Quick Route

What do you need today?

Choose the closest route and see the most useful pages straight away.

Protect

Stop small WordPress problems becoming business problems.

Maintenance, security, monitoring, backups and practical protection for websites that need to keep working.

Grow

Launch better, improve what you already have and generate more enquiries.

Website packages, ongoing growth support and useful interactive tools for businesses that want their website to do more.

Partner

Agency support without growing your internal support team.

Silent support, overflow help and white label WordPress maintenance for client websites.

Industries

Find the page that fits how your business uses its website.

Twenty sector-specific WordPress support pages, grouped by the way each website earns trust, enquiries, bookings or sales.

Pricing

Plans, fixes and add-ons without making it a puzzle.

Find the right route for ongoing protection, hosting or emergency work.

WordPress Security Research

What WordPress Security Data Reveals About Business Website Risk In 2026

Most business owners assume website problems happen to somebody else. The latest WordPress security data says otherwise. We reviewed research from W3Techs, Patchstack and Wordfence to see where business websites are most exposed.

Joe York
Written by Joe York Founder, PressGuard
Reading time: 18 minutes
Updated June 2026

A business website can look fine from the outside while carrying serious risk behind the scenes. That is the uncomfortable bit.

The homepage loads. The contact form appears. The logo is still in the right place. Nobody in the office is panicking.

So the website gets left alone.

Then something breaks. A form stops sending leads. A plugin update causes a layout issue. The website starts redirecting visitors. Google shows a warning. The business suddenly cares deeply about website maintenance. Funny how that happens.

This article looks at real industry data, not guesswork. We reviewed current WordPress usage figures, PHP version data and security reports from leading WordPress security sources. The aim is simple. To explain what the numbers mean for ordinary business owners.

This is not written for developers. It is for people who rely on their website but do not want to live inside it. That is entirely reasonable. Most people opened a business, not a plugin museum.

The short answer

WordPress remains the most used content management system on the web. That popularity makes it useful, flexible and well supported. It also means plugins, themes and outdated setups attract constant attention from attackers.

The biggest risks are rarely dramatic. They are usually missed updates, old PHP versions, abandoned plugins, weak access control and poor recovery planning.

Why This Data Matters

Website risk is often discussed in vague terms. People talk about hackers, malware and security without explaining the practical business problem.

The practical problem is simpler. Your website may be more exposed than you think.

That exposure does not always come from one obvious mistake. It often builds slowly. One old plugin. One weak password. One unsupported PHP version. One backup nobody has tested. One form plugin nobody has checked since the website went live.

None of these sound exciting. That is why they get ignored.

Yet this is where many real problems start. The boring jobs are often the important ones. They rarely get applause, which is harsh but true.

WordPress Is Huge, So Attackers Pay Attention

According to W3Techs WordPress usage data, WordPress is used by 41.9% of all websites. It also holds 59.4% of the market among websites with a known content management system.

That is a huge share of the public web. It explains why WordPress has such a large ecosystem. There are thousands of plugins, themes, developers, hosts and specialist tools.

For businesses, that is part of the appeal. WordPress can run a brochure site, a booking website, a membership platform or an online shop. It can be extended without rebuilding everything from scratch.

The same popularity also creates attention. Attackers do not need to invent a new method for every website. They can scan for known weaknesses at scale.

That does not mean WordPress is bad. It means WordPress needs ownership. A popular platform with poor maintenance becomes a soft target. A maintained website is a different story.

Reality Check

WordPress is not the problem. Neglect is usually the problem.

Most business website risk comes from how WordPress is managed after launch. The platform is only one part of the picture.

A website needs updates, monitoring, backups, access control and recovery planning. Without those, small problems can sit unnoticed.

What The Patchstack Data Shows

Patchstack publishes detailed research on vulnerabilities across the WordPress ecosystem. Its State of WordPress Security in 2026 report gives a clear warning.

Patchstack reported that 91% of new vulnerabilities were found in plugins. A further 9% were found in themes. Only six vulnerabilities were reported in WordPress core, and those were low priority issues.

That matters because many business owners think of “WordPress security” as one thing. In practice, the risk often comes from the parts added to the website.

Plugins handle forms, SEO, sliders, booking systems, ecommerce, galleries, caching, page building and memberships. Themes control design and layout. Together, they make WordPress useful. They also need care.

A business website might have twenty plugins installed. Some are essential. Some were added for a single feature years ago. Some are inactive. Some are no longer maintained. Some were installed by a developer nobody can contact now.

This is where the risk builds. Not because anyone did anything wildly reckless. More often, nobody was given the job of checking.

Plugins create most exposure

Patchstack’s 2026 report found most new vulnerabilities came from plugins. That makes plugin review a core maintenance task.

Themes still matter

Themes can also contain vulnerabilities. Old commercial themes are easy to forget once the design looks finished.

WordPress core is not the main issue

The core platform is actively maintained. Risk often appears around the wider setup.

Ownership matters

Someone needs to know what is installed, why it exists and whether it is still safe to use.

Why Plugin Risk Is So Common

Plugins are useful because they solve business problems quickly. Need a form? Install a plugin. Need bookings? Install a plugin. Need payment features? Install another plugin.

That is not wrong. It is one of the reasons WordPress works well for businesses.

The problem starts when plugins are treated like one time additions. They are not. They are software. Software changes. Vulnerabilities are found. Developers release fixes. Sometimes developers stop maintaining the plugin completely.

A plugin that was fine two years ago may not be fine today. That does not mean the original developer was careless. It means websites need review.

Business owners often see updates as a nuisance. That is understandable. Updates can break things. A form can change. A layout can shift. A checkout can stop behaving.

So updates get postponed. Then postponed again. Then the dashboard becomes a red badge collection. Very festive, but not ideal.

This is why WordPress maintenance should not mean blindly clicking update buttons. Updates need checking, sequencing and a recovery route.

Wordfence Shows How Fast Vulnerabilities Keep Appearing

Wordfence also publishes regular vulnerability reports through Wordfence Intelligence. These reports show how constant the issue is.

In its weekly report for 18 May to 24 May 2026, Wordfence listed 101 vulnerabilities. Those vulnerabilities affected 88 WordPress plugins and one WordPress theme.

This is only one weekly report. It shows how quickly the vulnerability picture can change.

A website can be reasonably safe one week and more exposed the next. That is why maintenance needs to be ongoing. Not dramatic. Not panicked. Just consistent.

For a business, the issue is not whether every vulnerability affects your exact website. Most will not. The issue is whether anyone is checking.

What this means in plain English

New WordPress plugin and theme vulnerabilities appear regularly. Your website does not need every update instantly. It does need someone checking whether any update affects security, stability or business function.

PHP Versions Are Still A Business Risk

WordPress runs on PHP. Most business owners never need to think about PHP. That is fine until the version becomes old, unsupported or incompatible.

According to W3Techs PHP usage data, PHP 8 is used by 60.4% of websites using PHP. PHP 7 is still used by 31.2%. PHP 5 is still used by 8.3%.

Those figures matter because old PHP versions can affect security, speed and compatibility. They can also stop newer plugins and themes working as expected.

This is where many older business websites get stuck. The site was built years ago. The hosting kept running. Nobody wanted to touch it because it still loaded. Then a plugin needs a newer PHP version. Or the host forces an upgrade. Or a security issue appears.

At that point, a small maintenance job becomes a bigger recovery job. Nobody enjoys that meeting.

Why Old PHP Versions Cause Problems

PHP version issues are often hidden from the business owner. They do not always show on the public website. The site may load, take enquiries and appear fine.

Behind the scenes, old PHP can cause several problems.

  • Newer plugins may not support the old version.
  • Security fixes may no longer be available.
  • The website may run slower than needed.
  • Updates may fail or create errors.
  • Developers may need extra time to work safely.
  • Hosting support may be limited.

This is why PHP should be checked before major WordPress updates. It is also why older websites need a maintenance review before changes are made.

A PHP upgrade is not always difficult. But it should not be treated as a random switch. The website needs checking before and after the change.

Business Risk

A website can be live and still be technically fragile.

An old PHP version may not be visible to customers. It can still affect security, updates and future support.

That is why hidden technical debt needs checking before it becomes urgent.

Security Is Not Just About Stopping Hackers

The word security makes people think about hackers. That is part of it, but not the whole issue.

Website security also protects enquiries, sales, trust, search visibility and business continuity. A compromised website can affect all of them.

A hacked website may redirect visitors to another site. It may create spam pages. It may send malicious emails. It may hide links for search engines. It may create admin users. It may damage your domain reputation.

Sometimes the website does not even go offline. That can make the problem harder to spot. The business owner sees the homepage and assumes all is fine. Search engines may see something else entirely.

This is why monitoring matters. A website needs more than someone checking it when they remember. Memory is not a system. It is a polite way to lose track.

What Business Owners Usually Miss

Most business owners do not ignore website risk because they are careless. They ignore it because the risk is not obvious.

You can see a broken image. You can see a missing phone number. You can see if the homepage looks terrible. You cannot always see outdated PHP, vulnerable plugins or weak admin access.

That creates a false sense of safety. The site looks normal, so it feels normal.

This is why business websites need regular technical review. Not a huge audit every few years. A steady routine is usually better.

Backups are assumed

Many businesses think backups exist. Fewer know where they are, how often they run or whether they restore cleanly.

Forms are forgotten

A form can fail silently. That means leads can be lost without anyone noticing quickly.

Admin users pile up

Old developers, staff and agencies may still have access. Access should be reviewed regularly.

Old plugins stay installed

Inactive does not always mean harmless. Unused plugins and themes should be removed when safe.

Backups Are Important, But They Are Not A Recovery Plan

Backups are essential. No sensible person argues otherwise.

The mistake is assuming that having backups solves every website problem. It does not.

A backup helps if it is recent, clean and restorable. Those three words do a lot of work.

A backup from last month may not help a busy ecommerce store. A backup containing malware may restore the same problem. A backup nobody can access is not much use. A backup that has never been tested is a hope with a filename.

For business websites, recovery planning matters. You need to know what happens if the website goes down, gets hacked or breaks after an update.

That includes who responds, what access they need, where backups live and how long recovery might take.

This is why PressGuard treats backups as one layer. They sit alongside updates, monitoring, access review and WordPress security hardening.

SSL Is Usually Visible, But Still Worth Checking

SSL is the padlock in the browser. It helps secure data between the visitor and the website. It is also expected by modern browsers and customers.

Most businesses now understand that a website should use HTTPS. That is good.

The problem is that SSL is sometimes treated as the whole security conversation. It is not.

SSL does not update plugins. It does not remove malware. It does not protect weak passwords. It does not check backups. It does not stop a vulnerable plugin being exploited.

SSL matters, but it is one piece. A padlock on a poorly maintained website can still leave the business exposed.

The Real Cost Is Often Lost Trust

Website risk is often judged by repair cost. That is too narrow.

The larger cost can be lost trust. A customer who sees a warning message may leave. A buyer who cannot complete checkout may not try again. A lead who submits a form and gets no reply may phone someone else.

The business may never know that enquiry existed. That is the painful bit.

For service businesses, one missed enquiry can matter. For ecommerce stores, a checkout problem can affect revenue immediately. For agencies, one maintenance failure can damage the client relationship.

This is why website care is not just technical housekeeping. It is business protection.

The simple test

Ask one question. What would happen if your website stopped working tomorrow morning?

If nobody knows who would fix it, where backups are, or what changed recently, the risk is already too high.

Why Agencies Should Pay Attention Too

This article is not only for business owners. Agencies should care about these numbers as well.

Many agencies build websites but do not have a strong maintenance process. Some offer maintenance but underprice it. Some include updates as a favour. Some rely on developers fitting support around project work.

That approach works until something breaks at the wrong moment. Then the agency loses margin, time and patience. Sometimes all before lunch.

Plugin vulnerabilities, PHP issues and recovery problems do not care how busy the agency is. Clients still expect help.

This is why white label WordPress maintenance can be useful for agencies. It gives client websites a support routine without pulling senior developers away from paid work.

What A Healthy WordPress Website Looks Like

A healthy website is not one with no plugins. That is unrealistic for most businesses.

A healthy website is one where the setup is known, reviewed and supported.

The plugin list is not a mystery. The PHP version is suitable. Backups are running. Recovery has been tested. Admin access is controlled. Security monitoring is active. Updates are handled carefully.

That may sound like a lot. It is easier when handled as a routine. Problems grow when everything is left until something breaks.

Clear ownership

Someone is responsible for updates, security checks, backups and support. It is not left floating between people.

Known plugin list

Installed plugins are reviewed. Unused tools are removed when safe. Important plugins are monitored.

Suitable hosting

The hosting supports the website properly. It is fast enough, secure enough and not forgotten.

Recovery route

Backups exist, access is available and recovery steps are understood before panic begins.

What Businesses Should Check This Month

You do not need to understand every technical detail. You do need clear answers to a few practical questions.

  • What PHP version is the website using?
  • How many plugins are installed?
  • Are any plugins abandoned or unused?
  • Are updates being checked safely?
  • Are backups running daily or weekly?
  • Has a backup ever been restored successfully?
  • Who has administrator access?
  • Is two factor login enabled?
  • Is security monitoring active?
  • Who responds if the website breaks?

If those questions are difficult to answer, that is the first finding. The website lacks clear ownership.

That does not mean it is doomed. It means it needs review before the next problem lands.

How PressGuard Uses This Data

PressGuard does not use this research to scare business owners. There is enough nonsense online already.

The point is to focus on practical risk. The data shows that plugin vulnerabilities, theme issues and old PHP versions are not rare edge cases. They are everyday website management concerns.

That is why our work focuses on ongoing care. Updates, monitoring, backups, access control, hardening and emergency support all sit together.

A single tool is not enough. A website needs a process. Not a dramatic one. Just a clear, repeatable way to keep the site stable and reduce risk.

Key Findings

1. WordPress is too large to ignore

W3Techs reports that WordPress powers 41.9% of all websites. That scale makes WordPress well supported, but also heavily watched by attackers.

2. Plugin risk dominates the data

Patchstack’s 2026 report found that 91% of new vulnerabilities were in plugins. This makes plugin review one of the most important website care tasks.

3. Old PHP versions still exist across the web

W3Techs shows that PHP 7 and PHP 5 still remain in public use. Older versions can create security, speed and compatibility problems.

4. New vulnerabilities keep appearing

Wordfence listed 101 vulnerabilities in one weekly report during May 2026. This shows why website checks need to continue after launch.

5. Backups alone are not enough

Backups help recovery, but only if they are recent, clean and restorable. They do not replace maintenance or security monitoring.

External Sources Used

This article is based on public data and research from recognised WordPress and web technology sources. The links below open the original sources used.

Not sure where your website stands?

Take the 2 Minute Website Risk Assessment. It checks common maintenance, security and recovery gaps before they become expensive problems.

Frequently Asked Questions

Is WordPress safe for business websites?

Yes, WordPress can be safe for business websites. Risk usually comes from poor maintenance, weak access and outdated plugins.

Why do plugins create so much risk?

Plugins add features to WordPress. They are separate pieces of software, so they need updates, review and ongoing support.

Does SSL mean my website is secure?

No. SSL protects data between the visitor and the website. It does not update plugins, remove malware or protect weak admin access.

How often should a WordPress website be checked?

Business websites should be checked regularly. Security updates should be reviewed quickly, especially for plugins handling forms, payments or user accounts.

What is PHP, and why does it matter?

PHP is the server language WordPress runs on. Old versions can affect security, performance and compatibility with newer plugins.

Are backups enough to protect a website?

No. Backups help recovery, but they do not stop attacks or fix weak setup choices. They should be part of a wider plan.

What should I check first?

Start with updates, backups, admin users, PHP version, SSL and security monitoring. If nobody owns those tasks, start there.

How PressGuard can help

PressGuard helps businesses reduce WordPress website risk through maintenance, monitoring, security hardening, backups and emergency support.

We focus on the jobs that keep websites stable, secure and available. That means fewer surprises, fewer rushed fixes and less avoidable disruption.

If your website matters to your business, it needs more than occasional attention. It needs clear ownership and a sensible support routine.