WordPress is open source and is free to use. There is no annual licensing to use WordPress itself. Anyone can create plugins that provide additional functionality to a WordPress site or create a theme that defines the look and feel of a site.
Due to its popularity and wide appeal hackers also target WordPress sites. WordPress gets updated very frequently but a site administrator has control over if he/she will update their site. Performance and security are the main reasons WordPress gets updated often. So it is wise to keep your site updated. Make sure your plugins and themes are also updated. Make sure your WordPress site is backed up frequently in case the unsavoury ever happens.
The below infographic from YourEscapeFrom9to5 can provide more tips on how to protect your site from hackers.
Infographic by: yourescapefrom9to5.com