Skip to main content
WP HealthKit
Monthly Snapshot

WordPress Monthly Health Status

April 2026

Aggregated, anonymised data from public audits during April 2026.

All-time totals

Aggregate snapshot across every public audit we have logged.

37

Plugins Audited

697

Total Findings Logged

authentication

Most Flagged Category

-

Most Improved Month

April 2026

Headline stats for the selected month.

42

Total Audits

151

Critical Findings

authentication

Most Common Category

D

Average Risk Grade

Category trend

Top 5 categories — April 2026 vs March 2026.

  • authentication+69
    April
    79
    March
    10
  • php compatibility+38
    April
    49
    March
    11
  • csrf+42
    April
    48
    March
    6
  • xss+42
    April
    48
    March
    6
  • lifecycle+41
    April
    48
    March
    7

Top 10 Finding Categories

Where WordPress plugins struggled the most this month.

  1. 1
    authentication79 (13.4%)
  2. 2
    php compatibility49 (8.3%)
  3. 3
    csrf48 (8.1%)
  4. 4
    xss48 (8.1%)
  5. 5
    lifecycle48 (8.1%)
  6. 6
    type safety47 (8%)
  7. 7
    file security41 (7%)
  8. 8
    sqli36 (6.1%)
  9. 9
    accessibility31 (5.3%)
  10. 10
    php compat19 (3.2%)

Top 10 Plugins by Findings

Plugins with the most findings logged across all time.

#PluginFindings
1regenerate-thumbnails57
2wp-super-cache42
3bbg-confetti-preloader37
4wps-hide-login36
5coming-soon35
6swft-digital31
7swft-license28
8classic-widgets28
9swft-funnels27
10so-widgets-bundle20

Top 10 Most Common Findings

Specific issues that appeared most often across audits this month.

#FindingSeverityCount
1PHP 8.0+ Required: Named argumentsHIGH26
2PHP Version Mismatch: Declared vs RequiredHIGH21
3Missing Nonce Verification on AJAX HandlerCRITICAL6
4No plugin files provided for auditHIGH5
5Missing text domain in __() callHIGH5
6N+1 query: get_post_meta() inside foreach loopHIGH4
7Cannot assess GDPR complianceHIGH3
8Function wc_get_products not found.MEDIUM3
9Function wc_get_product not found.MEDIUM3
10Missing nonce verification in AJAX handlerCRITICAL3

Severity Breakdown

How findings broke down across severity levels.

Critical
151
25.6%
High
351
59.6%
Medium
78
13.2%
Low
2
0.3%
Info
7
1.2%

Grade Distribution

How audits scored across the WP HealthKit grading system.

A
0
B
0
C
1
1
D
16
16

Want to know how your plugin scores?

Run a free security audit and see how your plugin compares to the April 2026 averages.