July 24, 2026 · FAQ

Why So Many Lubbock Websites Still Run on WordPress, and Why That's a Real Security Risk

← Back to all posts

This isn't meant to scare anyone, and it's not an exaggeration for effect. It's something we came across directly, and it's a clear, real world example of why WordPress, and especially the plugin-heavy page builders many local agencies still rely on, are becoming a genuine liability for small business websites.

What we actually saw

While looking through websites built by a Lubbock area competitor, we came across a site for a local wedding venue. The homepage loaded fine, a little dated in its design, but nothing unusual. Then we clicked over to the About page, and the site redirected entirely to an Indonesian gambling website. A plugin on the site had been compromised, and malicious actors were using the hijacked pages to redirect visitors somewhere else entirely.

That business now has a website that needs to be completely rebuilt, and in the meantime, anyone who visits certain pages gets sent to a gambling site instead of information about their venue. That's not a hypothetical risk. That's what happens when a plugin gets exploited.

Why this keeps happening on WordPress sites

The root of the problem is how WordPress sites are typically built. Page builder plugins like Divi and Elementor are extremely common among Lubbock web design companies, especially longer established ones that built their process around these tools years ago. We respect that these companies have been in business a long time. The issue isn't experience, it's the underlying technology.

Page builders like these require loading a large amount of extra code on every single page, whether that page actually needs it or not, along with a growing list of additional plugins for contact forms, security, SEO, image optimization, and more. Each one of those plugins is a separate piece of software, usually built and maintained by a completely different company, and each one is a potential entry point for an attacker. The more plugins a site depends on, the more doors there are for something to go wrong, and the less control the site owner actually has over any of them.

What this actually puts at risk

This isn't about something as severe as a data breach involving Social Security numbers or financial information. What's at risk is something just as damaging in a different way: your reputation. When a potential customer visits your website expecting to learn about your business and instead lands on a gambling site from another country, that's the impression they walk away with. For a business like a wedding venue, where trust and first impressions are everything, that kind of incident can undo years of a good reputation in a matter of seconds.

Why custom coded sites don't carry this risk

A custom coded website doesn't rely on a stack of third party plugins that each need their own updates, subscriptions, and security patches. There's no page builder loading unnecessary code across your entire site, and there's no plugin marketplace introducing a new vulnerability every time one of them gets outdated or abandoned by its developer. The code that runs your site is the code that was actually written for your site, nothing more.

The bottom line

We're not sharing this to single out any particular business or agency. We're sharing it because it's a real, current example of exactly what can go wrong on a plugin-dependent WordPress site, and it's happening to real Lubbock businesses right now. If your website runs on WordPress with a page builder like Divi or Elementor, it's worth asking who's actually responsible for keeping every one of those plugins patched and secure, and what happens to your business if one of them isn't.

READY TO BUILD SOMETHING REAL?
Did you know Lubbock Web Design is Texas Tech student owned?