Skip to content
SimplerWebs - digital agency in Algiers: web design, SEO and marketing

WordPress Security: The Real Risk, With Real Numbers

Published August 26, 2026Updated October 2, 20267 min read

Un homme inquiet au téléphone regarde son ordinateur portable, l'air préoccupé - SimplerWebs
La plupart des piratages WordPress ne viennent pas de WordPress lui-même, mais d'une extension.

Photo: RDNE Stock project on Pexels

We already compared WordPress and Next.js on speed. This is the other, less pleasant topic: security, with sourced numbers.

Share this article

The problem rarely comes from WordPress itself

WordPress runs a very large share of the world's websites. Its core software is closely watched and regularly fixed by its team. Most security flaws come from somewhere else: the plugins people install on top of it.

Patchstack, a company that tracks WordPress security flaws, publishes a report every year. In 2024, 96% of the flaws it found were in plugins, 4% in themes, and only 7 flaws in WordPress core. In 2025, plugins still made up 91% of the flaws.

So a well-kept WordPress site, with a few plugins that are all up to date, doesn't carry the same risk as a site with fifteen plugins added over the years, some of them forgotten.

Why plugins are the weak spot

There are tens of thousands of WordPress plugins, made by very different teams. Some are serious and looked after. Others were abandoned years ago.

According to the same Patchstack report, 43% of the flaws found in 2024 could be used without having an account on the site. That makes them easy to exploit in bulk: a bot tries them on thousands of sites at once. Nobody has to be after your site in particular for it to get hit.

The risk also grows with time. The older a site gets, the more plugins it collects, and the harder it becomes to know which ones are still needed and which ones are up to date.

What a hack really costs

With specialist services, just cleaning up a hacked site costs anywhere from a few hundred to a few thousand dollars, depending on how bad it is. And that is only part of the bill.

Add the days when the site is offline and no customer can find you, the Google visits you lose if the site gets flagged as dangerous, and the time spent putting everything back in order. Then there is the trust you lose when a customer opens your site and lands on a suspicious redirect or an error message.

A worried man on the phone looks at his laptop, looking concerned - SimplerWebs
Fixing a hacked site almost always costs more than expected, in money and time.

No need to panic: just know what's running on your site

WordPress is still a good tool. Plenty of WordPress sites run for years without ever being hacked. The question to ask is simple: does anyone know what's installed on the site, and is someone really keeping it up to date?

A site left alone for years, with plugins nobody maintains anymore, is at real risk. A site that someone checks regularly is at much less.

If you already have a WordPress site

  • Keep as few plugins as you can. Every extra plugin is one more door to watch.
  • Update WordPress, the theme and every plugin as soon as an update comes out, not once a year.
  • Delete plugins and themes you no longer use. Deactivating them isn't enough.
  • Use a unique, strong password for the admin area, never one you already use somewhere else.

How we choose the technology for a new site

As we said in our WordPress vs Next.js comparison, WordPress is still a good choice for some projects, especially if you want to edit your content yourself, and we build with it too. For most of the sites we deliver, we choose Next.js. Speed comes first, then security: with fewer third-party plugins to watch, there are fewer doors to keep shut.

In the end it's a practical question: how much time will someone have to spend each month watching what runs on your site to keep it safe?

How SimplerWebs can help

  • Website maintenance: we keep your site up to date and watch for signs of trouble before they turn into a hack.
  • Website redesign: if your WordPress site has aged and collected forgotten plugins, we look with you at what is worth keeping.
  • Custom website: for a new project, we start from a clean base that won't need hours of watching.

In short

WordPress security flaws mostly come from plugins, and the risk grows if nobody keeps an eye on what runs on the site. Fixing a hacked site often costs more, in money and time, than looking after it regularly.

Not sure where your current site stands? We can look at it with you.

Frequently asked questions

Is WordPress dangerous by itself?

No. The core software is well looked after. Most flaws come from the plugins installed on it: 96% of the WordPress flaws Patchstack recorded in 2024.

How many plugins is too many?

There is no set number. For each plugin, ask two questions instead: is it still used, and is it up to date? If the answer is no, delete it.

Do I need to drop WordPress to be safe?

Not necessarily. A well-kept WordPress site with a few up-to-date plugins is a reasonable choice. We recommend Next.js for most of our new projects, but WordPress is still a valid option.

How do I know if my WordPress site is at risk?

Start by checking how many plugins are installed, whether they're up to date, and whether you still know what each one is for. Our SEO audit also reviews the technical state of your site.

What do I do if my site is already hacked?

Act fast. The longer a site stays infected, the more the repair costs and the more trust your customers lose. We can point you in the right direction, even if we didn't build the site.

Worried about your WordPress site?

We can look at what's running on your current site and tell you plainly where the real risks are.

Lire cette page en français : Sécurité WordPress: le vrai risque, avec de vrais chiffres