Sucuri

Sucuri

CDN & Securitysucuri.net

Website security platform with WAF, CDN, and malware scanning.

7K
WordPress Sites Tracked on Sucuri
7K
Sites Detected
5.2
Avg Plugins / Site
+3.3 vs avg
1K
Vuln Exposure
sites with outdated plugins
45 / 50
Plugins with CVEs
1 unpatched
WordPress Versions
6.9.1
95736.7%
6.9.4
41916.1%
6.8.3
1837.0%
6.9
1033.9%
6.9.3
823.1%
6.8.5
793.0%
6.7.4
501.9%
6.7.5
301.1%
6.4.7
291.1%
6.8.2
261.0%
6.1.9
251.0%
6.6.4
240.9%
6.4.8
230.9%
6.8.1
210.8%
6.2.8
200.8%

Summary

Most Common
6.9.1
Version Coverage
40%
of sites have detectable WP version
Unique Versions
171
Most Popular Plugins
Top 50
1 of the top 50 plugins on Sucuri have unpatched vulnerabilities.

Vulnerable Version Usage

Sites running outdated (vulnerable) vs safe versions of top plugins

Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN100% vulnerable
SyntaxHighlighter Evolved93.9% vulnerable
Elementor Website Builder – more than just a page builder71.4% vulnerable
Jetpack – WP Security, Backup, Speed, & Growth39.1% vulnerable
Contact Form 735.4% vulnerable
Easy Table of Contents32.2% vulnerable
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic30.3% vulnerable
Comments – wpDiscuz29.4% vulnerable

Plugin Security Overview

Breakdown of 50 most popular plugins on Sucuri

50plugins
No known CVEs5
CVEs (all patched)44
Unpatched CVEs1
Est. exposed sites
1K
plugins on Sucuri — sorted by prevalence
#PluginCVEs
1
SlideShow Press
0
220
Version distribution on Sucuri (60 versions detected)
3.5.1
160.5%
2.4
60.2%
1.12.14
30.1%vuln
2.1.0
30.1%
2.12.17
30.1%
1.12.11
20.1%vuln
14.5
20.1%
2.3.4
20.1%
2.9.10
20.1%
0.3.1
10.0%vuln
+50 more versions
3
Meta Generator and Version Info Remover
0
4
Contact Form 7
8
547
626
72
824
96
1020
11
Open Graph
1
123
131
14
CoSchedule
3
15
Easy Table of Contents
5
16
Speculative Loading
0
1710
1824
1914
20
SyntaxHighlighter Evolved
3
Most Popular Themes
eatery
#1
233 sites

eatery

No CVEs
Hello Elementor
#2
220 sites

Hello Elementor

by elemntor

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

1.0M 1 CVE
Astra
#3
203 sites

Astra

by brainstormforce

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/

1.0M 3 CVEs
vb
#4
165 sites

vb

No CVEs
oceana
#5
159 sites

oceana

No CVEs
travelalerts
#6
154 sites

travelalerts

No CVEs
discussionwp-child
#7
132 sites

discussionwp-child

No CVEs
GeneratePress
#8
130 sites

GeneratePress

by edge22

GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performance is important to us, which is why a fresh GeneratePress install adds less than 10kb (gzipped) to your page size. We take full advantage of the block editor (Gutenberg), which gives you more control over creating your content. If you use page builders, GeneratePress is the right theme for you. It is completely compatible with all major page builders, including Beaver Builder and Elementor. Thanks to our emphasis on WordPress coding standards, we can boast full compatibility with all well-coded plugins, including WooCommerce. GeneratePress is fully responsive, uses valid HTML/CSS, and is translated into over 25 languages by our amazing community of users. A few of our many features include 60+ color controls, powerful dynamic typography, 5 navigation locations, 5 sidebar layouts, dropdown menus (click or hover), and 9 widget areas. Learn more and check out our powerful premium version at https://generatepress.com

500K No CVEs
begin
#9
128 sites

begin

No CVEs
pub
#10
112 sites

pub

No CVEs
wporg-main-2022
#11
107 sites

wporg-main-2022

No CVEs
wporg-parent-2021
#12
107 sites

wporg-parent-2021

No CVEs
wporg-themes-2024
#13
106 sites

wporg-themes-2024

No CVEs
wporg-pattern-directory-2024
#14
105 sites

wporg-pattern-directory-2024

No CVEs
core
#15
103 sites

core

No CVEs
Vulnerable Sites

These sites on Sucuri are running outdated plugin versions with known security vulnerabilities. Domain names are partially masked for privacy.

vulnerable domains on Sucuri
DomainVulnerable Plugins
metr************.com
mic********.com
sig*********.com
tirt***********.ng
im**.academy
ipa**********.com
th***.network
wph**********.nl
ar******.com
der********.ro
kee*******.io
ww******.org
beau***********.com
com*********.it
cont************.com
kor********.com
si*****.com
un*******.com
ww******.mw
as****.com

Showing 20 of the most affected sites. Run a free audit to check if your site is affected.

Is your Sucuri site secure?

Run a free audit to check your plugins, themes, and WordPress version against our vulnerability database.