Why Bots Attack WordPress Plugins (and Why Yours Is on the List)
Your site isn't being targeted — it's being harvested. How automated attacks find plugins like Gravity Forms and The Events Calendar, and why the treadmill never ends.
Here is the thing nobody tells you when you get that “suspicious login attempts” email: nobody chose your website. No one is sitting in a dark room targeting your salon or your HVAC company. Your site is being harvested — swept up by automated scanners that visit every WordPress site on the internet, around the clock, and check each one against a list.
The list is plugins.
How the harvest works
Every plugin you install leaves fingerprints in your site’s public code — file paths, script names, version numbers. A bot reads those fingerprints in under a second. Then it checks them against public databases of known plugin holes, the same databases security researchers publish so site owners can patch.
If your version of a plugin has a known hole, the bot doesn’t file a report. It walks in. Spam pages, redirects to sketchy pharmacies, stolen customer emails, or a quiet foothold it sells to someone else.
In 2025 alone, researchers logged more than eleven thousand new WordPress security holes — and 91% of them were in plugins, not WordPress itself. The median time from “hole published” to “bots exploiting it” is now about five hours. Your maintenance window is not five hours.
The popular plugins are the biggest targets
This is the part that feels backwards. The best plugins — the ones on millions of sites, like Gravity Forms, Contact Form 7, The Events Calendar, Elementor, and Slider Revolution — are the most attacked. Not because they’re badly made. Because one hole in a plugin with a million installs is a million doors that open with the same key.
So the plugins you were told to trust are precisely the ones every bot on earth knows how to probe.
Why the treadmill never ends
You can win this week’s race: update everything, today. But plugins are software, and software grows holes. Next week there’s a new version, a new hole, a new race. Every plugin you add is another racer you’re responsible for, forever. That’s not a maintenance task. That’s a part-time job you never applied for.
The way off the treadmill
The honest fix isn’t a better security plugin — a security plugin is another plugin. The fix is removing the thing bots probe.
When Shmove moves your site, the plugins don’t come along — their jobs do. Your forms still work, your events still show, your pages look the same. But the site itself becomes static files: no plugin code running, no login page, no database. A bot that scans it finds nothing to check against any list, because there’s nothing installed.
Your site stops being on the list, because there’s no longer anything to harvest.
Quick answers
Why is my small website getting attacked?
It isn't personal. Bots scan every WordPress site on the internet, around the clock, looking for plugins with known holes. Your site is on the list because every WordPress site is on the list.
How do bots know which plugins I use?
Plugins leave fingerprints in your site's code — file paths, version numbers, script names. A bot reads them in under a second, checks the list of known holes for your exact versions, and moves on or breaks in.
If I keep everything updated, am I safe?
Safer, yes. Safe, no. There's a gap between a hole being discovered and you clicking update — the median exploit now arrives within hours. Staying safe means winning that race every time, forever.
What's the alternative to running plugins at all?
A site with no plugins, no login page, and no database — static files that do the same job. That's what Shmove converts WordPress sites into. There's nothing left to probe.
Sixty seconds. Zero jargon.
See what's actually wrong with your site — speed, plugins, and every way in.
Check my site free