All posts
November 2022·6 min read

Why WordPress is still the most attacked CMS — and what that means for your site

WordPress powers over 40% of all websites on the internet. That level of market share makes it far and away the most targeted web platform by automated attacks. Here's what that actually means for you — and why it doesn't mean WordPress is uniquely insecure.

The market share problem

As of 2022, WordPress powers approximately 43% of all websites — not just CMS-built sites, all websites. The next closest competitor, Shopify, is at around 4%. Joomla, Drupal, and other platforms are a fraction of a percent each.

Attackers are economically rational. Building automated attack tools for WordPress gives access to a potential target pool of hundreds of millions of sites. Building the same tools for a platform with 0.5% market share is an order of magnitude less valuable. WordPress is targeted because it's everywhere — not because it's uniquely insecure.

How the attacks are automated

WordPress has several characteristics that make automated targeting straightforward:

  • The login form is always at the same URL (/wp-login.php) unless explicitly moved
  • WordPress version information has historically been visible in page source code (the wp-generator meta tag)
  • Plugin names and versions are often discoverable from page source and HTTP headers
  • The REST API exposes user information by default

These characteristics allow automated scanners to identify WordPress sites, determine what version is running, check against known vulnerability databases, and launch targeted exploits — all without human involvement.

What's actually exploited

Analysis of WordPress compromises consistently shows the same attack categories:

  • Vulnerable plugins and themes — the leading category, accounting for more than half of compromises. A vulnerability in a popular plugin is worth automating because of the number of sites affected.
  • Weak or reused passwords — credential stuffing with leaked credentials from other breaches, and traditional brute force against common passwords.
  • Outdated WordPress core — less common than it used to be, partly due to automatic minor updates.
  • Hosting environment vulnerabilities — server-level issues that affect all accounts on a shared host, not WordPress specifically.

The security through obscurity misconception

One response to WordPress's attack surface is to use a less common platform, reasoning that attackers won't bother with a system they don't have tools for. This is security through obscurity, and it's not a reliable approach. It trades known attack vectors for unknown ones — a less-targeted platform may have fewer security researchers looking at it as well.

WordPress's massive install base means it also has a large security community: dedicated security firms like Wordfence and Sucuri, the WPScan vulnerability database, the WordPress security team, and thousands of security researchers actively finding and disclosing vulnerabilities. The ecosystem's response to vulnerabilities is typically faster and better-organised than for smaller platforms.

What actually protects a WordPress site

The things that protect a WordPress site from the automated attack landscape:

  • Keeping WordPress core, plugins, and themes updated promptly when security releases arrive
  • Protecting wp-login.php at the server level — rate limiting at minimum, login protection via a portal ideally
  • Using strong, unique credentials on all accounts
  • Removing unused plugins and themes entirely (not just deactivating)
  • Running on a hosting environment with proper isolation and current PHP
  • Maintaining recent backups so that if something does go wrong, recovery is measured in hours not days

The sites that get compromised are overwhelmingly those that have skipped at least one of these. The sites that don't get compromised are the ones that have them all in place and maintain them consistently.


DownUnder WP applies server-level login protection, current PHP, and isolation for every hosted site as standard. The most common attack vectors are addressed in the hosting environment, not left to plugin configuration.

Australian WordPress hosting from $5/month

Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.