The patch window is now five hours

Monthly website maintenance was designed around an assumption that is no longer true: that there is a comfortable gap between a vulnerability becoming public and somebody using it against you.

That gap used to be measured in weeks. On the evidence of the last two years, for the components most websites are built from, it is now measured in hours.

This is not a reason to panic. It is a reason to look at what your maintenance arrangement actually promises, because a great deal of it was priced and scoped for a slower internet.

What changed

Three findings, from three independent directions, all point the same way.

Exploiting known vulnerabilities is now the leading way in. The 2026 Verizon Data Breach Investigations Report, drawing on more than twenty-two thousand breaches, puts vulnerability exploitation at 31 percent of initial access, up from 20 percent, a rise of roughly 55 percent year over year. It has overtaken the routes most security awareness training is built around. Verizon own framing is that AI is accelerating the time to exploit known vulnerabilities, shrinking the window from months to mere hours.

The window has closed almost entirely for CMS components. Patchstack State of WordPress Security for 2026 recorded 11,334 new WordPress vulnerabilities disclosed during 2025, a 42 percent increase, with 91 percent of them in plugins rather than core. The number that matters most is the weighted median time from disclosure to mass exploitation: about five hours. Roughly half of high-impact vulnerabilities were exploited within twenty-four hours. And 46 percent had no fix available at the moment they were disclosed.

Automation is doing the finding as well as the exploiting. In June 2025 an autonomous system reached the top of the HackerOne United States leaderboard, filing over a thousand reports including fifty-four rated critical. Google Big Sleep agent has been credited with finding twenty or more real vulnerabilities in open-source software. In November 2025 Anthropic documented an intrusion campaign it assessed as 80 to 90 percent executed by AI, running thousands of requests, sometimes several per second.

Put those together and the shape is clear. More vulnerabilities are being found, more of them are being found by machines, and the interval between this is public and this is being exploited at scale has compressed to less than a working day.

What this does to a monthly maintenance plan

Take the arithmetic at face value.

If updates are applied on a monthly cycle, the average exposure to any given plugin vulnerability is about fifteen days. Against a median time-to-exploitation of five hours, that is not a small margin of error. It is roughly seventy times the window.

Weekly is better and still not close. The honest conclusion is that scheduled patching, of any cadence a human would choose, no longer matches the threat it was designed for. What matters is not how often someone looks, but how quickly something is applied once a fix exists, and what protects the site during the 46 percent of cases where no fix exists yet.

This is the part most care plans quietly do not cover. Monthly updates is a real service and a useful one. It is not the same service as continuous monitoring, and the two are often sold at similar prices under similar names.

The AI framing, stated honestly

There is a lot of marketing at the moment about rogue AI agents attacking small business websites. It is worth being precise, because the exaggerated version is doing the honest version a disservice.

What the evidence supports: automation has collapsed the time from disclosure to exploitation; AI is measurably being used to discover vulnerabilities and, in at least one documented case, to execute most of an intrusion campaign; and AI crawlers now generate substantial uncontrolled load on ordinary websites, with crawl-to-referral ratios reported in the thousands to one.

What the evidence does not support: a present-tense wave of autonomous AI agents independently selecting and compromising small business websites. That is not what is happening, and claiming it invites a reasonable person to discount the rest.

The real argument does not need the embellishment. Mass exploitation of a known plugin flaw within five hours of disclosure is enough. It is already faster than any maintenance schedule a human being would design.

What to actually ask your provider

Five questions, and the answers are usually short.

How quickly are security updates applied after release? If the answer is a cycle rather than a trigger, you have a schedule, not a response.

What happens when there is no fix yet? Nearly half of disclosed vulnerabilities have no patch on day one. Virtual patching at the firewall layer is the mechanism that covers that gap. Ask whether it exists.

Who is watching between updates? Malware scanning, file integrity monitoring, login hardening and uptime checks are what turn a maintenance plan into a monitoring plan.

What happens if something does get through? This is the question that separates a care plan from a partner. Most contracts end at restore the most recent backup, which puts the site back and puts the vulnerability back with it.

What do we get afterwards? If the answer is a clean site and no explanation, you will not know what happened, you will not be able to prove anything to an insurer, and you have no reason to believe it will not happen again.

Two things you can do today, free

Reduce the plugin count. Ninety-one percent of disclosed WordPress vulnerabilities are in plugins, so surface area is a function of how many you run. Every plugin you remove is a vulnerability you never have to patch.

Find out whether anything is currently unpatched and unfixable. If a component on your site has a known vulnerability and no available fix, that is not a maintenance item to raise next month. It is today problem.

Where we sit

We manage and host websites with continuous monitoring rather than scheduled maintenance windows, across WordPress, WooCommerce, Adobe Commerce, BigCommerce, Shopify and custom builds, and when something does get through we investigate it, write up what happened, and tell you what to change. Monthly plans, no minimum term.

If you are dealing with a compromise right now, start with the first-hour checklist rather than with us.