Skip to main content
WP HealthKit
The ecosystem health report

WordPress security, measured weekly.

Vulnerability trends, plugin adoption, PHP version distribution, and CRA readiness — computed from every audit in the public corpus, updated as new audits land.

Computed from public auditsRefreshed continuouslyMethodology included
Ecosystem Report

WordPress Ecosystem Health Report

Aggregate security and code quality statistics across all publicly audited WordPress plugins and themes.

Last updated: Aug 20, 2026, 01:46 AM

Plugins Audited
981
Themes Audited
0
Avg Standards Score
0/100
Known CVEs Found
0
Total Audits
1000
Avg Findings / Audit
105.3
Secrets Detected
0
Total Plugins + Themes
981

Risk Distribution

How audited plugins and themes are distributed across risk levels.

Critical190(19%)
High792(79.2%)
Medium18(1.8%)
Low0(0%)

Weekly Trends

Audit activity and quality trends over the last 12 weeks.

Audits per weekAvg standards score
W32W33W3457501000
WeekAuditsAvg RiskAvg ScoreTrend
2026-W321563.20
2026-W335753.20
2026-W342693.20

Audit your plugin and join the leaderboard

Get a comprehensive security, quality, and accessibility audit for your WordPress plugin or theme. Results appear on the public directory and leaderboard.

Start Free Audit
Methodology

Figures are computed from completed, publicly-listed audits in the WP HealthKit corpus. Prevalence percentages are the share of audits with at least one finding in the class. Trend windows are trailing 30/90 days; the sample size is printed on every chart. This is measurement, not modeling — no projections, no estimates beyond the data itself.