The ones that cause real problems.
NULLED SOFTWARE
The most common cause of compromised sites we clean. There is no safe source.
NOT UPDATING
The second most common. Automated attacks find known vulnerable versions within days.
LEAVING THE INSTALL DIRECTORY
Allows anyone to re-run the installer.
DEFAULT ADMINISTRATOR CREDENTIALS
Guessed within hours by automated tools.
777 PERMISSIONS
Because documentation said so. It is never the right answer.
ABANDONED INSTALLATIONS
Software installed for a project that ended, still sitting there unpatched.
CONFIGURATION FILES IN PUBLIC DIRECTORIES
Exposing database credentials to anyone who guesses the path.
NOT CONFIGURING CRON
Scheduled tasks silently never run, and the symptoms are confusing.
DEFAULT EMAIL SENDING
Messages disappear into spam and nobody knows why.
NO BACKUPS
Discovered during an emergency.
TOO MANY EXTENSIONS
Slow, fragile, and difficult to update.
INSTALLING WITHOUT CHECKING REQUIREMENTS
Discovering the blocker after a week's work.