codexier.

Maintenance & Security

Running an Old Website: The Risks You Can't See

By CodexierPublished 5 min read

A website built five or six years ago and left alone still loads, still shows the phone number and still looks roughly like the company. Its owner reasonably concludes it is fine. Underneath, the software it runs on has stopped receiving fixes, the rules around cookies and accessibility have moved, and search engines have quietly started preferring faster sites. This guide explains the risks that grow without symptoms, and how to decide between fixing and replacing.

Unsupported software and versions

Every website stands on layers that have a support lifetime: the server's operating system, the language runtime such as PHP, the CMS core, the theme and each plugin. When a layer passes its end of life, its maintainers stop publishing fixes, but the vulnerabilities found afterwards are still published. An old site therefore becomes more exposed every month it stands still, without changing at all. Our note on outdated PHP versions covers the most common case.

Security gaps that grow

Attacks on small sites are automated: scanners look for known plugin versions and exploit them in bulk. The result is rarely a dramatic defacement. It is a hidden spam page, a redirect for some visitors, a mail relay, or malware that gets the domain flagged in browsers and search results.

What happensHow you noticeWhat it costs
Injected spam pagesSearch results for your domain show pharmacy or casino pagesRankings, trust, a clean-up
Malicious redirectsCustomers report being sent elsewhere, often only on mobileLost enquiries, browser warnings
Mail abuseYour domain lands in spam; deliverability collapsesInvoices and quotes not arriving
Data exposureA contact form database or backup is readableA GDPR breach with notification duties

If the site collects any personal data at all, even a contact form, a compromise is a personal data breach that may need reporting to IMY within 72 hours.

Compliance: cookies, accessibility, GDPR

Rules have moved since most old sites were built, and a site does not update itself.

  • Cookie consent: analytics and marketing scripts need real consent before they load, and old banners that only inform do not meet that.
  • Privacy notice: it must name the actual processors and purposes; old notices often describe a site that no longer exists.
  • Accessibility: expectations have risen and, for some organisations, become legal requirements. Old themes commonly fail contrast and keyboard navigation.
  • Company information: organisation number, VAT status and contact details must be present and correct, and old footers are where they go stale.

Speed and search decline

Speed on mobile

Old themes load everything on every page. Search engines now measure real user loading times, and slow sites lose position to faster ones for the same query.

Content that dated

Prices, staff, services and opening hours that were true at launch. Each stale fact is a small trust loss for a visitor and a small relevance loss for search.

Structure that search moved past

Missing structured data, no proper page titles, images without descriptions. Competitors' newer sites have these by default.

Deciding: fix or replace

The decision is technical first and aesthetic second. Answer these in order:

  1. Is the platform still supported and upgradeable? If the CMS or PHP version cannot be updated without breaking the theme, replacing is usually cheaper than a rescue.
  2. Is the content still right? If the services and message hold, a fix keeps them; if the company has changed, a rebuild is the moment to say so.
  3. Are there working backups and access to hosting, domain and CMS? Without them, even a fix starts with recovering control.
  4. What does the site have to do next year? A new booking flow or a shop is easier on a fresh platform than bolted onto an old one.

A website health audit answers the first three questions in writing, with a list of what to fix and a recommendation, at a fixed price. If the answer is fix, a monthly maintenance package keeps it from drifting again; both are on the pricing page.

When you can leave it alone

A static site with no forms, no logins and no plugins, on a host that keeps the server patched, carries little risk and can run for years with a yearly content check. If your site is that simple, do not buy an audit; check the footer, the phone number and the privacy text yourself. The risks above belong to sites running a CMS with plugins, collecting data or handling bookings. If you are not sure which yours is, a 15-minute call with the site open is enough to tell.

Frequently asked questions

How old is too old for a website?

Age is not the measure; support is. A three-year-old site on an unmaintained plugin stack is riskier than a ten-year-old static site. Check whether the CMS, PHP version and plugins are current and still receiving updates. If any of them are not, the site is too old regardless of the calendar.

Can an old website be hacked if it has no login?

Yes. Attacks target the software the site runs on, not the login page. A vulnerable plugin, an old PHP version or an exposed admin path is enough. No login area reduces the value of a compromise, not the chance of one.

Does a rebuild hurt our search rankings?

Only if it is done carelessly: changed addresses without redirects, dropped pages, slower templates. A rebuild that keeps the page structure, redirects every old address and improves speed usually gains position within a few months.

Not sure whether your site is a fix or a replace?

Bring the site address and whatever access you have to a short call. We tell you which platform layers are out of support, whether a rescue is realistic, and what a fixed-price audit or rebuild would cost.

Book a free 15-minute call