FIELD NOTES • WEB + SEARCH
Most business owners never look at the Users section of WordPress.
There usually is not much reason to. The website loads. Contact forms work. Pages look normal. Nothing on the front of the site suggests there is a problem.
That is what made one routine security review interesting.
I found two WordPress administrator accounts that nobody responsible for the website recognized.
They had full administrator privileges.
The public website still looked normal.
That experience is one reason I treat WordPress maintenance as more than installing updates.
I maintain WordPress websites for small businesses across Kansas. Some of the most important problems I find are not broken pages or obvious errors. They are things happening behind the website that a customer would never see.
If you open Users → All Users in WordPress and see an administrator you cannot identify, take it seriously.
Administrator access is powerful.
An administrator may be able to install plugins, change settings, create additional users, edit content, and make other changes throughout the website.
That does not mean every unfamiliar account is malicious. Old developers, former employees, hosting support accounts, and forgotten vendors can sometimes explain an unfamiliar user.
But an administrator account nobody can explain needs to be investigated.
That is what happened here.
There were two.
This is one of the most useful lessons from the incident.
There was no hacked home page.
Customers were not being greeted by a warning message.
The business had not disappeared from Google.
The site was still doing its normal job.
Yet two unauthorized administrator accounts were sitting inside WordPress.
A review of the available logs later showed that suspicious activity had started before the unauthorized accounts were discovered. The public website had continued to operate normally during that period, which is exactly why routine back-end review matters.
Waiting for a website to visibly break is not a security plan.
Sometimes the first meaningful sign is simply something that should not be there.
Keeping WordPress, plugins, and themes current matters.
When developers release a security fix, leaving the vulnerable version running can keep a known opening available longer than necessary.
But good website maintenance cannot stop at the Update button.
New vulnerabilities are discovered. Plugins change. Attack methods change. User accounts change. A website that was healthy during the last review can develop a problem later.
That is why I think of WordPress maintenance as a process.
Updates are one part of it.
So are reviewing administrator access, checking security warnings, looking at unusual activity, removing software that is no longer needed, and investigating something that does not make sense.
The goal is not to pretend a WordPress website can never be attacked.
The goal is to reduce the opportunity for an attack and catch problems before they have unlimited time to grow.
Deleting the two unauthorized users would have been the fastest response.
It would not have been enough.
The real question was how they got there and whether anything else had changed.
The investigation went deeper into the WordPress installation and available server information. Suspicious activity was reviewed. Additional unauthorized changes were found and removed.
Affected plugins were reviewed and updated or removed where necessary.
WordPress credentials were changed.
Database and hosting credentials were rotated.
WordPress security keys were changed so existing sessions could no longer simply remain trusted.
File permissions were tightened.
Additional login protection was put in place.
The hosting provider was also involved in reviewing the surrounding server environment.
That broader review mattered because a WordPress problem and a server-wide compromise are not automatically the same thing.
Later security scans across the hosting environment did not show an ongoing server-wide malware problem. Those checks helped narrow what had and had not happened.
That is a much better position than simply deleting two users and hoping the problem is over.
Security scanners are useful. I use them.
They are not substitutes for looking at the website itself.
One lesson from this incident was that an unauthorized administrator is itself evidence worth investigating, even when a malware scan is not lighting up the dashboard.
A security tool can look for suspicious files, known malware patterns, vulnerable software, and other warning signs.
A human can ask a different question:
Who is this person, and why do they have administrator access?
That is a very simple question.
It can also uncover a problem that is easy to miss when the website appears healthy.
This is why routine website maintenance should include more than checking whether WordPress says everything is up to date.
Backups do not prevent someone from attacking a website.
They solve a different problem.
They give you a recovery option when prevention and cleanup are not enough.
In this incident, the website did not ultimately need to be rolled back from a backup. After the unauthorized access and related changes were removed, a fresh clean backup was created as part of returning the website to a known working state.
But the experience reinforces why backups matter.
Suppose an attacker modifies important website files.
Suppose database content is damaged.
Suppose malicious changes are discovered after they have spread far enough that manually identifying every change is no longer practical.
At that point, having a usable backup from a known point in time can become much more important than having another security plugin.
A backup is not a security shield.
It is a recovery plan.
I consider both necessary.
Start by documenting what you found.
Record the username, email address, role, and anything else available before changing it.
Then determine whether there is a legitimate explanation for the account.
If nobody responsible for the website recognizes it, treat the situation as a possible compromise rather than simply an unwanted user.
Removing the account may be necessary, but the investigation should not end there.
Review the plugins and themes.
Check whether anything was recently installed or changed.
Review security warnings and available logs.
Look for other administrator accounts.
Review tools capable of adding custom code or scripts.
Change credentials that may have been exposed.
Make sure your backup system is actually working.
The important question is not only:
How do I delete this user?
It is:
What allowed this user to exist, and what else happened while that access was available?
Those are very different questions.
There is no single schedule that fits every website.
A small brochure site and an active ecommerce site do not have the same risk, traffic, software, or business impact.
But “only when something breaks” is not a maintenance schedule.
Website maintenance should happen regularly enough that outdated software, unexplained accounts, backup failures, and security warnings do not get years to sit unnoticed.
This matters especially for an established small business.
The website may contain years of content, search visibility, customer inquiries, service information, photos, and work that would be expensive to reconstruct.
Keeping that asset healthy is part of running it.
I provide WordPress support and ongoing website maintenance for small businesses across Kansas.
That work can include updates, technical troubleshooting, security review, content changes, backups, service-page development, and the less glamorous checks that keep a website useful after it has been launched.
For Kansas businesses, that is part of a larger approach to web design, local SEO, and long-term website support.
Getting a website found is only part of the job.
The website also has to remain functional, recoverable, and worth sending customers to.
If you find an administrator account you do not recognize, a plugin you cannot explain, or unusual behavior inside WordPress, do not start randomly deleting things.
Document what you see first.
Then figure out what changed and why.
Sometimes the most important thing on a website is the thing your customers will never see.
There can be legitimate explanations, such as an old developer or former vendor account. If nobody responsible for the website recognizes the administrator, however, it should be investigated as possible unauthorized access.
Document the account first. Removing unauthorized access is important, but deleting the user alone does not tell you how the account was created or whether anything else on the website was changed.
Yes. Unauthorized access does not always produce an obvious change on the public website. An attacker may create an account or make back-end changes while the site continues to appear normal.
No. Keeping WordPress, plugins, and themes current is an important security practice, but it is not a guarantee that a website cannot be attacked. Ongoing maintenance should also include access review, backups, security monitoring, and investigation of unusual activity.
Backups do not stop an attack. They provide a recovery option if files, database content, or other parts of the website become damaged or cannot be trusted after a compromise.
Yes. I provide WordPress support, website maintenance, web design, local SEO, and related technical work for small businesses across Kansas. Clients work directly with me rather than through an account manager or agency support queue.