Netlify

Netlify

Edge Platformsnetlify.com

Jamstack platform used with headless WordPress and static site generators.

148K
WordPress Sites Tracked on Netlify
148K
Sites Detected
2.2
Avg Plugins / Site
+0.3 vs avg
23K
Vuln Exposure
sites with outdated plugins
45 / 50
Plugins with CVEs
1 unpatched
WordPress Versions
6.9.1
12K31.0%
6.9.4
8K20.9%
6.8.3
3K6.8%
5.3
2K5.6%
6.8.5
1K3.1%
6.7.4
9242.3%
6.9.3
9122.3%
6.9
7972.0%
6.7.5
5841.5%
5.9
4621.2%
6.6.4
4451.1%
6.8.2
4321.1%
6.4.7
3841.0%
6.5.7
3800.9%
6.6.5
3310.8%

Summary

Most Common
6.9.1
Version Coverage
27%
of sites have detectable WP version
Unique Versions
398
Most Popular Plugins
Top 50
1 of the top 50 plugins on Netlify have unpatched vulnerabilities.

Vulnerable Version Usage

Sites running outdated (vulnerable) vs safe versions of top plugins

Complianz – GDPR/CCPA Cookie Consent100% vulnerable
The Events Calendar86.1% vulnerable
Spam protection, Honeypot, Anti-Spam by CleanTalk79.9% vulnerable
Elementor Website Builder – more than just a page builder70.3% vulnerable
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More60.4% vulnerable
Contact Form 745.6% vulnerable
TablePress – Tables in WordPress made easy43.8% vulnerable
Jetpack – WP Security, Backup, Speed, & Growth42.8% vulnerable

Plugin Security Overview

Breakdown of 50 most popular plugins on Netlify

50plugins
No known CVEs5
CVEs (all patched)44
Unpatched CVEs1
Est. exposed sites
23K
plugins on Netlify — sorted by prevalence
#PluginCVEs
1
SlideShow Press
0
220
Version distribution on Netlify (414 versions detected)
3.5.1
1K2.4%
1.12.14
320.1%vuln
6.9.1
210.0%
1.3
200.0%vuln
1.0
140.0%vuln
2.9.10
140.0%
2.1.0
130.0%
2.12.17
120.0%
2.5.0
100.0%
2.12.15
90.0%
+404 more versions
3
Meta Generator and Version Info Remover
0
4
Contact Form 7
8
547
626
72
824
91
104
1110
121
1310
14
Ultimate Addons for Elementor
12
151
1614
1713
18
Easy Table of Contents
5
199
20
The Events Calendar
25
Most Popular Themes
Hello Elementor
#1
4K sites

Hello Elementor

by elemntor

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

1.0M 1 CVE
Astra
#2
3K sites

Astra

by brainstormforce

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/

1.0M 3 CVEs
envo-magazine
#3
2K sites

envo-magazine

No CVEs
envo-magazine-dark
#4
2K sites

envo-magazine-dark

No CVEs
bb-theme
#5
2K sites

bb-theme

No CVEs
ConsultStreet
#6
1K sites

ConsultStreet

by themearile

ConsultStreet is a multipurpose WordPress theme that you can use to create any website you wish to create. The theme comes with a very flexible design, and it is fully customizable as per your requirement. ConsultStreet is a perfect theme for the consulting and finance business website. Not only that, but this is also a very lightweight theme that is load with a single click in no time. The theme is completely responsive and mobile-friendly and that your users can access your site from any device. As well as sophisticated plus it has some exotic features like customization and clean code, advanced typography, sticky menu, logo upload, header image, Bootstrap 4 framework, built with SEO in mind, and translation ready (WPML, Polylang). This theme supports the best Elementor page builder to create, edit, and updates page designs as per the requirement. ConsultStreet also supports popular free and premium WordPress plugins such as Elementor, Yoast SEO, WooCommerce, Contact Form 7, Jetpack, Google Analytics, and much more. Check the demo of ConsultStreet Pro https://themearile.com/consultstreet-pro-theme/.

1K 1 unpatched
GeneratePress
#7
1K sites

GeneratePress

by edge22

GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performance is important to us, which is why a fresh GeneratePress install adds less than 10kb (gzipped) to your page size. We take full advantage of the block editor (Gutenberg), which gives you more control over creating your content. If you use page builders, GeneratePress is the right theme for you. It is completely compatible with all major page builders, including Beaver Builder and Elementor. Thanks to our emphasis on WordPress coding standards, we can boast full compatibility with all well-coded plugins, including WooCommerce. GeneratePress is fully responsive, uses valid HTML/CSS, and is translated into over 25 languages by our amazing community of users. A few of our many features include 60+ color controls, powerful dynamic typography, 5 navigation locations, 5 sidebar layouts, dropdown menus (click or hover), and 9 widget areas. Learn more and check out our powerful premium version at https://generatepress.com

500K No CVEs
eatery
#8
1K sites

eatery

No CVEs
flatsome
#9
1K sites

flatsome

4 CVEs
begin
#10
958 sites

begin

No CVEs
Experon
#11
832 sites

Experon

by thinkupthemes

Experon is the free version of the multi-purpose professional theme (Experon Pro) ideal for a business or blog website. The theme has a responsive layout, HD retina ready and comes with a powerful theme options panel with can be used to make awesome changes without touching any code. The theme also comes with a full width easy to use slider. Easily add a logo to your site and create a beautiful homepage using the built-in homepage layout.

800 No CVEs
exblog
#12
830 sites

exblog

No CVEs
storybook
#13
682 sites

storybook

No CVEs
OceanWP
#14
596 sites

OceanWP

by oceanwp

OceanWP is the perfect theme for your project. Lightweight and highly extendable, it will enable you to create almost any type of website such a blog, portfolio, business website and WooCommerce storefront with a beautiful & professional design. Very fast, responsive, RTL & translation ready, best SEO practices, unique WooCommerce features to increase conversion and much more. You can even edit the settings on tablet & mobile so your site looks good on every device. Work with the most popular page builders as Elementor, Beaver Builder, Brizy, Visual Composer, Divi, SiteOrigin, etc... Developers will love his extensible codebase making it a joy to customize and extend. Best friend of Elementor & WooCommerce. Looking for a Multi-Purpose theme? Look no further! Check the demos to realize that it's the only theme you will ever need: https://oceanwp.org/demos/

500K 5 CVEs
Kadence
#15
585 sites

Kadence

by stellarwp

Kadence Theme is a lightweight yet full featured WordPress theme for creating beautiful fast loading and accessible websites, easier than ever. It features an easy to use drag and drop header and footer builder to build any type of header in minutes. It features a full library of gorgeous starter templates that are easy to modify with our intelligent global font and color controls. With extensive integration with the most popular 3rd party plugins, you can quickly build impressive ecommerce websites, course websites, business websites, and more.

400K No CVEs
Vulnerable Sites

These sites on Netlify are running outdated plugin versions with known security vulnerabilities. Domain names are partially masked for privacy.

vulnerable domains on Netlify
DomainVulnerable Plugins
engi**************.edu
www.***********.dz
long**********.com
af**.uz
btb**********.id
mart**************.co
ass**********.org
ci*****.com
hunt**********.net
ij*****.com
aq*******.gr
aroh************.org
chic******************.com
qa***.me
as***.blog
bjb*******.in
eu*****.ro
inve******************.sv
piv*********.cz
trad****************.com

Showing 20 of the most affected sites. Run a free audit to check if your site is affected.

Is your Netlify site secure?

Run a free audit to check your plugins, themes, and WordPress version against our vulnerability database.