Updated on 24 October, 2025 by Bram Vergouwen. Reviewed by Robert Abela | Published on 2 September, 2025
WordPress Security Stats 2025 – Melapress Security Survey Results
The Melapress WordPress Security Survey is back for 2025. Each year, we run this survey to get a clearer picture of how WordPress professionals think about, prepare for, and deal with security challenges.
For this edition, we reached a wider audience than ever before: WordPress administrators, developers, site owners, and other professionals in the WordPress space. The results shine a light on where the community is doing well, and where important gaps in awareness, preparation, and protection still remain.
So, if you want to find out what the current state of WordPress security is in 2025 from the perspective of the admins, developers, and site owners who work with this CMS daily, then read on.
Table of contents
Top WordPress security stats for 2025
- 96% of respondents have faced at least one security incident/event, and 64% have suffered a full breach
- On average, respondents rate their security concerns at 7.8/10
- Just 26% of respondents see compliance as a primary concern
- Only 1 in 4 respondents has a breach recovery plan in place
We couldnโt squeeze all the insights into this post. Want more? Subscribe below and weโll send the best ones right to your inbox.
Watch our 2025 Security Survey Panel Discussion, discussing the results of this year’s survey

How common are security breaches & incidents?
64% of respondents reported experiencing at least one security breach in the past, leaving just 36% who had never experienced a breach.
So, what about security incidents?
A whopping 96% of respondents say they had experienced a security incident. Only 4% claim otherwise.
Important: We defined a โsecurity incidentโ broadly, ranging from minor events (like phishing emails or automated login attempts) to major ones such as breaches. This helps capture the reality that while not every incident leads to damage, nearly every site faces some form of attack activity.
All of this makes one thing clear: WordPress security affects everyone, from agencies and developers to ecommerce store owners and WordPress admins. And the survey tells us that the most common security threats are brute force attacks, plugin or theme vulnerabilities, and malicious code injection.

How concerned are WordPress users about security
On average, respondents rated their concern for website security at 7.8 out of 10 โ a clear sign that WordPress professionals take security very seriously. This could potentially be driven both by the times we live in, with high-profile hacks frequently making headlines, and by personal experience, as nearly every WordPress admin has dealt with security incidents at some point in their career.
Interestingly, only 8% of respondents scored their concern under 5/10, with 67% scoring their concern for WordPress security at eight or higher.
More than a third (34%) scored their level of concern about security a 10/10.
Breaking it down by role, web designers were the least concerned, averaging 7.2/10, while website owners scored the highest at 8.2.
This makes sense: designers often have less direct responsibility for security, while owners have more at stake. Still, the gap between groups is relatively small, highlighting a strong consensus across the board that WordPress security matters.
Technical roles were among the ones most concerned: 44% of developers rated their concern at 10/10, and WordPress admins showed a similar trend, with 46% doing the same.

Those working on ecommerce stores also stood out, averaging 8.2/10 compared to 7.5/10 for those not working on online stores โ a reflection of the higher risks and stakes when customer data and transactions are involved.
What are WordPress professionals worried about?
We asked respondents to share their top concerns (they could select up to 3) when it comes to WordPress security. Hereโs what stood out.

Compliance a non-issue?
Only 26% of respondents listed compliance as a top concern, meaning nearly three-quarters donโt see it as a primary issue.
That doesnโt mean compliance is ignored completely, however. Many of the top concerns listed, such as data theft/loss, directly overlap with compliance. So while compliance may not be named as a top concern for most respondents, it doesnโt necessarily mean itโs completely off the radar either.
Also, regulators often focus more on bigger players when it comes to compliance regulations & enforcement, with many rules/fines only truly kicking in once a business reaches a certain size. For smaller businesses, this could make compliance feel like a lower priority, which might explain the numbers.
Still, itโs important to emphasise that compliance obligations, such as GDPR or PCI-DSS, can apply to businesses of any size, and overlooking them can carry risks. In fact, smaller organisations may be less resilient to the costs and reputational damage of non-compliance, making early attention to these requirements all the more important.

Website availability is the main concern
Nearly 60% of respondents named website availability as their biggest worry. Given its universal importance, this was expected, as downtime affects everyone. A site thatโs offline doesnโt just frustrate users, it can damage trust, hurt search rankings, and in many cases lead directly to financial loss.

Data theft/loss was the runner-up
At 53%, data theft came just shy of website availability as the second most common WordPress security concern. This makes sense, as data-related risks overlap heavily with other issues, from compliance and regulatory fines to direct financial loss and even site downtime. Beyond the financial and legal implications, a breach of customer data can seriously damage trust and reputation, often with longer-lasting consequences than downtime alone.

Website defacement is a close third
Finally, 50% of respondents named website defacement as a top concern. While it may sound more niche compared to data theft or website availability, defacement covers a wide range of issues. It can mean mass SEO spam or malicious link insertions through a vulnerable plugin, all the way to hacktivist campaigns targeting larger enterprises.
Quick stat: Did you know web designers and web developers are the least likely to use automatic updates, at 32% and 33% respectively?
The big question is: how prepared are WordPress professionals to actually deal with these concerns?
(Still) A mismatch between concerns and best practice implementation
As we observed in last year’s security survey, WordPress professionals donโt always take the steps necessary to prevent the very things theyโre most worried about. While the majority reported taking measures, gaps and inconsistencies remained.
Although this pattern kept repeating across all security controls and concerns, some of the big ones include:
Website defacement and data theft
32% of those concerned about website defacement donโt implement any form of user account security controls. The same percentage applies to those concerned about data theft. This means they havenโt implemented things like WordPress 2FA, login restrictions, and password policies, which are vital to ensuring your user accounts donโt get hacked.

Even more surprising: 37% of respondents who were concerned about website defacement didnโt use activity logs on their WordPress sites. With a WordPress activity log being one of the best methods to truly detect and monitor for this, it shows a clear disconnect between concern and action.
Compromised accounts
Among respondents who had experienced hacked or cracked user accounts, 30% still hadnโt implemented any form of user account security controls. And only 59% use a WordPress activity log to detect compromised accounts.
Perhaps most concerning: just 27% implement team training as a security measure, which is a critical step in preventing account compromises in the first place.

Quick stat: Only 29% of those who experienced phishing attempts (that theyโre aware of) implement team training.
Is no one prepared for a breach?
One thing this yearโs security survey makes clear is that most WordPress admins and site owners are still not well prepared for a breach. Many fail to implement the security controls needed to prevent their biggest concerns, but even more lack a plan for what to do when a breach does occur, even if theyโve already experienced one in the past.

Only 27% have a breach recovery plan
Our past security surveys have taught us that breach recovery plans are underutilized. This year was no different, as we noted that only 27% of respondents said they had a breach recovery plan in place. This means that over two-thirds of WordPress professionals donโt have a plan for how to respond if their site is hacked.
Responsibilities vs recovery plans
Thereโs also a clear difference between those managing security themselves and those outsourcing it. 31% of respondents managing security in-house had a recovery plan, compared to only 13% of those relying on a third party.
As we noted last year, this could be partly because some arenโt aware they even have one. Still, the gap emphasises an important truth: you can never fully outsource security responsibilities. Knowing what to do in the event of a breach is essential for all site owners and admins, regardless of who manages the day-to-day security.

Did you know: Only 26% of those concerned about compliance have a breach recovery plan in place? This is worrying, given that most compliance regulations/frameworks require some kind of breach recovery plan to be in place.
The most worrying part of this all?
The vast majority still havenโt developed a breach recovery plan, even after experiencing a breach!
Want to dig deeper into the survey? Get exclusive stats โ like how breach experience changes security habits โ straight to your inbox.
Quick fact: Did you know only 26% of respondents implement team training as a security measure, even though most data breaches involve some kind of human element.
What to do with this information
The survey highlights some positives, but also big gaps between what WordPress professionals worry about and what they actually do to protect their sites. The good news? Many of these gaps can be closed with a few practical steps that donโt require enterprise-level budgets or resources.
Here are a few quick wins you can act on today based on the insights from this survey:
Have a breach recovery plan
Even a simple checklist of who to contact, how to isolate your site, and how to restore from backup can make all the difference.
Take responsibility for your security
Outsourcing can help, but itโs still important to take ownership and stay on top of your WordPress security. Stay involved, stay aware, and make sure you know what to do if something happens.
Implement security controls that matter
Worried about hacked user accounts? Set up 2FA and secure your login page. Want to prevent hacks due to theme and plugin vulnerabilities? Implement virtual patching using services like Patchstack. More worried about general website availability and server compromises? Make sure your hosting provider has the correct security controls in place.
Train your team members
Most importantly, stay on top of team education. Here at Melapress, we have a ton of resources to help you keep team members educated. Some good ones include:
- The 2025 WordPress Security Checklist
- WooCommerce Security: How to Secure your Online Store
- And if youโve already got the basics down, our live session with Tim Nash on Advanced WordPress Security is a fun watch.
But there are many other great sources online too. The key is to make ongoing security training a priority, so your team stays prepared against evolving threats. great sources online too. The key is to make ongoing security training a priority, so your team stays prepared against evolving threats.
Who we surveyed and how we ensured data quality
Our 264 respondents represent a broad and experienced cross-section of the WordPress community. Most have been working with WordPress for more than two years (with nearly 100 respondents reporting over a decade of experience). To ensure data quality, responses were validated, and incomplete/unattributable entries were removed before compiling the results.
We gathered a reasonably even mix of developers, site owners, admins, and agencies, along with smaller but important groups such as web designers and consultants. Their work spans ecommerce, blogs, membership sites, agency projects, and enterprise/brand websites.
Responses came from a variety of channels, including in-person (WCEU) and virtual third-party events, social media (organic and paid), email campaigns, and both organic and paid YouTube promotion. The survey ran from the 14th of May till the 29th of July.
Small disclaimer: As with any survey, these findings represent the perspectives of our respondents and may not capture every corner of the WordPress community. That said, the diverse mix of roles and experience levels gives us a strong snapshot of how WordPress professionals are thinking about security today.
Join the WP Security discussion on Reddit


