Piperic
Security Report
PricingToplistsBrowse free →
🛡️ The WordPress Security Report · July 2026

🇮🇪 60.7% of Ireland's WordPress sites run a known-vulnerable component

Of 506 Ireland WordPress sites where we could read a component version, 307 (60.7%) run at least one plugin or theme in a version with a publicly known vulnerability. This measures patch hygiene — not that a site is exploitable.

Analysis of live, content-validated websites · vulnerability data from Wordfence Intelligence · snapshot 2026-07-25 · by Piperic

Share:XLinkedIn

60.7%
run a known-vulnerable component
5.7%
run a critical (CVSS 9+) flaw
#20
safest-web rank
of 37 countries (lower = more up-to-date)

Where Ireland stands in the world

Share of measured WordPress sites running a known-vulnerable component — lower = more up-to-date. Ireland ranks #20 of 37 countries.

🇻🇳 Vietnam83.2%🇮🇱 Israel75.8%🇧🇷 Brazil72.0%🇬🇷 Greece71.5%🇸🇰 Slovakia70.7%🇨🇱 Chile69.2%🇷🇴 Romania68.6%🇦🇷 Argentina67.5%🇮🇪 Ireland60.7%

Neighbours shown for context. Full ranking in the data download.

How Ireland compares to the world

Ireland's WordPress web measured against the global average — and its exposure to an end-of-life front-end library that stopped receiving security fixes in 2016.

60.7%
of Ireland's sites vulnerable
58.8%
global average
6.0%
on end-of-life jQuery 1.x

The most common vulnerable components in Ireland

Share of measured Ireland WordPress sites running each plugin or theme in a version with a known vulnerability.

Slider Revolution11.46%Contact Form 78.89%WPBakery Page Builder5.34%Elementor Pro5.34%WooCommerce4.94%Astra (theme)3.95%Elementor2.96%Essential Addons for Elementor2.57%Elementor Header & Footer1.98%Avada1.78%Smash Balloon Instagram Feed1.78%Divi (theme)1.78%LayerSlider1.38%Hello Elementor1.38%Bridge1.38%

The most-used plugins — and how often they're outdated

Among Ireland sites that run each of these popular components, the share on a version with a known vulnerability. Some stay current; page-builders and sliders lag.

Contact Form 730%Elementor12%WooCommerce27%Elementor Pro32%Slider Revolution88%

How severe are the exposures?

Of Ireland sites running a vulnerable component, the worst-case severity (CVSS) present.

Critical (CVSS 9.0–10)9.4%High (7.0–8.9)48.2%Medium (4.0–6.9)42.3%

Check your own website

Free, no signup — see what our index knows about any site:

For journalists — press kit

“The headline vulnerabilities make the news; the quiet reality is that most of Ireland's WordPress web runs a component with a long-known, unpatched flaw — usually a premium plugin bundled into a theme that no one ever updates,”
— said Attila Rácz-Akácosi, founder of Piperic.

How to cite: “According to Piperic's WordPress Security Report (2026-07-25), 60.7% of measured Ireland WordPress sites run a component with a known vulnerability…” — link to this page.

Download the country dataset (JSON) Global rankings dataset

Methodology

Sample: measured Ireland WordPress sites (ccTLD-based assignment) where at least one plugin/theme version was readable from the homepage. Plugin/theme versions are cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). This measures update hygiene — running a version for which a vulnerability was disclosed — not exploitability. Homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate; no individual site is identified. Snapshot 2026-07-25 (frozen). Vulnerability data © Wordfence Intelligence, MITRE where applicable.

Press contact: press@piperic.com · Data: Piperic Business Intelligence

Every number on this page is reproducible from the public dataset above.

Country reports

🌍 Worldwide🇩🇪 Germany🇳🇱 Netherlands🇬🇧 United Kingdom🇫🇷 France🇷🇺 Russia🇦🇺 Australia🇧🇷 Brazil🇨🇭 Switzerland🇯🇵 Japan🇵🇱 Poland🇸🇪 Sweden🇨🇦 Canada🇪🇺 EU🇮🇹 Italy🇧🇪 Belgium🇪🇸 Spain🇨🇿 Czechia🇦🇹 Austria🇸🇰 Slovakia🇩🇰 Denmark🇮🇳 India🇨🇴 Colombia🇳🇴 Norway🇬🇷 Greece🇭🇺 Hungary🇫🇮 Finland🇲🇽 Mexico🇪🇪 Estonia🇳🇿 New Zealand🇿🇦 South Africa🇮🇱 Israel🇨🇱 Chile🇻🇳 Vietnam🇮🇪 Ireland🇷🇴 Romania🇦🇷 Argentina