How does your site compare?

Benchmark your website against 246,197 real-world WordPress sites (400,960 total scans). Free, instant, no credit card.

Non-invasive read-only analysis · Results in ~60 seconds

WordPress Security Index

Live security benchmark from 246,197 real-world WordPress sites across 400,960 security scans, continuously analyzed by ThreatSpot.

Average Grade
F
50/100
Websites Scanned
246,197
400,960 total scans
30-Day Change
▲ +3.0
index points, month over month
Scans Today
1,668
live data
live Updated September 20, 2026 · · 1,668 scans today
1,668
Sites Scanned Today
11,392
Issues Found Today
51.9
Avg Score Today
0
Critical Issues Today
Grade Distribution
A
0.9%
635
B
3.2%
2322
C
42.3%
30789
D
29.7%
21622
F
24.0%
17453
Category Pass Rates
Check Pass Rate
SSL/TLS Config 6.8%
Security Headers 0.5%
CSP Policy 0.0%
Cookie Security 83.2%
Mixed Content 63.1%
Server Banner 1.6%
Version Exposure 63.4%
TLS Protocols 95.1%

What the data tells us

HTTPS isn’t the problem anymore. Hardening is.

95.1% of sites pass our TLS protocol checks, but only 0.0% pass the CSP benchmark.

Latest Plugin Vulnerabilities 20
Gum Addon for Elementor
CVE-2026-8354
Affected: ≤1.3.15 · Fixed in 1.3.15
50K+ installs
LiteSpeed Cache
CVE-2026-76579
Affected: ≤7.9 · Fixed in 7.9
7.0M+ installs
Redux Framework
CVE-2026-5410
Affected: ≤4.5.13 · Fixed in 4.5.13
900K+ installs
TikTok
CVE-2026-18346
Affected: ≤1.4.1 · Fixed in 1.4.1
200K+ installs
Custom Field Template
CVE-2026-9855
Affected: ≤2.7.8 · Fixed in 2.7.8
30K+ installs
Payment Gateway of Stripe for WooCommerce
CVE-2026-9832
Affected: ≤5.0.8 · Fixed in 5.0.8
8K+ installs
Easy Appointments
CVE-2026-9232
Affected: ≤3.12.27 · Fixed in 3.12.27
10K+ installs
MC4WP: Mailchimp for WordPress
CVE-2026-87917
Affected: ≤4.14.0 · Fixed in 4.14.0
1.0M+ installs
Redux Framework
CVE-2026-5400
Affected: ≤4.5.13 · Fixed in 4.5.13
900K+ installs
Ibtana – Ecommerce Product Addons
CVE-2026-1984
Affected: ≤0.4.7 · Fixed in 0.4.7
6K+ installs
BlockSpare – Gutenberg Blocks for News, Magazine, Blog & Business Websites
CVE-2026-1242
Affected: ≤4.2.6 · Fixed in 4.2.6
10K+ installs
Search Atlas SEO – OTTO AI SEO Automation for WordPress
CVE-2026-15947
Affected: ≤2.6.23 · Fixed in 2.6.23
8K+ installs
SSL Zen — SSL Certificate Installer & HTTPS Redirects
CVE-2026-15463
Affected: ≤4.7.42 · Fixed in 4.7.42
10K+ installs
Real3D Flipbook – 3D FlipBook, PDF FlipBook, PDF Viewer, PDF Embedder
CVE-2026-15098
Affected: ≤5.1.1 · Fixed in 5.1.1
10K+ installs
Create
CVE-2026-13200
Affected: ≤2.5.3 · Fixed in 2.5.3
6K+ installs
Create
CVE-2026-13191
Affected: ≤2.5.3 · Fixed in 2.5.3
6K+ installs
PDF Builder for WooCommerce. Create invoices,packing slips and more
CVE-2026-11899
Affected: ≤2.0.11 · Fixed in 2.0.11
2K+ installs
WP Customer Reviews
CVE-2026-11608
Affected: ≤3.7.8 · Fixed in 3.7.8
20K+ installs
Pochipp
CVE-2026-92967
Affected: ≤1.20.2 · Fixed in 1.20.2
30K+ installs
WP Recipe Maker
CVE-2026-89274
Affected: ≤10.8.1 · Fixed in 10.8.1
50K+ installs
Trending WordPress CVEs EPSS + KEV
CVE-2026-16777 Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
EPSS: 0.5%
The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to...
Is your site affected? Scan free
15.5
CVE-2026-87909 WP Photo Album Plus
EPSS: 0.4%
The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_m...
Is your site affected? Scan free
15.4
CVE-2026-87915 Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
EPSS: 0.4%
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
Is your site affected? Scan free
15.4
CVE-2026-15797 Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
EPSS: 0.4%
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ...
Is your site affected? Scan free
15.4
CVE-2026-12954 Mapster WP Maps
EPSS: 0.4%
The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including...
Is your site affected? Scan free
15.4
CVE-2026-9855 Custom Field Template
EPSS: 0.3%
The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parameter in all...
Is your site affected? Scan free
15.3
CVE-2026-11608 WP Customer Reviews
EPSS: 0.3%
The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' param...
Is your site affected? Scan free
15.3
CVE-2026-89274 WP Recipe Maker
EPSS: 0.3%
The WP Recipe Maker plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in all versions up to, and inclu...
Is your site affected? Scan free
15.3
CVE-2026-13471 Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
EPSS: 0.3%
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direc...
Is your site affected? Scan free
15.3
CVE-2026-92619 Booking Calendar
EPSS: 0.3%
The Booking Calendar plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11...
Is your site affected? Scan free
15.3
Top Security Issues (Last 7 days)
Issue Count Critical % of Scans
Security Header 28365 0 35.3%
Server Banner 4921 0 6.1%
Csp 4758 4590 5.9%
Ssl Expiration 4725 494 5.9%
Email Security Dmarc 4317 0 5.4%
Performance 3812 0 4.7%
Sitemap 2721 0 3.4%
Http To Https Redirect 2483 2230 3.1%
Mixed Content 2287 2234 2.8%
Robots Txt Leakage 2101 0 2.6%
Fastest-Growing Issue
Server Version
+10.9% week over week
This week: 1329 occurrences · Last week: 1198

How does your site compare?

Run a free security scan to see your score vs the global average.

Run a Free Scan
Industry Security Rankings (90-day average, min 5 scans per sector)
# Industry Avg Score Scans
1 Manufacturing 53.2 4335
2 Government 51.5 819
3 Insurance 51.4 599
4 Towing 51.3 49
5 Security 51.2 315
6 Education 51.1 3331
7 Retail 51.1 5821
8 Entertainment 51.0 4662
9 Finance 50.9 1264
10 Dental 50.8 7938
11 Fitness 50.7 1096
12 Agriculture 50.2 1210
13 Restaurant 50.1 1928
14 Technology 50.1 6527
15 Healthcare 50.0 4568
Methodology & Data Privacy

The ThreatSpot WordPress Security Index is the average security score across all scans performed in the last 30 days. Each site is scored 0–100 based on:

  • SSL/TLS configuration — valid certificate, HSTS, modern TLS version
  • Security headers — CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Cookie security — Secure flag, SameSite, HttpOnly
  • Server version disclosure — whether version info is exposed
  • Mixed content — HTTP resources on HTTPS pages
  • Known vulnerable plugins — cross-referenced with NVD, CISA KEV, and EPSS data
Privacy-first: All data is anonymized and aggregated. No individual site domains, URLs, or identifying information are exposed on this dashboard. Statistics are only published when minimum sample sizes are met to prevent re-identification. The sample focuses on small-business WordPress sites.

Get the monthly WordPress Security Index report

One email a month: the latest index score, trending CVEs, and the fastest-growing issues — straight from our scan telemetry. No spam, unsubscribe anytime.

Embed the live index on your site

Free badge + widget for blogs, agencies, and hosting companies. Copy-paste HTML, Markdown, or WordPress snippet.

Get Embed Code