The 15-Minute Shopfront Check
By The Most Secure Man Alive | WISECLICK Ambassador
Criminals rarely break into small business websites to rob the owner. They break in to borrow the shopfront — your good name, your green padlock, your customers' trust — and quietly put it to work for them.
The Australian Signals Directorate published an alert in May about exactly this: legitimate Australian business websites, compromised through out-of-date plugins, serving fake "verify you are human" boxes to their own visitors. The owners never clicked anything. They simply never looked.
So here is the looking, made simple. Fifteen minutes, once a month. No email address, no catch — take it, use it, send it to a mate with a website and a busy life. If you'd like the full story of how the borrowing works, it's told in the Dispatch.
Before you start
This routine is written for WordPress, because roughly four in ten websites on earth run on it and nearly every break-in of this kind comes through a plugin nobody updated. If your site lives on Shopify, Squarespace or Wix, the platform patches itself — skip to steps 4 and 5, which apply to everyone.
You'll need your website's admin login and fifteen minutes. Put the kettle on.
The check
1. Walk the shelves — 3 minutes
Log in to WordPress and open Plugins, then Appearance → Themes. Read the list slowly.
You might expect me to tell you how to spot a fake plugin. I can't, and neither can anyone else — criminals name theirs things like "Advanced User Manager", and perfectly real plugins have names just like it. Happily, you don't need to. Their plugin was never how they got in. It's what they left behind once they were inside.
So the question is never "is this one real?" The question is "did I put it there?"
Anything you don't remember installing, and your web person didn't either, doesn't belong. Deactivate it, delete it, and treat the finding seriously — see the calm procedure at the bottom.
2. Turn the updates on — 2 minutes
On the Plugins page, tick everything and choose Enable auto-updates. Then Dashboard → Updates and let WordPress itself update too. The single most common way in is a known flaw with a fix already published that nobody applied. Auto-updates apply it while you sleep.
3. Delete, don't deactivate — 2 minutes
A deactivated plugin is still code sitting on your site, still carrying its flaws. If you're not using it, it isn't a spare — it's an unlocked window in a room you never enter. Delete it. You can always reinstall in two clicks if you miss it, and you won't.
4. Count the keys — 3 minutes
Open Users (or your platform's staff accounts page). Every administrator listed should be a face you can picture. Old web developers, former staff, accounts named "admin" or "test" — remove them or demote them. Then turn on two-step login for everyone who remains. A stolen password is the other common way in, and two-step login turns a stolen password into a blank key.
5. The stranger check — 3 minutes
Open a private browsing window — better still, use your phone on mobile data — and visit your own website the way a customer does. Click through the home page, a product or booking page, your contact page.
You're looking for anything you didn't put there: boxes asking visitors to "verify" themselves, unexpected pop-ups, redirects to pages that aren't yours. And keep the one line that protects everyone, on every website, always:
A real check never leaves the browser. Any "verification" that tells a visitor to press keyboard shortcuts, open a window, paste or run something — that's not a check. That's the borrowed-shopfront trick, running on your site.
6. The outside opinion — 2 minutes
Some of what criminals leave behind hides from your own plugin list entirely. So finish with a scanner that looks from the outside: Sucuri SiteCheck is free and takes your web address, nothing more. Eyeball what you can see; scan for what you can't. A clean result on both is a genuinely good answer.
If you found something
No hurry, and no shame — the owners in the ASD's alert were busy people, not careless ones. In order:
- Change the passwords from a different device — your WordPress admin and your hosting account, both. Long, unique, new.
- Ring your hosting company. Tell them you believe the site is compromised. Cleaning infected sites is routine work for them, and most offer it as a service.
- Restore from a backup taken before the strange plugin appeared, if your host keeps them. Then run steps 1–6 again on the restored site.
- Report it through ReportCyber at cyber.gov.au. It takes minutes and it genuinely helps the next business.
Your customers met that fake box trusting your name. Finding it first is you earning that trust back before anyone knew it was borrowed.
The honest limit
This routine protects your customers from your website. It does nothing for the machine you actually run the business on — the laptop holding your email, your banking, your client files. That machine is what the borrowed shopfronts are ultimately aimed at, and it needs its own answer.
Knowing where that machine actually stands is a different fifteen minutes:
The Ransomware Readiness Check → 30 minutes. Plain English. $149.
Otherwise: calendar reminder, first Monday of the month, fifteen minutes, this page. That's the whole discipline.
Stay protected, my friends.
— The Most Secure Man Alive
Frequently asked questions
How often should I run this check?
Monthly. The break-ins this routine catches build slowly — a plugin left unpatched, a strange addition sitting quietly. A monthly fifteen minutes finds it before your customers do.
My site is on Shopify, Squarespace or Wix. Do I still need this?
A shorter version. Those platforms patch themselves, so the plugin steps mostly don't apply. Steps 4 and 5 absolutely do: check who holds admin access with two-step login on, and walk your own site as a stranger monthly. On Shopify, also review your installed apps the way WordPress owners review plugins — same question: "did I put it there?"
How do I tell a fake plugin from a real one?
You can't, by name, and you don't need to. The criminals' plugin isn't how they got in — it's what they left behind. The only question that matters is whether you put it there. Unrecognised means unwanted.
What's the catch with this page?
There isn't one. No email address, no sign-up, nothing tracked beyond ordinary website statistics. Send it to anyone. We publish it because fewer borrowed shopfronts is good for every business in the country, including ours.
Get the next Dispatch delivered to your inbox
Who We Are
Cybersecurity for small business, run by people who've run one.
We're a small, founder-led Australian team. Over 22 years we've helped thousands of small businesses put a realistic security baseline in place, so owners can get back to work with genuine peace of mind. Small enough that you're a name to us, not a ticket number. We don't rely on our opinion of what's safe. We build to the government's - the Essential Eight, the baseline set by the Australian Cyber Security Centre. We take the protection you already half-rely on and make it real, set up properly, kept current, and there on the day something goes wrong.
You won't catch us chasing a crowd. In this line of work, quiet is the whole point. You get on with the work. We make sure it's still there tomorrow.
The simplest place to start is knowing where you stand. The Ransomware Readiness Check is thirty minutes, plain English, and nothing to install.
Take the Ransomware Readiness Check →