Piperic
Security Report
PricingToplistsBrowse free →
🛡️ The WordPress Security Report · July 2026

🇳🇴 51.4% of Norway's WordPress sites run a known-vulnerable component

Of 764 Norway WordPress sites where we could read a component version, 393 (51.4%) run at least one plugin or theme in a version with a publicly known vulnerability. This measures patch hygiene — not that a site is exploitable.

Analysis of live, content-validated websites · vulnerability data from Wordfence Intelligence · snapshot 2026-07-25 · by Piperic

Share:XLinkedIn

51.4%
run a known-vulnerable component
5.9%
run a critical (CVSS 9+) flaw
#34
safest-web rank
of 37 countries (lower = more up-to-date)

Where Norway stands in the world

Share of measured WordPress sites running a known-vulnerable component — lower = more up-to-date. Norway ranks #34 of 37 countries.

🇻🇳 Vietnam83.2%🇮🇱 Israel75.8%🇧🇷 Brazil72.0%🇬🇷 Greece71.5%🇸🇰 Slovakia70.7%🇨🇱 Chile69.2%🇷🇴 Romania68.6%🇦🇷 Argentina67.5%🇳🇴 Norway51.4%

Neighbours shown for context. Full ranking in the data download.

How Norway compares to the world

Norway's WordPress web measured against the global average — and its exposure to an end-of-life front-end library that stopped receiving security fixes in 2016.

51.4%
of Norway's sites vulnerable
58.8%
global average
3.5%
on end-of-life jQuery 1.x

The most common vulnerable components in Norway

Share of measured Norway WordPress sites running each plugin or theme in a version with a known vulnerability.

Contact Form 78.38%Slider Revolution6.41%WPBakery Page Builder5.76%Elementor Pro5.37%WooCommerce4.06%Essential Addons for Elementor3.4%Astra (theme)3.27%Elementor2.36%Flatsome (theme)2.23%Smash Balloon Instagram Feed2.09%Elementor Header & Footer1.83%Divi (theme)1.7%Jetpack1.44%Hello Elementor1.31%Avada1.18%

The most-used plugins — and how often they're outdated

Among Norway sites that run each of these popular components, the share on a version with a known vulnerability. Some stay current; page-builders and sliders lag.

Elementor10%Contact Form 737%Elementor Pro36%WooCommerce28%Hello Elementor16%

How severe are the exposures?

Of Norway sites running a vulnerable component, the worst-case severity (CVSS) present.

Critical (CVSS 9.0–10)11.5%High (7.0–8.9)47.8%Medium (4.0–6.9)40.7%

Check your own website

Free, no signup — see what our index knows about any site:

For journalists — press kit

“The headline vulnerabilities make the news; the quiet reality is that most of Norway's WordPress web runs a component with a long-known, unpatched flaw — usually a premium plugin bundled into a theme that no one ever updates,”
— said Attila Rácz-Akácosi, founder of Piperic.

How to cite: “According to Piperic's WordPress Security Report (2026-07-25), 51.4% of measured Norway WordPress sites run a component with a known vulnerability…” — link to this page.

Download the country dataset (JSON) Global rankings dataset

Methodology

Sample: measured Norway WordPress sites (ccTLD-based assignment) where at least one plugin/theme version was readable from the homepage. Plugin/theme versions are cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). This measures update hygiene — running a version for which a vulnerability was disclosed — not exploitability. Homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate; no individual site is identified. Snapshot 2026-07-25 (frozen). Vulnerability data © Wordfence Intelligence, MITRE where applicable.

Press contact: press@piperic.com · Data: Piperic Business Intelligence

Every number on this page is reproducible from the public dataset above.

Country reports

🌍 Worldwide🇩🇪 Germany🇳🇱 Netherlands🇬🇧 United Kingdom🇫🇷 France🇷🇺 Russia🇦🇺 Australia🇧🇷 Brazil🇨🇭 Switzerland🇯🇵 Japan🇵🇱 Poland🇸🇪 Sweden🇨🇦 Canada🇪🇺 EU🇮🇹 Italy🇧🇪 Belgium🇪🇸 Spain🇨🇿 Czechia🇦🇹 Austria🇸🇰 Slovakia🇩🇰 Denmark🇮🇳 India🇨🇴 Colombia🇳🇴 Norway🇬🇷 Greece🇭🇺 Hungary🇫🇮 Finland🇲🇽 Mexico🇪🇪 Estonia🇳🇿 New Zealand🇿🇦 South Africa🇮🇱 Israel🇨🇱 Chile🇻🇳 Vietnam🇮🇪 Ireland🇷🇴 Romania🇦🇷 Argentina