However, a website is not a static thing sitting untouched on the internet. It’s built from layers of software, a content management system, a theme, a collection of plugins, all sitting on a hosting server that is also running its own software. Every one of those layers gets updated, patched, or retired on its own schedule, and none of them wait for permission from the website owner. When enough of those changes stack up, something eventually gives.
Every piece of software behind a website, the platform itself, the coding language it runs on, the plugins that add features, has a shelf life. Developers release new versions, phase out old ones, and eventually stop supporting the older versions altogether. A website built a few years ago and never updated since is quietly running on software that its own developers have moved on from.
A good example is PHP, the coding language that powers WordPress and a large share of the web. PHP goes through major version releases, and each new version quietly removes or changes functions that used to work perfectly well in older versions. A plugin or theme written for an older version of PHP might call on a function that has since been deprecated, meaning it no longer exists or behaves differently. The website doesn’t complain about this while everything stays still, but the moment the environment underneath it changes, that old code has nowhere left to stand.
This is really the root cause behind most of the other ways a website can break. Obsolete software doesn’t announce itself, it just sits there working until something else forces the issue. That something is usually one of a handful of triggers, and hosting providers pulling support for an old version is one of the most common.
Obsolete software can sit quietly for years without causing a problem, which is exactly what makes a forced hosting upgrade such a common trigger. Website owners often assume their hosting is a “set and forget” arrangement, but hosting providers are constantly maintaining their own infrastructure in the background. Security patches, server software updates, and version upgrades happen regularly, and reputable hosts don’t leave old, vulnerable server software running indefinitely just because a customer’s website depends on it.
This is most visible with PHP version upgrades. Hosting providers will periodically retire support for older PHP versions across their servers, sometimes with a notice period and sometimes as part of a broader security push. PHP 7.4 is a good real-world example, it reached official end of life in November 2022, and hosts have been progressively moving customers off it ever since. When that kind of upgrade happens, any website still relying on outdated PHP functions or an old, unmaintained plugin suddenly has the ground shift underneath it. The same thing can happen with database software, where a forced upgrade exposes compatibility issues that had been sitting dormant for years.
None of this is the hosting provider being careless. Running outdated, unpatched server software is a genuine security risk, so providers have good reason to move everyone forward. The problem is that a website which hasn’t been kept in step with these changes is the one left exposed when the upgrade finally lands.
A hosting-forced upgrade is one way old software gets exposed, but it isn’t the only one. A WordPress website is really a combination of several independent pieces working together, the core platform, a theme controlling how it looks, and a handful of plugins adding specific functionality. Each of these is built and maintained separately, often by entirely different developers, and each one gets updated on its own timeline.
Most of the time this works fine, but every so often a WordPress core update changes something a theme or plugin was relying on, or one plugin update changes something another plugin depends on. A common version of this is a caching plugin and a security plugin, both perfectly well behaved on their own, suddenly clashing after one of them updates and starts fighting the other for control over the same part of the website. When that happens, the website can display a blank white page, show a layout that has completely fallen apart, or lose a feature that worked perfectly the day before. It often looks alarming, but it usually comes down to two pieces of software that used to agree with each other suddenly not agreeing anymore.
This kind of breakage tends to happen invisibly until someone actually loads the site, which is exactly why nobody sees it coming. There’s no warning light on a website telling the owner that two of its components have quietly stopped getting along. The first anyone knows about it is usually when a customer mentions the site looks broken, or a staff member goes to update something and finds half the page missing.
Sometimes the problem isn’t incompatibility, it’s that the developer behind a theme or plugin has simply stopped maintaining it. This happens more often than people realise. A developer moves on to other projects, a small plugin never gets the support it needs, or a theme is quietly discontinued in favour of something newer.
An abandoned theme or plugin doesn’t cause any problems on the day it’s abandoned. It just stops receiving the updates that would normally keep it working alongside everything else. A common pattern is a small plugin installed years ago for one specific job, a booking calendar or a contact form add-on, that quietly stopped getting updates once its developer moved on, with nobody at the business any the wiser until it finally breaks. From that point on, it’s only a matter of time before a WordPress update, a PHP upgrade, or another plugin change finally breaks it, because there’s nobody left maintaining that piece of the puzzle. There’s no way to know in advance when that day will arrive, only that it eventually will.
Not every broken website is simply inconvenient. Outdated, unpatched software is one of the most common ways a website ends up compromised, because old plugins and themes with known vulnerabilities are exactly what attackers look for. Security research on hacked websites consistently points to out-of-date plugins as the leading way attackers get in, well ahead of weak passwords or anything on the hosting side. What looks like a website “breaking” can sometimes actually be a website that has been hacked, with malicious code injected or content altered without the owner realising straight away.
This is worth calling out on its own because the two situations can look identical to a business owner. A defaced page, a site that suddenly redirects somewhere strange, or a form that stops working properly could be an innocent compatibility issue, or it could be a sign that outdated software has been used as a way in. Either way, the underlying cause is the same, software that hasn’t been kept current is a growing liability the longer it’s left alone.
All of this comes back to the same root issue. A website sits on layers of software that keep moving, even when nobody is actively touching the site itself. WordPress updates, PHP versions change, hosting providers patch their servers, and individual plugin and theme developers come and go. None of that stops just because a business owner hasn’t logged into their website admin in over a year.
The businesses that avoid these problems aren’t the ones with newer websites, they’re the ones with someone actually keeping an eye on all these moving parts. A website that’s actively maintained gets its updates applied in a controlled way, gets tested when something changes, and gets caught before a forced hosting upgrade turns into a broken site on a Monday morning.
The Bottom Line: A website isn’t a one-off purchase, it’s an ongoing arrangement between several pieces of software that all keep changing. Left unattended, it’s not a question of if something breaks, but when.
We manage hosting and maintenance for hundreds of websites, which means we’re watching for exactly these kinds of issues. It’s the sort of thing that’s easy to overlook when everything’s running smoothly, and much harder to catch up on once it isn’t.
If your website has broken unexpectedly, or you’d simply rather not find out the hard way, get in touch with us.
Google reviews build trust, but that trust does not always follow a visitor onto your…
A single well-chosen photo can do more for your business online than a page of…
Not sure if your website is actually working for your business? You're not alone. Here's…
More content doesn't always mean better rankings. Find out why publishing less and focusing on…
AI tools are impressive, but AI-generated code dropped into a live website without a professional…
A new web standard called WebMCP is changing how AI agents interact with websites. Most…