WordPress.com

WordPress.com

Managed WordPresswordpress.com

Automattic's hosted WordPress platform serving millions of sites.

1.5M
WordPress Sites Tracked on WordPress.com
1.5M
Sites Detected
4.2
Avg Plugins / Site
+2.4 vs avg
557K
Vuln Exposure
sites with outdated plugins
46 / 50
Plugins with CVEs
all patched
WordPress Versions
6.9.1
267K33.4%
6.9.4
153K19.1%
6.8.3
55K6.9%
6.8.5
26K3.2%
6.9.3
23K2.8%
6.7.4
17K2.1%
6.9
15K1.9%
6.0.11
10K1.2%
6.7.5
10K1.2%
6.2.8
10K1.2%
6.4.7
9K1.1%
6.6.4
9K1.1%
6.1.9
8K1.0%
6.5.7
8K0.9%
4.9.26
6K0.8%

Summary

Most Common
6.9.1
Version Coverage
55%
of sites have detectable WP version
Unique Versions
815
Most Popular Plugins
Top 50

Vulnerable Version Usage

Sites running outdated (vulnerable) vs safe versions of top plugins

Complianz – GDPR/CCPA Cookie Consent100% vulnerable
The Events Calendar81.6% vulnerable
WooPayments: Integrated WooCommerce Payments79.3% vulnerable
Elementor Website Builder – more than just a page builder65% vulnerable
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More51.1% vulnerable
Jetpack – WP Security, Backup, Speed, & Growth49.2% vulnerable
Contact Form 741.2% vulnerable
TablePress – Tables in WordPress made easy41% vulnerable

Plugin Security Overview

Breakdown of 50 most popular plugins on WordPress.com

50plugins
No known CVEs4
CVEs (all patched)46
Unpatched CVEs0
Est. exposed sites
557K
plugins on WordPress.com — sorted by prevalence
#PluginCVEs
1
SlideShow Press
0
224
Version distribution on WordPress.com (1080 versions detected)
15.6
120K23.3%
3.1
19K3.8%vuln
15.5
13K2.4%
14.8
10K1.9%
15.4
7K1.4%
15.3.1
7K1.3%
12.8.2
4K0.7%vuln
12.5.1
3K0.6%vuln
12.0.2
3K0.6%vuln
4.6.2
3K0.5%vuln
+1070 more versions
320
4
Meta Generator and Version Info Remover
0
5
Contact Form 7
8
647
72
826
94
1010
111
121
137
1410
1514
16
WooCommerce Stripe Payment Gateway
4
17
The Events Calendar
25
189
19
Ultimate Addons for Elementor
12
206
Most Popular Themes
Astra
#1
54K sites

Astra

by brainstormforce

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/

1.0M 3 CVEs
Hello Elementor
#2
43K sites

Hello Elementor

by elemntor

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

1.0M 1 CVE
cocoon-master
#3
28K sites

cocoon-master

No CVEs
GeneratePress
#4
18K sites

GeneratePress

by edge22

GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performance is important to us, which is why a fresh GeneratePress install adds less than 10kb (gzipped) to your page size. We take full advantage of the block editor (Gutenberg), which gives you more control over creating your content. If you use page builders, GeneratePress is the right theme for you. It is completely compatible with all major page builders, including Beaver Builder and Elementor. Thanks to our emphasis on WordPress coding standards, we can boast full compatibility with all well-coded plugins, including WooCommerce. GeneratePress is fully responsive, uses valid HTML/CSS, and is translated into over 25 languages by our amazing community of users. A few of our many features include 60+ color controls, powerful dynamic typography, 5 navigation locations, 5 sidebar layouts, dropdown menus (click or hover), and 9 widget areas. Learn more and check out our powerful premium version at https://generatepress.com

500K No CVEs
cocoon-child-master
#5
17K sites

cocoon-child-master

No CVEs
Twenty Seventeen
#6
16K sites

Twenty Seventeen

by wordpressdotorg

Twenty Seventeen brings your site to life with header video and immersive featured images. With a focus on business sites, it features multiple sections on the front page as well as widgets, navigation and social menus, a logo, and more. Personalize its asymmetrical grid with a custom color scheme and showcase your multimedia content with post formats. Our default theme for 2017 works great in many languages, for any abilities, and on any device.

300K No CVEs
flatsome
#7
14K sites

flatsome

4 CVEs
OceanWP
#8
13K sites

OceanWP

by oceanwp

OceanWP is the perfect theme for your project. Lightweight and highly extendable, it will enable you to create almost any type of website such a blog, portfolio, business website and WooCommerce storefront with a beautiful & professional design. Very fast, responsive, RTL & translation ready, best SEO practices, unique WooCommerce features to increase conversion and much more. You can even edit the settings on tablet & mobile so your site looks good on every device. Work with the most popular page builders as Elementor, Beaver Builder, Brizy, Visual Composer, Divi, SiteOrigin, etc... Developers will love his extensible codebase making it a joy to customize and extend. Best friend of Elementor & WooCommerce. Looking for a Multi-Purpose theme? Look no further! Check the demos to realize that it's the only theme you will ever need: https://oceanwp.org/demos/

500K 5 CVEs
Kadence
#9
12K sites

Kadence

by stellarwp

Kadence Theme is a lightweight yet full featured WordPress theme for creating beautiful fast loading and accessible websites, easier than ever. It features an easy to use drag and drop header and footer builder to build any type of header in minutes. It features a full library of gorgeous starter templates that are easy to modify with our intelligent global font and color controls. With extensive integration with the most popular 3rd party plugins, you can quickly build impressive ecommerce websites, course websites, business websites, and more.

400K No CVEs
genesis
#10
10K sites

genesis

1 CVE
Storefront
#11
9K sites

Storefront

by automattic

Storefront is the perfect theme for your next WooCommerce project. Designed and developed by WooCommerce Core developers, it features a bespoke integration with WooCommerce itself plus many of the most popular customer facing WooCommerce extensions. There are several layout & color options to personalise your shop, multiple widget regions, a responsive design and much more. Developers will love its lean and extensible codebase making it a joy to customize and extend. Looking for a WooCommerce theme? Look no further!

100K No CVEs
enfold
#12
9K sites

enfold

1 unpatched
Blocksy
#13
8K sites

Blocksy

by creativethemeshq

Blocksy is a fast, modern WordPress theme with advanced WooCommerce support and full compatibility with the block editor.

300K 12 CVEs
Neve
#14
8K sites

Neve

by themeisle

Neve is a next-generation, ultra-fast WordPress theme designed for top performance, SEO, and Core Web Vitals. Its lightweight codebase and small size ensure minimal overhead and lightning-fast load times. Fully compatible with the block editor, popular page builders (Elementor, Bricks, Oxygen etc), and WooCommerce, it’s perfect for blogs, small businesses, agencies, portfolios, and online stores. With responsive design, multilingual translations, and easy customization options, Neve empowers you to create a future-proof, high-ranking online presence. Discover everything Neve has to offer and explore our powerful premium version at https://themeisle.com/themes/neve/.

200K No CVEs
Twenty Sixteen
#15
8K sites

Twenty Sixteen

by wordpressdotorg

Twenty Sixteen is a modernized take on an ever-popular WordPress layout — the horizontal masthead with an optional right sidebar that works perfectly for blogs and websites. It has custom color options with beautiful default color schemes, a harmonious fluid grid using a mobile-first approach, and impeccable polish in every detail. Twenty Sixteen will make your WordPress look beautiful everywhere.

100K No CVEs
Vulnerable Sites

These sites on WordPress.com are running outdated plugin versions with known security vulnerabilities. Domain names are partially masked for privacy.

vulnerable domains on WordPress.com
DomainVulnerable Plugins
www3*******************.org
gre**********.com
mika************.jp
lite***********.hk
acad*************************.com
cand**********.com
ww******.it
ar******.fr
d.r********.com
hom**********.edu
feed*************.com
nor********.dk
www*********.eu

Showing 13 of the most affected sites. Run a free audit to check if your site is affected.

Is your WordPress.com site secure?

Run a free audit to check your plugins, themes, and WordPress version against our vulnerability database.