WP Engine

WP Engine

Managed WordPresswpengine.com

Premium managed WordPress hosting with built-in performance and security tools.

39K
WordPress Sites Tracked on WP Engine
39K
Sites Detected
3.8
Avg Plugins / Site
+2.0 vs avg
12K
Vuln Exposure
sites with outdated plugins
44 / 50
Plugins with CVEs
all patched
WordPress Versions
6.9.1
2K44.6%
6.9.4
61717.6%
6.8.3
2878.2%
6.8.1
1273.6%
6.9
1123.2%
6.9.3
922.6%
6.7.4
782.2%
6.8.5
742.1%
6.8.2
541.5%
6.6.4
310.9%
6.5.7
300.9%
6.7.2
270.8%
6.7.5
270.8%
6.4.7
220.6%
6.2.8
180.5%

Summary

Most Common
6.9.1
Version Coverage
9%
of sites have detectable WP version
Unique Versions
121
Most Popular Plugins
Top 50

Vulnerable Version Usage

Sites running outdated (vulnerable) vs safe versions of top plugins

Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder90.2% vulnerable
The Events Calendar84.7% vulnerable
Elementor Website Builder – more than just a page builder80.6% vulnerable
Genesis Blocks75% vulnerable
Jetpack – WP Security, Backup, Speed, & Growth37.2% vulnerable
Max Mega Menu31.4% vulnerable
Spam protection, Honeypot, Anti-Spam by CleanTalk31.3% vulnerable
Contact Form 729.9% vulnerable

Plugin Security Overview

Breakdown of 50 most popular plugins on WP Engine

50plugins
No known CVEs6
CVEs (all patched)44
Unpatched CVEs0
Est. exposed sites
12K
plugins on WP Engine — sorted by prevalence
#PluginCVEs
1
SlideShow Press
0
2
Meta Generator and Version Info Remover
0
320
Version distribution on WP Engine (274 versions detected)
3.5.1
1621.5%
1.12.14
540.5%vuln
2.1.0
530.5%
2.12.17
440.4%
6.9.1
320.3%
19.5.1
260.2%
2.9.10
210.2%
8.4.7
120.1%
2.12.16
110.1%
2.12.15
100.1%
+264 more versions
447
5
Contact Form 7
8
6
Genesis Blocks
4
72
826
9
The Events Calendar
25
1010
111
124
131
1413
1524
163
1723
182
19
Ultimate Addons for Elementor
12
209
Most Popular Themes
Hello Elementor
#1
4K sites

Hello Elementor

by elemntor

Hello Elementor is a lightweight and minimalist WordPress theme that was built specifically to work seamlessly with the Elementor site builder plugin. The theme is free, open-source, and designed for users who want a flexible, easy-to-use, and customizable website. The theme, which is optimized for performance, provides a solid foundation for users to build their own unique designs using the Elementor drag-and-drop site builder. Its simplicity and flexibility make it a great choice for both beginners and experienced Web Creators.

1.0M 1 CVE
Astra
#2
2K sites

Astra

by brainstormforce

The Astra WordPress theme is lightning-fast and highly customizable. It has over 1 million downloads and the only theme in the world with 6,000+ five-star reviews! It’s ideal for professional web designers, solopreneurs, small businesses, eCommerce, membership sites and any type of website. It offers special features and templates so it works perfectly with all page builders like Spectra, Elementor, Beaver Builder, etc. Fast performance, clean code, mobile-first design and schema markup are all built-in, making the theme exceptionally SEO-friendly. It’s fully compatible with WooCommerce, SureCart and other eCommerce plugins and comes with lots of store-friendly features and templates. Astra also provides expert support for free users. A dedicated team of fully trained WordPress experts are on hand to help with every aspect of the theme. Try the live demo of Astra: https://zipwp.org/themes/astra/

1.0M 3 CVEs
hello-theme-child-master
#3
791 sites

hello-theme-child-master

No CVEs
salient
#4
680 sites

salient

2 CVEs
bb-theme
#5
564 sites

bb-theme

No CVEs
genesis
#6
553 sites

genesis

1 CVE
divi-child
#7
537 sites

divi-child

No CVEs
genesis-block-theme
#8
438 sites

genesis-block-theme

No CVEs
enfold
#9
429 sites

enfold

1 unpatched
GeneratePress
#10
385 sites

GeneratePress

by edge22

GeneratePress is a lightweight WordPress theme built with a focus on speed and usability. Performance is important to us, which is why a fresh GeneratePress install adds less than 10kb (gzipped) to your page size. We take full advantage of the block editor (Gutenberg), which gives you more control over creating your content. If you use page builders, GeneratePress is the right theme for you. It is completely compatible with all major page builders, including Beaver Builder and Elementor. Thanks to our emphasis on WordPress coding standards, we can boast full compatibility with all well-coded plugins, including WooCommerce. GeneratePress is fully responsive, uses valid HTML/CSS, and is translated into over 25 languages by our amazing community of users. A few of our many features include 60+ color controls, powerful dynamic typography, 5 navigation locations, 5 sidebar layouts, dropdown menus (click or hover), and 9 widget areas. Learn more and check out our powerful premium version at https://generatepress.com

500K No CVEs
bb-theme-child
#11
375 sites

bb-theme-child

No CVEs
Kadence
#12
363 sites

Kadence

by stellarwp

Kadence Theme is a lightweight yet full featured WordPress theme for creating beautiful fast loading and accessible websites, easier than ever. It features an easy to use drag and drop header and footer builder to build any type of header in minutes. It features a full library of gorgeous starter templates that are easy to modify with our intelligent global font and color controls. With extensive integration with the most popular 3rd party plugins, you can quickly build impressive ecommerce websites, course websites, business websites, and more.

400K No CVEs
astra-child
#13
348 sites

astra-child

No CVEs
hello-elementor-child
#14
337 sites

hello-elementor-child

No CVEs
flatsome
#15
316 sites

flatsome

4 CVEs
Vulnerable Sites

These sites on WP Engine are running outdated plugin versions with known security vulnerabilities. Domain names are partially masked for privacy.

vulnerable domains on WP Engine
DomainVulnerable Plugins
www2****************.mx
prof******************.com
sie*******.shop
sunn************.com
te*****.work
www*******.com
gre********.com
li******.io
theb***********.com
vict****************.com
theg*********************.com
wh***.inc
www.****************.com
dh****.com
jeff**********************.uk
ut***.com
www.********************.com
aw******.com
cici************.com
disc********************.com

Showing 20 of the most affected sites. Run a free audit to check if your site is affected.

Is your WP Engine site secure?

Run a free audit to check your plugins, themes, and WordPress version against our vulnerability database.