Skip to main content
WP HealthKit
Monthly Snapshot

WordPress Monthly Health Status

March 2026

Aggregated, anonymised data from public audits during March 2026.

All-time totals

Aggregate snapshot across every public audit we have logged.

37

Plugins Audited

697

Total Findings Logged

authentication

Most Flagged Category

-

Most Improved Month

March 2026

Headline stats for the selected month.

8

Total Audits

3

Critical Findings

accessibility

Most Common Category

-

Average Risk Grade

Category trend

Top 5 categories — March 2026 vs February 2026.

  • accessibility+16
    March
    16
    February
    0
  • php compatibility+11
    March
    11
    February
    0
  • coding standards+10
    March
    10
    February
    0
  • authentication+10
    March
    10
    February
    0
  • lifecycle+7
    March
    7
    February
    0

Top 10 Finding Categories

Where WordPress plugins struggled the most this month.

  1. 1
    accessibility16 (14.8%)
  2. 2
    php compatibility11 (10.2%)
  3. 3
    coding standards10 (9.3%)
  4. 4
    authentication10 (9.3%)
  5. 5
    lifecycle7 (6.5%)
  6. 6
    performance6 (5.6%)
  7. 7
    csrf6 (5.6%)
  8. 8
    xss6 (5.6%)
  9. 9
    php compat6 (5.6%)
  10. 10
    wp compatibility5 (4.6%)

Top 10 Plugins by Findings

Plugins with the most findings logged across all time.

#PluginFindings
1regenerate-thumbnails57
2wp-super-cache42
3bbg-confetti-preloader37
4wps-hide-login36
5coming-soon35
6swft-digital31
7swft-license28
8classic-widgets28
9swft-funnels27
10so-widgets-bundle20

Top 10 Most Common Findings

Specific issues that appeared most often across audits this month.

#FindingSeverityCount
1PHP Version Mismatch: Declared vs RequiredHIGH5
2PHP 8.0+ Required: Named argumentsHIGH4
3Deprecated: get_settings() (since WP 2.1)HIGH1
4Version mismatch: declares WP 4.9+ but uses WP 5.0+ functionsHIGH1
5Deprecated: block_editor_settings filter (since WP 5.9)MEDIUM1
6Missing 'Tested up to' headerMEDIUM1
7Direct superglobal access without sanitization wrapperLOW1
8Direct superglobal access patternLOW1
9Direct superglobal access in multiple locationsLOW1
10Direct superglobal access in get_edit_post_linkLOW1

Severity Breakdown

How findings broke down across severity levels.

Critical
3
2.8%
High
48
44.4%
Medium
20
18.5%
Low
24
22.2%
Info
13
12.0%

Grade Distribution

How audits scored across the WP HealthKit grading system.

A
0
B
0
C
0
D
0

Want to know how your plugin scores?

Run a free security audit and see how your plugin compares to the March 2026 averages.