Of 17,779 Ukraine WordPress sites where we could read a component version, 11,556 (65%) run at least one plugin or theme in a version with a publicly known vulnerability. This measures patch hygiene — not that a site is exploitable.
Analysis of live, content-validated websites · vulnerability data from Wordfence Intelligence · snapshot 2026-07-25 · by Piperic
Share of measured WordPress sites running a known-vulnerable component — lower = more up-to-date. Ukraine ranks #27 of 59 countries.
Neighbours shown for context. Full ranking in the data download.
Ukraine's WordPress web measured against the global average — and its exposure to an end-of-life front-end library that stopped receiving security fixes in 2016.
These measures apply to every live Ukraine website we analysed. They need no version detection, so they carry no selection bias.
Share of each platform's Ukraine sites still on a release line for which the vendor has stopped shipping security fixes.
| Platform | Sites | On an unsupported line |
|---|---|---|
| Joomla | 2,764 | 55.4% |
| Drupal | 1,166 | 46.5% |
| Magento | 306 | 39.2% |
End of support: Joomla 3.x — August 2023 · Drupal 7 — January 2025 · Magento 1 — June 2020.
Share of measured Ukraine WordPress sites running each plugin or theme in a version with a known vulnerability.
Among Ukraine sites that run each of these popular components, the share on a version with a known vulnerability. Some stay current; page-builders and sliders lag.
Of Ukraine sites running a vulnerable component, the worst-case severity (CVSS) present.
Share of measured Ukraine WordPress sites with a known-vulnerable component, by industry.
| Sector | Sites | Vulnerable |
|---|---|---|
| Shopping | 584 | 81.8% |
| Food And Drink | 136 | 77.9% |
| Automotive | 173 | 77.5% |
| Law | 175 | 73.1% |
| Technology And Computing | 121 | 65.3% |
| Business And Finance | 159 | 59.1% |
| Attractions | 1,367 | 22.9% |
The same implant sits on 15,852 of the homepages we analysed, calling 2 attacker-controlled hosts and sending an identical hard-coded campaign ID from every one of them: this is a single operation, not a coincidence. The code first checks whether the visitor is on a desktop computer, and stays silent if so. On a phone it opens a channel to the operator's server and runs whatever that server sends back, inside the visitor's browser — so what actually happens is decided remotely, at the moment of the visit. In two thirds of the copies a random gate limits this to roughly every third visitor: another way to stay unnoticed.
Ukraine: we measured 2 affected websites.
⚠ Three quarters of the affected sites worldwide run on generic domains (.com, .net) that cannot be attributed to any country, so national counts are a floor, never a total. And the implant reacts to the visitor's device, not to the website's country.
Conservatively detected indicators on Ukraine sites. Every figure is a LOWER BOUND — we only count what we can identify with high confidence, and we never name an individual website.
⚠ The implant we found most often runs only for a share of mobile visitors and opens a connection to an attacker-controlled host, which can then execute arbitrary code in the visitor's browser — a design that deliberately evades desktop security scans.
Ukraine sites whose homepage prints server-side error messages or internal file paths — information that helps an attacker map the system.
Free, no signup — see what our index knows about any site:
How to cite: “According to Piperic's WordPress Security Report (2026-07-25), 65% of measured Ukraine WordPress sites run a component with a known vulnerability…” — link to this page.
Download the country dataset (JSON) Global rankings dataset
Sample: measured Ukraine WordPress sites (ccTLD-based assignment) where at least one plugin/theme version was readable from the homepage. Plugin/theme versions are cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). This measures update hygiene — running a version for which a vulnerability was disclosed — not exploitability. Homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate; no individual site is identified. Snapshot 2026-07-25 (frozen). Vulnerability data © Wordfence Intelligence, MITRE where applicable.
Press contact: press@piperic.com · Data: Piperic Business Intelligence
Every number on this page is reproducible from the public dataset above.