Piperic
Security Report
PricingToplistsBrowse free →
🛡️ The WordPress Security Report · July 2026

🇸🇬 72.8% of SG's WordPress sites run a known-vulnerable component

Of 9,538 SG WordPress sites where we could read a component version, 6,944 (72.8%) run at least one plugin or theme in a version with a publicly known vulnerability. This measures patch hygiene — not that a site is exploitable.

Analysis of live, content-validated websites · vulnerability data from Wordfence Intelligence · snapshot 2026-07-25 · by Piperic

Share:XLinkedIn

72.8%
run a known-vulnerable component
58%
run a component exploitable WITHOUT any login
Of the known vulnerabilities we matched, this counts only those that require no authenticated account (CVSS “Privileges Required: None”) — the subset an anonymous attacker could reach.
10.6%
run a critical (CVSS 9+) flaw

Where SG stands in the world

Share of measured WordPress sites running a known-vulnerable component — lower = more up-to-date. SG ranks #9 of 59 countries.

🇻🇳 Vietnam83.6%🇲🇦 MA76.9%🇹🇷 Turkey75.7%🇹🇭 TH74.1%🇧🇾 BY73.9%🇭🇰 HK73.6%🇮🇱 Israel73.3%🇬🇷 Greece73.1%🇸🇬 SG72.8%

Neighbours shown for context. Full ranking in the data download.

How SG compares to the world

SG's WordPress web measured against the global average — and its exposure to an end-of-life front-end library that stopped receiving security fixes in 2016.

72.8%
of SG's sites vulnerable
57.8%
global average
26.9%
on end-of-life jQuery 1.x

The whole web — not just WordPress

These measures apply to every live SG website we analysed. They need no version detection, so they carry no selection bias.

3.8%
still serve without HTTPS
42.5%
load third-party JavaScript unchecked (no SRI)
18
pages ask for a password over an unencrypted connection
6.6%
mix insecure resources into a secure page

Platforms past their end of life

Share of each platform's SG sites still on a release line for which the vendor has stopped shipping security fixes.

PlatformSitesOn an unsupported line
Joomla24549.8%
Drupal25316.2%
Magento29215.8%

End of support: Joomla 3.x — August 2023 · Drupal 7 — January 2025 · Magento 1 — June 2020.

The most common vulnerable components in SG

Share of measured SG WordPress sites running each plugin or theme in a version with a known vulnerability.

Contact Form 720.01%Slider Revolution15.17%WooCommerce11.32%WPBakery Page Builder11.06%Elementor Pro7.75%Essential Addons for Elementor6.06%Astra (theme)5.17%Elementor Header & Footer4.69%Elementor3.78%Smash Balloon Instagram Feed2.91%LayerSlider2.82%ElementsKit2.52%Flatsome (theme)2.46%Click To Chat For Whatsapp2.32%Hello Elementor2.1%

The most-used plugins — and how often they're outdated

Among SG sites that run each of these popular components, the share on a version with a known vulnerability. Some stay current; page-builders and sliders lag.

Contact Form 750%Elementor12%WooCommerce57%Elementor Pro46%Slider Revolution97%WPBakery Page Builder95%Hello Elementor22%Astra (theme)66%Essential Addons for Elementor100%Elementor Header & Footer100%Smash Balloon Instagram Feed70%Click To Chat For Whatsapp61%ElementsKit69%Google Analytics For Wordpress39%LayerSlider86%

How severe are the exposures?

Of SG sites running a vulnerable component, the worst-case severity (CVSS) present.

Critical (CVSS 9.0–10)14.5%High (7.0–8.9)52.9%Medium (4.0–6.9)32.5%

Which industries run the most vulnerable components

Share of measured SG WordPress sites with a known-vulnerable component, by industry.

SectorSitesVulnerable
Shopping41887.1%
Technology And Computing13175.6%
Business And Finance35074.9%
Automotive12373.2%
Law12273%
Real Estate19566.7%

One operator, 15,852 websites — and it only wakes up on phones

The same implant sits on 15,852 of the homepages we analysed, calling 2 attacker-controlled hosts and sending an identical hard-coded campaign ID from every one of them: this is a single operation, not a coincidence. The code first checks whether the visitor is on a desktop computer, and stays silent if so. On a phone it opens a channel to the operator's server and runs whatever that server sends back, inside the visitor's browser — so what actually happens is decided remotely, at the moment of the visit. In two thirds of the copies a random gate limits this to roughly every third visitor: another way to stay unnoticed.

SG: we measured no affected websites — which is not a clean bill of health.

⚠ Three quarters of the affected sites worldwide run on generic domains (.com, .net) that cannot be attributed to any country, so national counts are a floor, never a total. And the implant reacts to the visitor's device, not to the website's country.

Signs of compromise

Conservatively detected indicators on SG sites. Every figure is a LOWER BOUND — we only count what we can identify with high confidence, and we never name an individual website.

0
carry a hidden remote-code implant
9
carry injected hidden link spam
0
show defacement text

⚠ The implant we found most often runs only for a share of mobile visitors and opens a connection to an attacker-controlled host, which can then execute arbitrary code in the visitor's browser — a design that deliberately evades desktop security scans.

Servers leaking their own internals

SG sites whose homepage prints server-side error messages or internal file paths — information that helps an attacker map the system.

43
print PHP or database errors on the homepage
98
expose server file paths

Check your own website

Free, no signup — see what our index knows about any site:

For journalists — press kit

“The headline vulnerabilities make the news; the quiet reality is that most of SG's WordPress web runs a component with a long-known, unpatched flaw — usually a premium plugin bundled into a theme that no one ever updates,”
— said Attila Rácz-Akácosi, founder of Piperic.

How to cite: “According to Piperic's WordPress Security Report (2026-07-25), 72.8% of measured SG WordPress sites run a component with a known vulnerability…” — link to this page.

Download the country dataset (JSON) Global rankings dataset

Methodology

Sample: measured SG WordPress sites (ccTLD-based assignment) where at least one plugin/theme version was readable from the homepage. Plugin/theme versions are cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). This measures update hygiene — running a version for which a vulnerability was disclosed — not exploitability. Homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate; no individual site is identified. Snapshot 2026-07-25 (frozen). Vulnerability data © Wordfence Intelligence, MITRE where applicable.

Press contact: press@piperic.com · Data: Piperic Business Intelligence

Every number on this page is reproducible from the public dataset above.

Country reports

🌍 Worldwide🇩🇪 Germany🇳🇱 Netherlands🇬🇧 United Kingdom🇷🇺 Russia🇫🇷 France🇧🇷 Brazil🇨🇭 Switzerland🇦🇺 Australia🇵🇱 Poland🇯🇵 Japan🇸🇪 Sweden🇮🇹 Italy🇨🇦 Canada🇪🇸 Spain🇧🇪 Belgium🇦🇹 Austria🇨🇿 Czechia🇸🇰 Slovakia🇩🇰 Denmark🇮🇳 India🇨🇴 Colombia🇬🇷 Greece🇳🇴 Norway🇭🇺 Hungary🇫🇮 Finland🇲🇽 Mexico🇪🇪 Estonia🇳🇿 New Zealand🇨🇱 Chile🇿🇦 South Africa🇷🇴 Romania🇮🇱 Israel🇦🇷 Argentina🇮🇪 Ireland🇺🇦 Ukraine🇻🇳 Vietnam🇵🇹 Portugal🇹🇷 Turkey🇱🇹 Lithuania🇨🇳 China🇷🇸 RS🇮🇩 Indonesia🇸🇬 SG🇹🇼 Taiwan🇰🇷 South Korea🇸🇮 SI🇭🇷 HR🇧🇾 BY🇱🇻 LV🇱🇺 LU🇦🇪 AE🇭🇰 HK🇹🇭 TH🇮🇸 IS🇧🇬 BG🇳🇬 NG🇲🇦 MA🇱🇮 LI