Skip to main content
WP HealthKit
Live data · updated hourly

WordPress Plugin Security Trends

What's broken in WordPress.org plugins right now, by the numbers. Aggregate findings from 500 independent audits across the last 6 days of audits.

Headline
20%
of plugins ship with at least one CRITICAL finding
First-pass audit, no remediation applied
Headline
98%
ship with at least one HIGH-severity issue
Includes XSS, missing nonces, capability gaps
Headline
2%
contain hardcoded secrets or API keys
Tokens / passwords / credentials in source
Headline
6%
bundle dependencies with known CVEs
Composer / npm vulnerabilities at audit time

Most common finding categories

% of audited plugins that ship with at least one finding in each category. Multiple categories can apply to the same plugin.

CategoryPrevalence
security99.8%
WordPress Compatibility99.8%
Coding Standards99.6%
Dependencies93.8%
Type Safety90.6%
Performance73.4%
PHP Compatibility60.6%
Plugin Lifecycle59.4%
hook-wiring57.2%
Theme Standards56.4%
Plugin Conflicts54.4%
Internationalization47.0%

Grade distribution

Distribution of overall security grades across the sample. Most plugins land between B and D on first audit.

A
0.0%
0 plugins
B
0.0%
0 plugins
C
50.0%
2 plugins
D
50.0%
2 plugins
F
0.0%
0 plugins

Methodology

Statistics are computed from the last 500 public, completed plugin audits run by WP HealthKit. Each audit runs a multi-engine pipeline including deterministic scanners (Wordfence CVE database, OSV, PHPCS, PHPStan, Semgrep, Psalm, hardcoded-secret detection across 22 patterns) and AI-powered analysis for security, code quality, and accessibility. A 500-audit sample is more than enough for prevalence percentages to stabilise within a percentage point or two.

“Prevalence” measures the percentage of plugins that contain at least one finding in a given category. A single plugin can contribute to multiple category counts but contributes at most once per category, so the percentages don't sum to 100.

Cached at 1-hour granularity. Re-audits are deduplicated by plugin slug (we count each plugin's most recent audit, not historical re-audits).

Want to cite this data? Link to wphealthkit.com/stats/trends. Released under CC-BY 4.0 — attribution requested but not enforced. Email [email protected] if you need raw figures or want to discuss methodology.

Want to know where your plugin sits in these numbers?

Free audit — no signup required to see your overall score and headline findings.

Run a free audit