Pantheon

Pantheon

Managed WordPresspantheon.io

WebOps platform for WordPress and Drupal with dev/test/live workflows.

18K
WordPress Sites Tracked on Pantheon
18K
Sites Detected
3.9
Avg Plugins / Site
+2.1 vs avg
5K
Vuln Exposure
sites with outdated plugins
44 / 50
Plugins with CVEs
1 unpatched
WordPress Versions
6.9.1
3K29.3%
6.9.4
7808.6%
6.8.3
7298.0%
6.9
6647.3%
6.8.2
3043.3%
6.7.2
3023.3%
6.8.1
2582.8%
6.7.1
1571.7%
6.7.4
1501.7%
6.9.3
1311.4%
6.8.5
1281.4%
6.4.3
1251.4%
6.6.2
1201.3%
6.4.7
951.0%
6.1.1
911.0%

Summary

Most Common
6.9.1
Version Coverage
52%
of sites have detectable WP version
Unique Versions
231
Most Popular Plugins
Top 50
1 of the top 50 plugins on Pantheon have unpatched vulnerabilities.

Vulnerable Version Usage

Sites running outdated (vulnerable) vs safe versions of top plugins

The Events Calendar95% vulnerable
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More70.4% vulnerable
Elementor Website Builder – more than just a page builder68.5% vulnerable
Contact Form 751.3% vulnerable
Ultimate Addons for Elementor45.8% vulnerable
Jetpack – WP Security, Backup, Speed, & Growth43.5% vulnerable
TablePress – Tables in WordPress made easy41.7% vulnerable
Max Mega Menu37.1% vulnerable

Plugin Security Overview

Breakdown of 50 most popular plugins on Pantheon

50plugins
No known CVEs6
CVEs (all patched)43
Unpatched CVEs1
Est. exposed sites
5K
plugins on Pantheon — sorted by prevalence
#PluginCVEs
1
SlideShow Press
0
220
Version distribution on Pantheon (135 versions detected)
3.5.1
400.5%
2.1.0
130.1%
1.12.14
60.1%vuln
1.12.10
50.1%vuln
2.7.6
50.1%
1.0
40.0%vuln
1.12.11
40.0%vuln
1.0.0
30.0%vuln
2.4
30.0%
2.9.8
30.0%
+125 more versions
3
Meta Generator and Version Info Remover
0
447
5
Contact Form 7
8
62
726
8
The Events Calendar
25
924
1010
119
12
WCAG 2.0 form fields for Gravity Forms
0
134
143
15
WP-PageNavi
0
162
17
Ultimate Addons for Elementor
12
185
191
2014
Most Popular Themes
Hello Elementor
#1
877 sites

Hello Elementor

by elemntor

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

1.0M 1 CVE
Astra
#2
584 sites

Astra

by brainstormforce

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/

1.0M 3 CVEs
eatery
#3
485 sites

eatery

No CVEs
begin
#4
370 sites

begin

No CVEs
nashvilleparent
#5
169 sites

nashvilleparent

No CVEs
GeneratePress
#6
159 sites

GeneratePress

by edge22

GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performance is important to us, which is why a fresh GeneratePress install adds less than 10kb (gzipped) to your page size. We take full advantage of the block editor (Gutenberg), which gives you more control over creating your content. If you use page builders, GeneratePress is the right theme for you. It is completely compatible with all major page builders, including Beaver Builder and Elementor. Thanks to our emphasis on WordPress coding standards, we can boast full compatibility with all well-coded plugins, including WooCommerce. GeneratePress is fully responsive, uses valid HTML/CSS, and is translated into over 25 languages by our amazing community of users. A few of our many features include 60+ color controls, powerful dynamic typography, 5 navigation locations, 5 sidebar layouts, dropdown menus (click or hover), and 9 widget areas. Learn more and check out our powerful premium version at https://generatepress.com

500K No CVEs
Kadence
#7
157 sites

Kadence

by stellarwp

Kadence Theme is a lightweight yet full featured WordPress theme for creating beautiful fast loading and accessible websites, easier than ever. It features an easy to use drag and drop header and footer builder to build any type of header in minutes. It features a full library of gorgeous starter templates that are easy to modify with our intelligent global font and color controls. With extensive integration with the most popular 3rd party plugins, you can quickly build impressive ecommerce websites, course websites, business websites, and more.

400K No CVEs
hello-theme-child-master
#8
146 sites

hello-theme-child-master

No CVEs
flatsome
#9
138 sites

flatsome

4 CVEs
salient
#10
137 sites

salient

2 CVEs
myconveyor
#11
137 sites

myconveyor

No CVEs
prostore
#12
135 sites

prostore

1 CVE
astra-child
#13
132 sites

astra-child

No CVEs
enfold
#14
121 sites

enfold

1 unpatched
genesis
#15
115 sites

genesis

1 CVE
Vulnerable Sites

These sites on Pantheon are running outdated plugin versions with known security vulnerabilities. Domain names are partially masked for privacy.

vulnerable domains on Pantheon
DomainVulnerable Plugins
answ***************.com
www.***************.org
alu*******.edu
bric*************.com
cjs*******.com
ecb**********.io
evol*************.website
www.**********.com
beau*********************.com
elea***************************.org
etoi**********.com
infi************.au
clm*******.org
cop*********.com
elit*********************.net
har**********.com
jrss**********.com
sec**********.org
www.*************.com
www.**********.org

Showing 20 of the most affected sites. Run a free audit to check if your site is affected.

Is your Pantheon site secure?

Run a free audit to check your plugins, themes, and WordPress version against our vulnerability database.