CMS security vs web maintenance: why they aren't the same and what it means for your business

By Kike Gandia · Co-Founder & CEO, OSCP

One of the most common misconceptions in companies with CMS-based websites is treating web maintenance as if it were security. The web agency updates plugins, runs backups and monitors uptime. That isn't security: it's operational management. The difference has real consequences when an incident occurs.

What web maintenance covers

Routine web maintenance of a CMS includes: updating the core and plugins/modules with released patches, periodic backups, availability (uptime) monitoring, SSL certificate renewal and hosting management. These tasks are necessary and reduce the risk of compromise through known vulnerabilities that already have a patch available.

The problem: they address 20% of the real attack vectors. The remaining 80% —insecure code with no published CVE, misconfigurations, vulnerable business logic, exposed APIs— is not detected by updating versions.

What a CMS security audit covers

A CMS security audit analyses how the system behaves under a real attack. It detects:

  • Vulnerabilities in custom plugins or modules with no published CVE (no one has analysed them before)
  • Server misconfigurations that amplify the impact of other vulnerabilities
  • Roles and users with excessive privileges that make escalation easier
  • Exposed APIs and endpoints without proper authentication
  • Web shells or backdoors from previous, undetected compromises
  • Business logic flaws specific to the installation
  • External integrations that introduce additional attack vectors

None of these vulnerabilities appears on a list of "outdated plugins".

The mistake of relying on the web agency alone for security

Web agencies have expertise in development and content management, not in offensive security. They aren't equipped to simulate real attacks, analyse code with an adversarial mindset or identify configuration flaws that require specific security knowledge. This isn't a criticism: it's a different specialism.

The problem arises when the company assumes the web agency manages its security. When an incident occurs, the gap between "we updated all the plugins" and "the website had been compromised for 3 months" is hard to explain to management, clients and regulators.

How to combine web maintenance and security the right way

Web maintenance is the operational foundation: version updates, backups and monitoring. The security audit is the periodic validation that this foundation is effective. They aren't mutually exclusive: they complement each other.

The recommended audit frequency depends on the context: corporate websites with sensitive data, at least once a year; online shops handling payment data, every 6 months or after significant changes; institutional portals subject to the ENS or other regulations, according to the compliance schedule.

FAQ

Can we ask our web agency to carry out the security audit as well?

It depends on whether the agency has a dedicated offensive security team. If the agency uses the same tools it uses for maintenance (security plugins, automated scanners), it isn't a real technical audit. An independent audit by a specialised third party also brings the value of objectivity.

Do we need an audit even if we've never had an incident?

Yes. The absence of detected incidents does not mean the absence of compromise. Many CMS compromises go unnoticed for months: the attacker keeps persistent access without interrupting the service. An audit detects active compromises as well as potential vulnerabilities.

Related service

CMS pentesting service

Related content

Sources

Request a CMS security audit