"More than half of the respondents (59%) responded that in their opinion the biggest problem in WordPress security is core, plugin, and theme vulnerabilities." considering that a WP app consists of core, plugin, and theme, results of this survey isn't very surprising.
Is there any actual meaning to it to say core, plugin, and theme, when that's all there is anyway?
@lkraav Yeah, you got a point. We usually use word "components" which would then mean core, plugins and themes, but we decided to write it this way so it's less likely to be mistaken what we mean. Also, in some cases people also say "plugins" and actually mean themes as well (aka anything that can be installed to WP site).
In your opinion, what is the biggest problem in WordPress security?
1. WP core, plugin, and theme vulnerabilities - 59%
2. Insecure passwords - 15%
3. Nulled (malicious) plugins, themes - 15%
4. Insecure hosting environment - 9%
5. And "other" where people mentioned - All of the above; not updating regularly; I don't know and so on.
So that's where the percentage comes.
Good morning Producthunt!
At Patchstack, we work on identifying and providing protection against security issues in WordPress core, plugins and themes. That's what we do, every day!
Each year, we pull together every bit of data from previous to have an in-depth overview about how WordPress ecosystem evolves in terms of security.
WordPress powers more than 43% of the web and it's safe to say that the security of its ecosystem affects every one of us.
Today, we are happy to share our whitepaper that covers everything that happened in 2021. Let's see how 2021 compares with previous year, what is improving and what needs more attention.
Some of the highlights:
- Security vulnerabilities affecting WordPress ecosystem in 2021 are up by 150% compared to previous year.
- 29% of WordPress plugins with critical security vulnerabilities received no patch!
- 99.42% of security vulnerabilities originate from Plugins and Themes (compared to 96.22% in 2020).
Check it out and let us know what you think! Yes, it's completely free :)