Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

3Zero WordPress Security Research

Are Recorded WordPress Plugin Vulnerabilities Increasing?

Annual plugin vulnerability records, affected-plugin counts and comparable growth measures without treating disclosure volume as a software-quality score.

Approved snapshot #1Data through August 1, 2026 UTC38,293 active records
Research question

Are recorded plugin vulnerabilities increasing across the complete years 2021–2025?

This study separates disclosure records from the number of distinct plugin slugs represented in those records. Neither number is an installed-base vulnerability rate.

Recorded plugin vulnerability growthUnique plugin-associated records and distinct affected plugin slugs by complete year. 10,0077,5055,0042,5020 20212022202320242025 Plugin records: 1,473 in 2021Plugin records: 2,341 in 2022Plugin records: 4,777 in 2023Plugin records: 8,006 in 2024Plugin records: 10,007 in 2025Affected plugin slugs: 1,171 in 2021Affected plugin slugs: 2,257 in 2022Affected plugin slugs: 3,562 in 2023Affected plugin slugs: 4,422 in 2024Affected plugin slugs: 6,696 in 2025
Recorded plugin vulnerability growthUnique plugin-associated records and distinct affected plugin slugs by complete year.Plugin recordsAffected plugin slugs
Plugin disclosure growth measures
YearPlugin recordsAffected plugin slugsIndex (first year = 100)Year-over-year
20211,4731,171100.0
20222,3412,257158.958.9%
20234,7773,562324.3104.1%
20248,0064,422543.567.6%
202510,0076,696679.425%

How to interpret growth

An increasing line means Wordfence Intelligence contains more plugin-associated records with publication dates in the later year. It does not establish that the average installed plugin became less secure, because the dataset does not contain a complete denominator for all plugin installations, versions or sites.

Download this report’s primary data (CSV)

Data Source, Attribution and Methodology

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.

Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.