Build Stories

Why WordPress Is the Most Targeted Website Platform on the Internet

WordPress runs roughly four in ten websites, which makes it the biggest target on the internet. The core software is solid — the danger is the plugins bolted onto it, the way most sites are set up, and the fact that almost nobody is watching them after launch.

Elite Performance Exclusive LLC 5 min read

WordPress is the most popular way to build a website in the world. According to W3Techs, it runs 40.2% of every website on the internet — and almost six out of ten sites that use any content management system at all.

That popularity is exactly why it is the most attacked website platform there is.

If you are a criminal writing a tool to break into websites, you don't write it for one site. You write it for the platform that runs four in ten of them. One working exploit, millions of possible targets.

Open source isn't the problem

It's worth being fair here, because WordPress gets blamed for things that aren't its fault.

WordPress itself — the core software — is open source, heavily reviewed, and well maintained. In 2025, security researchers at Patchstack recorded only six vulnerabilities in WordPress core, all of them low priority.

The trouble is everything that gets bolted onto it.

The real risk lives in the plugins

A WordPress site is rarely just WordPress. It's WordPress plus a theme, plus a page builder, plus a contact form, a slider, an SEO tool, a booking widget, a backup plugin, a security plugin, and whatever else got installed along the way. Each one is written by a different developer, to a different standard, with a different commitment to keeping it safe.

Patchstack's numbers for 2025 tell the story:

  • 11,334 new vulnerabilities were found across the WordPress ecosystem — a 42% jump on the year before.
  • 91% of them were in plugins. Another 9% were in themes.
  • 1,966 of them (17%) were high severity — the kind that get exploited in automated, mass-scale attacks.
  • 46% had no fix available from the developer by the time they were made public.
  • And once a vulnerability was known, the weighted median time to the first attack was about five hours.

Read that last point again. Five hours. Most business owners don't check their website in five hours — let alone update it.

Most WordPress sites are set up wrong

Even with trustworthy plugins, the majority of WordPress sites we see were built to launch, not to last:

  • The login page is wide open at the same address on every WordPress site in the world, with no two-factor authentication and no limit on guesses.
  • The admin account is shared — or still called "admin" — with a password that hasn't changed since launch.
  • Plugins pile up and never leave. Installed once for a feature nobody uses anymore, still running, still exposed, sometimes abandoned by the developer who wrote it.
  • "Free" premium themes and plugins from unofficial download sites, which frequently arrive with malware already inside.
  • Cheap shared hosting, where your site sits on the same server as hundreds of others — including compromised ones.
  • No backups, or backups stored on the same server that gets hacked, which means they disappear at the same moment the site does.
  • Nobody is watching. The freelancer who built it moved on. Updates pile up. The site quietly falls further behind every week.

You don't get targeted. You get found.

This is the part most owners misunderstand. Nobody is sitting down to hack your bakery or your law firm. Automated bots scan the entire internet around the clock, checking every site for a plugin version they know how to break. If yours matches, you're in — no personal grudge required.

What happens next usually looks like one of these:

  • Hidden spam pages and links injected into your site, quietly wrecking your Google rankings.
  • Visitors redirected to scam, gambling or malware pages.
  • A red "This site may be hacked" warning on Google, and browsers blocking your site outright.
  • Customer form submissions and personal data stolen.
  • Your host suspending your account until it's cleaned — with your business offline in the meantime.

If you're staying on WordPress, do this

WordPress can be run safely. It just has to be run, not just built:

  • Keep core, themes and plugins updated — promptly, not quarterly.
  • Delete every plugin and theme you don't actively use. Fewer plugins, fewer doors.
  • Only install plugins from reputable, actively maintained developers. Never "free" copies of paid ones.
  • Turn on two-factor authentication for every admin, and give everyone else the lowest access level that works.
  • Put a web application firewall in front of the site and limit login attempts.
  • Keep backups off the server, automatically, and test that they restore.
  • Monitor it, so you hear about a problem before your customers — or Google — do.

Or take the target off your back

The other option is to stop running software designed around a public plugin marketplace at all.

A hand-coded website has no plugin store, no page builder, no third-party slider written by a stranger — and so none of the 91% of vulnerabilities that come with them. It does exactly what your business needs and nothing else, which means there is far less to attack. And because you own the code, there's always something to back up and restore.

That's how we build: owned, hand-coded websites and web applications, hardened before launch, and looked after once they're live. If you already run WordPress and want to know where you stand, our security hardening work starts with finding the holes before someone else does.

The bottom line

WordPress isn't dangerous because it's open source. It's dangerous because it's popular, because its plugins are where the vulnerabilities live, and because most sites are set up once and never looked at again.

The fix is the same either way: fewer moving parts, real security from day one, and someone whose job it is to keep watching.

Want a straight answer on how exposed your site is? Get a tech quote or read about our security hardening.

Sources: W3Techs — Usage statistics of WordPress (30 September 2026); Patchstack — State of WordPress Security in 2026 (2025 data).

Share X LinkedIn Facebook

Want a result like this?

Engineering wins, build breakdowns, and lessons from shipping scalable apps — iOS, Android, and web.

Get a Tech Quote