Most people who run WordPress sites worry about security. Few have a plan for when something goes wrong. That is the main finding of Melapress’s 2026 WordPress Security Survey.
The survey drew 319 responses from agencies, developers, designers, site owners and administrators between March and July. Respondents rated their concern about security at 7.85 out of 10, almost the same as last year’s 7.8.
Concern has not turned into preparation
Only 27.9% said they had a breach recovery plan. Last year it was 27%. Team security training sits at 26%, unchanged from 2025.
Even among people who rated their concern at 7 or higher, just 32.5% had a recovery plan.
Overall, 67.7% reported at least one known security incident. Downtime was the most common result, reported by 68.4% of those hit. Last year’s headline figure was 96%, but Melapress says that survey likely used a broader definition of “incident.”
Hacks are noticed by accident
The most common way people found out about an incident was that someone noticed the site behaving strangely. That was 42.6% of cases. Logs or alerts caught 38.4%, hosting provider alerts 35.6%, and malware scanners 30.1%.
Melapress CEO Robert Abela told The Repository that people focus on hardening, like installing a firewall, and skip monitoring. By the time a visitor spots a problem, he said, you are “reacting to a hack.”
Higher-stakes sites did better. Among membership sites, 44.1% had a recovery plan, and 35.8% of ecommerce respondents did.
What to do
- Write down who restores your site, from which backup, and who tells your customers.
- Turn on some form of monitoring: an activity log, host alerts, or a malware scanner.
- Test your backups before you need them.
Melapress sells the WP Activity Log plugin, and its report notes that some responses came through its own channels. Well over half came from third-party channels.
End of article