Your website is not a purchase. It is a decay curve.
Around 36 new vulnerabilities are disclosed against common website software every day, and exploitation typically begins within five hours. That single fact is the honest answer to why a website plan is monthly, and it is the one most providers never give.

A website is not a thing you buy once. It is a thing that decays. Around 36 new vulnerabilities are disclosed against common website software every day, and exploitation of a critical one typically begins within about five hours. The build takes a week. Keeping it safe takes every week after that.
That single fact is the honest answer to the question every small business asks about monthly website plans: why am I still paying?

The building looks fine
Nothing about a compromised website looks wrong from the outside. The homepage loads. The phone number is right. The photos are the ones you chose. The failure is structural and it is invisible, which is precisely why it goes unnoticed until something expensive happens.
Here is what the numbers say about the software most small business sites are built on.
| Share of WordPress vulnerabilities that live in plugins | around 91% |
| New plugin vulnerabilities disclosed | roughly 36 a day, 250 a week |
| New vulnerabilities across the ecosystem in 2025 | over 11,000, up about 42% year on year |
| Compromised sites found running outdated software | over 90% |
| Typical time from public disclosure to exploitation | about five hours |
Sources: Swif, WebHostMost, DEV Community. These are secondary aggregators rather than primary research, and we cite them as such. They agree with each other and with what anyone running sites at scale sees.
Read the last two rows together, because that is the whole problem. A flaw becomes public. Automated scanning for it starts the same afternoon. And over ninety percent of the sites that get taken were running something the owner did not know needed updating.

The lock is still on the door
This is the part that gets misunderstood. Nobody removed your security. The plugin that handles your contact form is still installed. The booking system still works. The lock is still bolted to the door, it simply stopped engaging, and there is no way to tell from the street.
An unpatched website is not an asset. It is a liability with your name on it.
What actually happens
Not theory. This is the sequence, roughly in the order it hurts.
Your traffic stops, not slowly. When Google's Safe Browsing detects malicious content, visitors get a full-page red warning instead of your site. Chrome, Firefox and Safari all honour it. There is no gradual decline to notice and react to. You go from normal to nothing.
Your rankings take months to recover. Compromises usually inject spam content or hidden links pointing somewhere else. By the time it is cleaned up, that content has been crawled and indexed. Removing the malware is a day. Recovering the rankings is a quarter, sometimes more.
Your email starts bouncing. If your domain is used to send spam, it lands on blocklists. Suddenly your quotes and appointment confirmations are going to junk, and you will not find out from a bounce message. You will find out from a customer who says they never heard back.
Your customers find out before you do. Defacements and injected redirects are usually spotted by a visitor, not the owner. The first you hear is a phone call asking why your website is sending people to a gambling site.
If you handle personal data, it is a different problem entirely
Everything above is commercial damage. For a clinic, a dental practice, an accountant, a solicitor or anyone holding customer records, a compromise is a legal event.

If personal data was accessible, you may have a notifiable breach. Under UK GDPR that means assessing it and, where there is a risk to people, telling the Information Commissioner's Office within 72 hours. Not 72 working hours. Three days, including the weekend, starting from when you became aware.
Then consider what your website actually holds. A new patient enquiry form. A booking system with names, dates of birth and phone numbers. A contact form where someone described their symptoms because the field said "how can we help?". That is health data, and health data is a special category under UK GDPR with a higher bar.
Now the question worth sitting with: if that happened next Tuesday, who would you call?
If the answer is a support inbox at a provider who has never mentioned data protection to you, has no Data Processing Agreement, and cannot tell you which country your data is held in, then you are the one who will be answering the ICO's questions. Not them.
When we surveyed twelve UK pay monthly website providers in July 2026, three mentioned a Data Processing Agreement anywhere on their public site. Three of twelve.
What a monthly plan is actually for
Strip away the marketing and a monthly website plan is buying you exactly one thing that a one-off build cannot: somebody whose job it is to notice.
Concretely, on our plans that means the components your site depends on are patched and redeployed, the security headers are maintained rather than set once and forgotten, hosting and TLS are managed, backups are taken and tested, and the site is built without plugins or a public CMS admin panel, which removes most of the attack surface before we start.
That last point is architecture, not marketing. Most of the risk in the table above lives in third-party plugins. A site that does not have plugins does not inherit their vulnerabilities.
When you do not need this
We would rather say this plainly than have you work it out later and feel sold to.
If your website is a single page with your opening hours and a phone number, it takes no personal data, has no forms, no booking, no login, and you genuinely will not touch it for years, then a monthly plan is poor value. Buy a site once, keep it simple, and put the money somewhere it works harder. The decay curve is real but it is much flatter when there is nothing to exploit.
The plan earns its keep when your site does something: takes enquiries, holds data, integrates with a booking tool, or represents a business that would suffer if it went dark for a week.
Our own record, since it would be hypocritical to hide it
In July 2026 we ran a full audit against this site, the one you are reading. It found our own framework was five patch releases behind, carrying nine high-severity advisories. Our Content Security Policy was in report-only mode, meaning it was reporting problems and blocking nothing. And our security page displayed a hardcoded score of 98 with the words "Grade A+" next to it, on a page selling security, having measured precisely nothing.
We fixed all three the same day. The dependencies are current and the advisory count is zero. The invented score is gone and now counts the controls we actually apply. The page no longer claims a nonce-based policy we had not deployed.
We are telling you this because it is the point. Decay is not something that happens to careless people. It happened to a site run by a certified security auditor, in the space of a few months, without anyone doing anything wrong. It happens because software moves and sites do not.
The only defence is somebody looking, on a schedule, forever.
The ten-minute version
Ask whoever runs your website today: when did you last update the software this site runs on, will you sign a Data Processing Agreement, and what happens if it is compromised on a Friday night?
You are entitled to three straight answers. If you do not get them, you have learned something useful for the price of one email.
Put this to work