Industry Benchmark

Hvac WordPress Security Index

Average score 44.4/100 across 1784 scanned hvac sites (90-day window) vs the global index of 48/100.

View Global Index

How does your site compare?

Benchmark your hvac website against 1784 scanned sites. Free, instant, no credit card.

Non-invasive read-only analysis · Results in ~60 seconds

WordPress Security Index

Live security benchmark based on 339,561 real-world WordPress websites continuously analyzed by ThreatSpot.

Average Grade
F
48/100
Websites Scanned
184,835
339,561 total scans
Issues Found
339,560
scans with findings
Scans Today
128
live data
live Updated August 28, 2026 · · 128 scans today
128
Sites Scanned Today
1,661
Issues Found Today
49.2
Avg Score Today
0
Critical Issues Today
Grade Distribution
A
0.4%
361
B
2.5%
2070
C
32.8%
27545
D
26.5%
22229
F
28.4%
23846
Category Pass Rates
Check Pass Rate
SSL/TLS Config 5.9%
Security Headers 0.3%
CSP Policy 0.0%
Cookie Security 81.5%
Mixed Content 62.9%
Server Banner 1.3%
Version Exposure 64.8%
TLS Protocols 94.9%
Latest Plugin Vulnerabilities 10
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress
CVE-2026-8176
Affected: *
100K+ installs
WooCommerce Stripe Payment Gateway
CVE-2026-2381
Affected: *
700K+ installs
RTMKit
CVE-2026-5149
Affected: *
50K+ installs
Video Conferencing with Zoom
CVE-2026-6964
Affected: *
10K+ installs
AI
CVE-2026-12057
Affected: *
40K+ installs
Online Scheduling and Appointment Booking System – Bookly
CVE-2026-5513
Affected: *
60K+ installs
Meow Gallery
CVE-2026-1291
Affected: *
10K+ installs
Canvas
CVE-2026-9629
Affected: *
10K+ installs
Page Builder: Pagelayer – Drag and Drop website builder
CVE-2026-3297
Affected: *
400K+ installs
Page Builder: Pagelayer – Drag and Drop website builder
CVE-2026-2470
Affected: *
400K+ installs
Trending CVEs EPSS + KEV
CVE-2026-72735
EPSS: 0.5%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/se...
Is your site affected? Scan free
8.5
CVE-2026-72881
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command bui...
Is your site affected? Scan free
8.4
CVE-2026-72876
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, swarm.getNodes, swarm.getNodeInfo, swar...
Is your site affected? Scan free
8.4
CVE-2026-71962
EPSS: 0.4%
Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants...
Is your site affected? Scan free
8.4
CVE-2026-72740
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, packages/server/src/utils/providers/git...
Is your site affected? Scan free
8.4
CVE-2026-72739
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs...
Is your site affected? Scan free
8.4
CVE-2026-72738
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.listBackupFiles tRPC endpoin...
Is your site affected? Scan free
8.4
CVE-2026-72736
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values d...
Is your site affected? Scan free
8.4
CVE-2026-72733
EPSS: 0.4%
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC s...
Is your site affected? Scan free
8.4
CVE-2026-72886
EPSS: 0.3%
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.u...
Is your site affected? Scan free
8.3
Top Security Issues (Last 7 days)
Issue Count Critical % of Scans
Unknown 62507 0 74.4%
Fastest-Growing Issue
Unknown
+3.0% week over week
This week: 65118 occurrences · Last week: 63199

How does your site compare?

Run a free security scan to see your score vs the global average.

Run a Free Scan
Industry Security Rankings (90-day average, min 5 scans per sector)
# Industry Avg Score Scans
1 Manufacturing 48.8 4580
2 Retail 46.3 6695
3 Dental 46.3 11803
4 Insurance 45.9 829
5 Security 45.1 529
6 Agriculture 45.1 1450
7 Fitness 45.0 1198
8 Towing 44.5 71
9 Hvac 44.4 1784
10 Education 44.2 3536
11 Healthcare 44.1 5532
12 Entertainment 43.7 4396
13 Painting 43.6 453
14 Pet_Services 43.6 707
15 Moving_Storage 43.4 620
Methodology & Data Privacy

The ThreatSpot WordPress Security Index is the average security score across all scans performed in the last 30 days. Each site is scored 0–100 based on:

  • SSL/TLS configuration — valid certificate, HSTS, modern TLS version
  • Security headers — CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Cookie security — Secure flag, SameSite, HttpOnly
  • Server version disclosure — whether version info is exposed
  • Mixed content — HTTP resources on HTTPS pages
  • Known vulnerable plugins — cross-referenced with NVD, CISA KEV, and EPSS data
Privacy-first: All data is anonymized and aggregated. No individual site domains, URLs, or identifying information are exposed on this dashboard. Statistics are only published when minimum sample sizes are met to prevent re-identification. The sample focuses on small-business WordPress sites.

Get the monthly WordPress Security Index report

One email a month: the latest index score, trending CVEs, and the fastest-growing issues — straight from our scan telemetry. No spam, unsubscribe anytime.

Embed the live index on your site

Free badge + widget for blogs, agencies, and hosting companies. Copy-paste HTML, Markdown, or WordPress snippet.

Get Embed Code