WordPress powers over 40% of all websites on the internet. That level of market share makes it far and away the most targeted web platform by automated attacks. Here's what that actually means for you — and why it doesn't mean WordPress is uniquely insecure.
As of 2022, WordPress powers approximately 43% of all websites — not just CMS-built sites, all websites. The next closest competitor, Shopify, is at around 4%. Joomla, Drupal, and other platforms are a fraction of a percent each.
Attackers are economically rational. Building automated attack tools for WordPress gives access to a potential target pool of hundreds of millions of sites. Building the same tools for a platform with 0.5% market share is an order of magnitude less valuable. WordPress is targeted because it's everywhere — not because it's uniquely insecure.
WordPress has several characteristics that make automated targeting straightforward:
/wp-login.php) unless explicitly movedwp-generator meta tag)These characteristics allow automated scanners to identify WordPress sites, determine what version is running, check against known vulnerability databases, and launch targeted exploits — all without human involvement.
Analysis of WordPress compromises consistently shows the same attack categories:
One response to WordPress's attack surface is to use a less common platform, reasoning that attackers won't bother with a system they don't have tools for. This is security through obscurity, and it's not a reliable approach. It trades known attack vectors for unknown ones — a less-targeted platform may have fewer security researchers looking at it as well.
WordPress's massive install base means it also has a large security community: dedicated security firms like Wordfence and Sucuri, the WPScan vulnerability database, the WordPress security team, and thousands of security researchers actively finding and disclosing vulnerabilities. The ecosystem's response to vulnerabilities is typically faster and better-organised than for smaller platforms.
The things that protect a WordPress site from the automated attack landscape:
The sites that get compromised are overwhelmingly those that have skipped at least one of these. The sites that don't get compromised are the ones that have them all in place and maintain them consistently.
DownUnder WP applies server-level login protection, current PHP, and isolation for every hosted site as standard. The most common attack vectors are addressed in the hosting environment, not left to plugin configuration.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.