Original calculations from synchronized vulnerability data
WordPress Security Research & Data
Multi-year trends, software comparisons, patch-status analysis, weakness patterns and disclosure timing—calculated by 3Zero Digital from approved Wordfence Intelligence snapshots.
Five complete years
Recorded disclosure volume, 2021–2025
The flagship analysis compares complete calendar years so a partial current year does not distort the direction of the series.
Read the five-year study →Published studies
Explore the evidence from different angles
Each report has its own research question, denominator, calculations, limitations, charts and accessible tables. They share a reproducible snapshot—not repeated filler content.
Five-Year Vulnerability Trends
A complete-year analysis of recorded WordPress vulnerabilities, software types, severity, weakness categories and current patch status.
Open study →02Plugin Vulnerability Growth
Annual plugin vulnerability records, affected-plugin counts and comparable growth measures without treating disclosure volume as a software-quality score.
Open study →03Plugin, Theme and Core Comparison
A comparison of unique records, software associations, severity profiles, patch status and weakness patterns across WordPress software types.
Open study →04Patched vs Unpatched
Current synchronized patch status by software association, severity, software type and age of disclosure.
Open study →05Common Vulnerability Types
CWE-based weakness categories, their share of the dataset, severity distribution and five-year movement.
Open study →06Severity Trends
Annual severity shares, median CVSS scores and high-or-critical proportions across complete calendar years.
Open study →07Disclosure Seasonality
Month-of-year disclosure patterns normalized for month length and annual changes in record volume.
Open study →Reproducible by design
Research pages use approved data snapshots
Calculations are prepared after successful Production Feed synchronization and stored outside autoloaded options. Public pages never run full-dataset aggregation queries. Each report identifies its cutoff, calculation version and limitations.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital. Record counts are not software-quality rankings and do not prove exploitation or infection.
Read the methodology