How much of the live web runs outdated, publicly-vulnerable plugins & themes — CVE-anchored, aggregate, never naming a site.
Source: Piperic index of live websites · vulnerability data from Wordfence Intelligence (37,804 CVEs) · updated 2026-07-24
The State of WordPress Security on the Open Web is Piperic's free study of software update hygiene across the live web. We read the homepage of live WordPress sites, detect the plugin and theme versions they load, and cross-reference those versions against the Wordfence Intelligence vulnerability database. The result is an honest, CVE-anchored picture of how much of the web runs outdated, publicly-vulnerable components — reported only in aggregate, never naming a single site. It measures patch hygiene, not exploitability: running a version for which a vulnerability has been disclosed is a maintenance signal, not proof a site can be hacked.
Share of measured WordPress sites running each plugin/theme in a version with a known vulnerability.
Among sites that run each of these widely-used plugins & themes, the share on a version with a known vulnerability. Ordered by popularity — note how some stay current while page-builders & sliders lag.
Of sites running a vulnerable component, the worst-case severity (CVSS) present.
Share of measured WordPress sites with a known-vulnerable component, by industry (min. 500 sites each).
Share of measured WordPress sites running a known-vulnerable component, by country (min. 300 sites each). Per-country reports are coming next.
Least up-to-date
Most up-to-date
About 57.6% of measured WordPress sites (those where we could read a plugin or theme version from the homepage) run at least one plugin or theme in a version with a publicly known vulnerability. Around 6.3% run one rated critical (CVSS 9.0+).
Premium page-builder and slider plugins bundled into themes are the most likely, because they are rarely updated. We never name individual sites — only aggregate rates.
No. We measure update hygiene — running a version for which a vulnerability has been publicly disclosed. Whether a site is actually exploitable depends on configuration and whether a fix has been back-ported. This is a patch-hygiene study, not an exploitation claim.
We read each site's homepage across Piperic's index of live websites and detect plugin/theme versions from the assets they load, then cross-reference those versions against the Wordfence Intelligence vulnerability database (CVE-anchored). All figures are aggregate; no individual site is ever identified.
Methodology: plugin/theme versions are read from the homepage assets of live, content-validated WordPress sites (HTTP 2xx, not parked) across Piperic's index, then cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). "Measured" sites are those where at least one component version was readable (74% of WordPress sites seen); homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate — no individual site is identified. Based on a 150-of-7,022 sample of the recrawl cohort. Vulnerability data © Wordfence Intelligence, MITRE where applicable.