Annual Benchmark Report

State of WordPress Security 2026

What 339,471 real-world scans tell us about the security posture of WordPress sites — and what it means for yours.

Executive Summary

The average WordPress site in our dataset scores 48/100 (F) — a passing grade, but far from secure. Across 84,008 scans in the last 30 days, 84,008 scans found at least one security issue.

The most common problems aren't exotic zero-days — they're basic hygiene failures: missing security headers, permissive Content Security Policies, exposed server banners, and outdated plugins with known CVEs. The good news: most of these are fixable in minutes.

F
Global Average Grade
48
Index Score / 100
84,008
Scans With Issues
81,413
Unique Sites Analyzed
Where Sites Fail Most
Security Check Pass Rate Status
SSL/TLS Configuration 5.9%
Security Headers 0.3%
CSP Policy 0.0%
Cookie Security 81.5%
Mixed Content 62.9%
Server Banner 1.3%
Version Exposure 64.8%
TLS Protocols 94.9%
Top Issues Found (Last 7 Days)
Issue Count % of Scans
Unknown 62497 74.4%
Industry Rankings
# Industry Avg Score Scans
1 Manufacturing 48.8 4579
2 Retail 46.3 6698
3 Dental 46.3 11845
4 Insurance 45.9 829
5 Security 45.1 527
6 Agriculture 45.1 1450
7 Fitness 44.9 1199
8 Towing 44.5 71
9 Hvac 44.4 1784
10 Education 44.2 3541
11 Healthcare 44.1 5549
12 Entertainment 43.7 4394
13 Painting 43.6 453
14 Pet_Services 43.5 708
15 Moving_Storage 43.4 620
Trending CVEs to Watch
CVE-2026-72735 EPSS 0.5%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traef...
CVE-2026-72881 EPSS 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/se...
CVE-2026-72876 EPSS 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swarm.getNodeApps, and s...
CVE-2026-71962 EPSS 0.4%
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpo...
CVE-2026-72740 EPSS 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git.ts parses the user-...
CVE-2026-72739 EPSS 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs shell commands by i...
CVE-2026-72738 EPSS 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoint in apps/dokploy/se...
CVE-2026-72736 EPSS 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell c...
Methodology

The ThreatSpot WordPress Security Index is the average security score across all scans performed in the last 30 days. Each site is scored 0–100 based on SSL/TLS configuration, security headers, cookie security, server version disclosure, mixed content, and known vulnerable plugins (cross-referenced with NVD, CISA KEV, and EPSS data). All data is anonymized and aggregated — no individual site domains are exposed. Statistics are only published when minimum sample sizes are met.

Where does your site rank?

Run a free scan and see your score vs the global average.

Scan My Site Free