Nobody plans to run a legacy website. A site gets built, it works, attention moves elsewhere — and five years later the business depends on a CMS version that stopped receiving security patches, extended by plugins whose authors moved on.
We’ve inherited and rescued enough of these sites to describe the failure pattern precisely:
The updates stop first. Some plugin isn’t compatible with the next CMS version, so updates get postponed. Postponed becomes never. Every month after that widens the gap between your site and the current, patched world.
Then the site becomes a target — impersonally. Most compromised small-business sites aren’t chosen; they’re found. Automated scanners sweep the internet for known vulnerabilities in old CMS versions, and a hit gets sold or exploited automatically — spam pages injected into your domain, malware served to your visitors, or your server drafted into someone’s botnet.
The damage is reputational before it’s technical. Google flags the site. Customers see warnings. Email from your domain starts landing in spam. The cleanup is a bad week; the trust repair takes longer.
Your realistic options
Maintain it properly. If the site must stay on its platform, someone has to own updates, monitoring, backups, and a firewall — genuinely own them, on a schedule. This is what a real care plan is.
Rebuild on a current platform. Right when the site also needs functional or design changes anyway. The critical discipline is migration: preserving the URLs and content that earn your search traffic, with redirects for anything that moves.
Retire the moving parts entirely. For sites that are primarily informational, a static rebuild is often the best answer nobody mentions: same content, same URLs, dramatically faster — and no CMS, database, or plugin layer to attack. We’ve used this pattern to retire failing Joomla sites, and when one of them later took a DDoS attack, the combination of static architecture and a web application firewall shrugged it off.
The wrong option is the default one: waiting. A legacy site is a liability with a timer you can’t see. If you’re not sure where yours stands, a security and platform audit is a small, fast way to find out — and it’s the first thing we do when a site like this comes to us.
