05
Where your DNS points.
Domain at one company, site at another, email at a third is extremely common and completely fine, as long as somebody has the map.
Credential 06
Who owns and renews your SSL certificate.
Usually the host. Sometimes not. Worth knowing before the day it expires and your site starts warning visitors away.
If you can't produce those, don't panic. Hosting support and cPanel can usually get you back in with proof of ownership. But it's real work, it takes real time, and it will be the first line item on any project rather than something anyone can skip.
One note while we're here: never email your passwords to anyone, including me. Use a share link or a password manager. Anyone who asks you to put credentials in a plain email is telling you something useful about how they work.
What I keep finding once we're in
A short tour of the greatest hits.
Ghost admins. Old contractors, a former agency's entire staff, the web person two web people ago, all still sitting at Administrator level. Nobody removed them because nobody knew to look. Every one of those accounts is a live key to your site.
Contact forms routing to dead email addresses. The form still submits. The visitor still sees the thank you message. The lead goes to an inbox that stopped existing in 2019. I've found sites quietly dropping every inquiry for years.
Abandoned plugins. WordPress.org treats a plugin as abandoned when it hasn't been updated in roughly two years, and abandoned doesn't mean it stops working. It means nobody is fixing it when a hole gets found. Of 827 vulnerable plugins and themes Patchstack reported to the WordPress team in 2023, 481 were removed from the repository rather than patched (Patchstack, reported via DreamHost, July 2026). No fix ever came for those. Plenty of sites are still running them right now.
No backups. Sometimes there's no backup system at all. Sometimes there's one that stopped writing to a storage account four years ago and nobody checked, which is arguably worse, because everyone thinks they're covered. If you want the fuller list of what quietly breaks on an unattended site, I've written about the website mistakes that keep small businesses out of AI answers separately.
And then there's the one that actually costs the most money, which deserves its own section.
The dead newsletter form is the most expensive thing on that list
Owners treat the newsletter signup like decoration. It is not decoration. It's the only marketing channel you actually own.
Everything else is rented. Google changes how it ranks you. Instagram throttles your reach. ChatGPT names a competitor tomorrow and never tells you why. Your email list is the one audience nobody can take away, reprice, or bury in an algorithm. Email marketing returns roughly $36 for every $1 spent, compared to about $2 to $5 for paid social (Litmus, 2024, widely reported through 2026).
So when I find a signup form wired to a tool the business canceled in 2018, what I'm looking at is years of people raising their hand to say "I want to hear from you," landing nowhere. Those were the warmest leads the business had. Past customers. The person who almost booked and wanted a reason to come back.
And it still looks like it works. The form submits. The thank you message appears. The owner assumes the list is somewhere. It's nowhere. Usually it's the "Join our newsletter!" box that's been sitting in the footer since 2013, right next to a Twitter bird icon linking to an account that stopped posting in 2016.
If you can't find where your own signup landed, you don't have a list. You have a form.
So do this today: subscribe to your own list from a personal email address, then go find where that address landed. Ten minutes. If you can't find it, you know what you're dealing with.
Why keeping a bad website costs more than replacing it
I'm not romantic about rebuilds. If your site works, keep it. But there's a specific kind of site where holding on is the expensive choice, and owners rarely see the math because it arrives in pieces too small to notice.
A site built as a hackjob charges you a tax on every single change. A twenty minute edit becomes two hours because the page was built in a page builder that no longer builds, layered over a theme that fights it. You pay that tax every time, forever. Add hosting for a site producing nothing, an eventual security cleanup, and the leads that quietly went nowhere, and the cheap option stopped being cheap a long time ago.
The speed of the risk is what most people underestimate. The weighted median time from a WordPress vulnerability being disclosed to first exploitation in 2025 was five hours, and 46% of vulnerabilities had no patch available when they were made public (Patchstack, State of WordPress Security in 2026, published February 25, 2026). Nobody is personally targeting your dog grooming site. Automated scanners find it because it's reachable and out of date.
Keep it or rebuild it: how I actually decide
Keep and optimize
The foundation is fine. The work is content, schema, and cleanup, not construction.
Rebuild
You'd pay more to untangle it than to replace it, and you'd still own the tangle afterward.
Recover access first, then decide
You can't make a real decision about an asset you don't control.
Rebuild lean, put the effort into Google Business Profile
A fast, correct, simple site plus a strong profile beats a big broken site for local demand.
Keep and migrate carefully
Do not blow up URLs that are working. Ever.
If you land on rebuild, the next question is always "on what?" That's a separate decision with real tradeoffs, and I've broken it down in Shopify vs Squarespace vs WordPress for small business. If you land on the local-search row, start with the Google Business Profile checklist before you spend a dollar on the website itself.
If you keep it, here's what bringing it forward means
Modernizing an existing site is a legitimate path. It's not a consolation prize. It just has a specific checklist.
- Secure and document ownership of domain, hosting, and admin, in your name, on an email address you control
- Remove every admin account that isn't a current person
- Prune plugins down to what's actively maintained and actually used
- Fix form routing, then test it from an outside email address every quarter
- Reconnect the newsletter form to an email platform you're actually paying for
- Confirm your name, address, and phone match your Google Business Profile exactly
- Add schema markup so search engines and AI tools can read what your business is
- Then, and only then, work on the content
Why this matters more in 2026 than it did in 2019
Here's what changed. Your website is no longer just something a person visits after they find you. It's source material. ChatGPT, Google AI Overviews, Gemini, and Perplexity are reading sites like yours to decide who to name when somebody asks for a recommendation in your city.
A site that's thin, outdated, or structurally broken gives those systems nothing specific to cite. It's not that you rank lower. You're not in the answer at all. If you want the short version of what actually moves that needle, it's four things, not a strategy deck.
The practical version of the problem is simpler than that. If an AI tool does recommend you, and the person clicks through to a contact form pointed at an inbox nobody has opened since 2017, you earned the visibility and handed the lead to nobody.
And as AI answers keep more people from clicking through to any website at all, the audience you own directly gets more valuable, not less. Getting cited by Perplexity puts you in front of someone once. A working email list lets you stay there.
This is what demystifying AI usually looks like in practice. Not a strategy deck. Plumbing.
The takeaways
- Keep the site if you have full access, the platform is current, and the structure still fits the business. Modernizing an existing site is a real path, not a consolation prize.
- Rebuild if you're locked out, dependent on abandoned plugins, or sitting on custom work nobody can maintain.
- Know your credentials before you need them. Domain registrar, hosting, WordPress admin, and the email address attached to all three.
- Your newsletter list is the only channel you own. Email returns roughly $36 per $1 spent versus about $2 to $5 for paid social (Litmus, 2024). A signup form pointed at nothing has been costing you the warmest leads you had.
- Plugins caused 91% of the 11,334 WordPress vulnerabilities disclosed in 2025, and WordPress core caused six (Patchstack, February 25, 2026). The risk is almost never the platform. It's what got added to it.
- Test your contact form from an outside email address this week. Free, four minutes, and the single most common broken thing I find.
Last updated: July 25, 2026
Sources
- Patchstack, State of WordPress Security in 2026, published February 25, 2026
- DreamHost, Abandoned WordPress Plugins: How To Find & Replace Them, July 2026, citing Patchstack 2023 disclosure data
- Litmus, email marketing ROI research, 2024, as reported through 2026