WordPress Security Index

Live security benchmark based on 275,070 real-world WordPress websites continuously analyzed by ThreatSpot.

Average Grade
F
41/100
Websites Scanned
120,366
275,070 total scans
Issues Found
275,069
scans with findings
Scans Today
2,512
live data
live Updated August 04, 2026 · · 2,512 scans today
2,512
Sites Scanned Today
12,392
Issues Found Today
42.1
Avg Score Today
0
Critical Issues Today
Grade Distribution
A
0.6%
519
B
2.1%
1940
C
29.5%
27669
D
21.0%
19666
F
35.2%
33059
Category Pass Rates
Check Pass Rate
SSL/TLS Config 5.8%
Security Headers 0.4%
CSP Policy 0.0%
Cookie Security 82.2%
Mixed Content 62.7%
Server Banner 1.4%
Version Exposure 62.7%
TLS Protocols 95.5%
Latest Plugin Vulnerabilities 10
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
CVE-2026-8176
Affected: *
100K+ installs
WooCommerce Stripe Payment Gateway
CVE-2026-2381
Affected: *
700K+ installs
RTMKit
CVE-2026-5149
Affected: *
50K+ installs
Video Conferencing with Zoom
CVE-2026-6964
Affected: *
10K+ installs
AI
CVE-2026-12057
Affected: *
40K+ installs
Online Scheduling and Appointment Booking System – Bookly
CVE-2026-5513
Affected: *
60K+ installs
Meow Gallery
CVE-2026-1291
Affected: *
10K+ installs
Canvas
CVE-2026-9629
Affected: *
10K+ installs
Page Builder: Pagelayer – Drag and Drop website builder
CVE-2026-3297
Affected: *
400K+ installs
Page Builder: Pagelayer – Drag and Drop website builder
CVE-2026-2470
Affected: *
400K+ installs
Trending CVEs EPSS + KEV
CVE-2026-63030 KEV
EPSS: 1.0%
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which...
39.0
CVE-2026-47429
EPSS: 0.6%
Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFile...
8.6
CVE-2026-47302
EPSS: 0.6%
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
8.6
CVE-2026-58627
EPSS: 0.6%
Uncontrolled resource consumption in Windows DHCP Server allows an unauthorized attacker to deny service over a network.
8.6
CVE-2026-50651
EPSS: 0.5%
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
8.5
CVE-2026-50648
EPSS: 0.5%
Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service o...
8.5
CVE-2026-50527
EPSS: 0.5%
Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network.
8.5
CVE-2026-50525
EPSS: 0.5%
Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a netw...
8.5
CVE-2026-50524
EPSS: 0.5%
Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a ...
8.5
CVE-2026-48068
EPSS: 0.5%
@grpc/grps-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.9.16, 1.10...
8.5
Top Security Issues (Last 7 days)
Issue Count Critical % of Scans
Unknown 60345 0 64.3%
Fastest-Growing Issue
Unknown
+1.3% week over week
This week: 63151 occurrences · Last week: 62359

How does your site compare?

Run a free security scan to see your score vs the global average.

Run a Free Scan
Industry Security Rankings (90-day average, min 5 scans per sector)
# Industry Avg Score Scans
1 Manufacturing 46.7 3077
2 Insurance 45.6 892
3 Dental 45.5 14633
4 Towing 44.7 63
5 Retail 44.6 4640
6 Hvac 44.2 1780
7 Agriculture 44.2 1230
8 Fitness 43.5 936
9 Painting 43.1 492
10 Healthcare 42.9 5307
11 Security 42.9 570
12 Hospitality 42.5 6710
13 Restaurant 42.4 6741
14 Pet_Services 42.2 534
15 Landscaping 42.2 1145
Methodology & Data Privacy

The ThreatSpot WordPress Security Index is the average security score across all scans performed in the last 30 days. Each site is scored 0–100 based on:

  • SSL/TLS configuration — valid certificate, HSTS, modern TLS version
  • Security headers — CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Cookie security — Secure flag, SameSite, HttpOnly
  • Server version disclosure — whether version info is exposed
  • Mixed content — HTTP resources on HTTPS pages
  • Known vulnerable plugins — cross-referenced with NVD, CISA KEV, and EPSS data
Privacy-first: All data is anonymized and aggregated. No individual site domains, URLs, or identifying information are exposed on this dashboard. Statistics are only published when minimum sample sizes are met to prevent re-identification. The sample focuses on small-business WordPress sites.