3Zero WordPress Security Research
Are Recorded WordPress Plugin Vulnerabilities Increasing?
Annual plugin vulnerability records, affected-plugin counts and comparable growth measures without treating disclosure volume as a software-quality score.
Are recorded plugin vulnerabilities increasing across the complete years 2021–2025?
This study separates disclosure records from the number of distinct plugin slugs represented in those records. Neither number is an installed-base vulnerability rate.
| Year | Plugin records | Affected plugin slugs | Index (first year = 100) | Year-over-year |
|---|---|---|---|---|
| 2021 | 1,473 | 1,171 | 100.0 | — |
| 2022 | 2,341 | 2,257 | 158.9 | 58.9% |
| 2023 | 4,777 | 3,562 | 324.3 | 104.1% |
| 2024 | 8,006 | 4,422 | 543.5 | 67.6% |
| 2025 | 10,007 | 6,696 | 679.4 | 25% |
How to interpret growth
An increasing line means Wordfence Intelligence contains more plugin-associated records with publication dates in the later year. It does not establish that the average installed plugin became less secure, because the dataset does not contain a complete denominator for all plugin installations, versions or sites.
Download this report’s primary data (CSV)
Data Source, Attribution and Methodology
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.
Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.