Home Blog WordPress Security WordPress Security Stats 2025 – Melapress Security Survey Results
Melapress 2025 WordPress Security Survey

WordPress Security Stats 2025 – Melapress Security Survey Results

The Melapress WordPress Security Survey is back for 2025. Each year, we run this survey to get a clearer picture of how WordPress professionals think about, prepare for, and deal with security challenges.

For this edition, we reached a wider audience than ever before: WordPress administrators, developers, site owners, and other professionals in the WordPress space. The results shine a light on where the community is doing well, and where important gaps in awareness, preparation, and protection still remain.

So, if you want to find out what the current state of WordPress security is in 2025 from the perspective of the admins, developers, and site owners who work with this CMS daily, then read on.

Top WordPress security stats for 2025

  • 96% of respondents have faced at least one security incident/event, and 64% have suffered a full breach
  • On average, respondents rate their security concerns at 7.8/10
  • Just 26% of respondents see compliance as a primary concern
  • Only 1 in 4 respondents has a breach recovery plan in place

Watch our 2025 Security Survey Panel Discussion, discussing the results of this year’s survey

Click to accept marketing cookies and enable this content
Spinner
Pie charts 96 percent experienced at least 1 security incident, 64 percent reporting at least 1 security breach

How common are security breaches & incidents?

64% of respondents reported experiencing at least one security breach in the past, leaving just 36% who had never experienced a breach. 

So, what about security incidents?

A whopping 96% of respondents say they had experienced a security incident. Only 4% claim otherwise.

Important: We defined a โ€˜security incidentโ€™ broadly, ranging from minor events (like phishing emails or automated login attempts) to major ones such as breaches. This helps capture the reality that while not every incident leads to damage, nearly every site faces some form of attack activity.


All of this makes one thing clear: WordPress security affects everyone, from agencies and developers to ecommerce store owners and WordPress admins. And the survey tells us that the most common security threats are brute force attacks, plugin or theme vulnerabilities, and malicious code injection.

Horizontal bar chart showing WordPress professionals' average concern rating about WordPress security, scored on a scale of 0 to 10, with an average of 7.8, based on the 2025 WordPress Security Survey by Melapress.

How concerned are WordPress users about security

On average, respondents rated their concern for website security at 7.8 out of 10 โ€” a clear sign that WordPress professionals take security very seriously. This could potentially be driven both by the times we live in, with high-profile hacks frequently making headlines, and by personal experience, as nearly every WordPress admin has dealt with security incidents at some point in their career.

Interestingly, only 8% of respondents scored their concern under 5/10, with 67% scoring their concern for WordPress security at eight or higher

More than a third (34%) scored their level of concern about security a 10/10.

Breaking it down by role, web designers were the least concerned, averaging 7.2/10, while website owners scored the highest at 8.2

This makes sense: designers often have less direct responsibility for security, while owners have more at stake. Still, the gap between groups is relatively small, highlighting a strong consensus across the board that WordPress security matters.

Technical roles were among the ones most concerned: 44% of developers rated their concern at 10/10, and WordPress admins showed a similar trend, with 46% doing the same.

Bar chart comparing the level of security concern among WordPress professionals, rated on a scale of 0 to 10, from the 2025 WordPress Security Survey by Melapress. Those working on ecommerce stores scored an average of 8.2, while those working solely on other site types scored 7.5.

Those working on ecommerce stores also stood out, averaging 8.2/10 compared to 7.5/10 for those not working on online stores โ€” a reflection of the higher risks and stakes when customer data and transactions are involved.

What are WordPress professionals worried about?

We asked respondents to share their top concerns (they could select up to 3) when it comes to WordPress security. Hereโ€™s what stood out.

Pie chart from the 2025 WordPress Security Survey by Melapress showing that only 26 percent of respondents listed compliance as a primary concern

Compliance a non-issue?

Only 26% of respondents listed compliance as a top concern, meaning nearly three-quarters donโ€™t see it as a primary issue. 

That doesnโ€™t mean compliance is ignored completely, however. Many of the top concerns listed, such as data theft/loss, directly overlap with compliance. So while compliance may not be named as a top concern for most respondents, it doesnโ€™t necessarily mean itโ€™s completely off the radar either.

Also, regulators often focus more on bigger players when it comes to compliance regulations & enforcement, with many rules/fines only truly kicking in once a business reaches a certain size. For smaller businesses, this could make compliance feel like a lower priority, which might explain the numbers. 

Still, itโ€™s important to emphasise that compliance obligations, such as GDPR or PCI-DSS, can apply to businesses of any size, and overlooking them can carry risks. In fact, smaller organisations may be less resilient to the costs and reputational damage of non-compliance, making early attention to these requirements all the more important.

Pie chart from the 2025 WordPress Security Survey by Melapress showing that 60 percent of respondents say website availability is one of their biggest concerns.

Website availability is the main concern

Nearly 60% of respondents named website availability as their biggest worry. Given its universal importance, this was expected, as downtime affects everyone. A site thatโ€™s offline doesnโ€™t just frustrate users, it can damage trust, hurt search rankings, and in many cases lead directly to financial loss.

Infographic from the 2025 WordPress Security Survey by Melapress stating that 53 percent of WordPress professionals said that data theft or loss is one of their biggest security concerns.

Data theft/loss was the runner-up

At 53%, data theft came just shy of website availability as the second most common WordPress security concern. This makes sense, as data-related risks overlap heavily with other issues, from compliance and regulatory fines to direct financial loss and even site downtime. Beyond the financial and legal implications, a breach of customer data can seriously damage trust and reputation, often with longer-lasting consequences than downtime alone.

Infographic from the 2025 WordPress Security Survey by Melapress stating that 50 percent of respondents named website defacement as a top concern for them.

Website defacement is a close third

Finally, 50% of respondents named website defacement as a top concern. While it may sound more niche compared to data theft or website availability, defacement covers a wide range of issues. It can mean mass SEO spam or malicious link insertions through a vulnerable plugin, all the way to hacktivist campaigns targeting larger enterprises.

The big question is: how prepared are WordPress professionals to actually deal with these concerns?

(Still) A mismatch between concerns and best practice implementation

As we observed in last year’s security survey, WordPress professionals donโ€™t always take the steps necessary to prevent the very things theyโ€™re most worried about. While the majority reported taking measures, gaps and inconsistencies remained.

Although this pattern kept repeating across all security controls and concerns, some of the big ones include:

Website defacement and data theft

32% of those concerned about website defacement donโ€™t implement any form of user account security controls. The same percentage applies to those concerned about data theft. This means they havenโ€™t implemented things like WordPress 2FA, login restrictions, and password policies, which are vital to ensuring your user accounts donโ€™t get hacked.

Pie chart from the 2025 WordPress Security Survey by Melapress showing that 37 percent of those concerned about website defacement don't use activity logs.

Even more surprising: 37% of respondents who were concerned about website defacement didnโ€™t use activity logs on their WordPress sites. With a WordPress activity log being one of the best methods to truly detect and monitor for this, it shows a clear disconnect between concern and action.

Compromised accounts

Among respondents who had experienced hacked or cracked user accounts, 30% still hadnโ€™t implemented any form of user account security controls. And only 59% use a WordPress activity log to detect compromised accounts.

Perhaps most concerning: just 27% implement team training as a security measure, which is a critical step in preventing account compromises in the first place.

Infographic from the 2025 WordPress Security Survey by Melapress stating that 26 percent of respondents implement team training as a security measure.

Is no one prepared for a breach? 

One thing this yearโ€™s security survey makes clear is that most WordPress admins and site owners are still not well prepared for a breach. Many fail to implement the security controls needed to prevent their biggest concerns, but even more lack a plan for what to do when a breach does occur, even if theyโ€™ve already experienced one in the past.

Pie chart from the 2025 WordPress Security Survey by Melapress showing that 27 percent of WordPress professionals have a breach recovery plan.

Only 27% have a breach recovery plan

Our past security surveys have taught us that breach recovery plans are underutilized. This year was no different, as we noted that only 27% of respondents said they had a breach recovery plan in place. This means that over two-thirds of WordPress professionals donโ€™t have a plan for how to respond if their site is hacked.

Responsibilities vs recovery plans

Thereโ€™s also a clear difference between those managing security themselves and those outsourcing it. 31% of respondents managing security in-house had a recovery plan, compared to only 13% of those relying on a third party. 

As we noted last year, this could be partly because some arenโ€™t aware they even have one. Still, the gap emphasises an important truth: you can never fully outsource security responsibilities. Knowing what to do in the event of a breach is essential for all site owners and admins, regardless of who manages the day-to-day security.

Infographic from the 2025 WordPress Security Survey by Melapress stating that only 26 percent of those concerned about compliance have a breach recovery plan in place.

The most worrying part of this all?

The vast majority still havenโ€™t developed a breach recovery plan, even after experiencing a breach!

What to do with this information

The survey highlights some positives, but also big gaps between what WordPress professionals worry about and what they actually do to protect their sites. The good news? Many of these gaps can be closed with a few practical steps that donโ€™t require enterprise-level budgets or resources.

Here are a few quick wins you can act on today based on the insights from this survey:

Have a breach recovery plan

Even a simple checklist of who to contact, how to isolate your site, and how to restore from backup can make all the difference.

Take responsibility for your security

Outsourcing can help, but itโ€™s still important to take ownership and stay on top of your WordPress security. Stay involved, stay aware, and make sure you know what to do if something happens.

Implement security controls that matter

Worried about hacked user accounts? Set up 2FA and secure your login page. Want to prevent hacks due to theme and plugin vulnerabilities? Implement virtual patching using services like Patchstack. More worried about general website availability and server compromises? Make sure your hosting provider has the correct security controls in place.

Train your team members

Most importantly, stay on top of team education. Here at Melapress, we have a ton of resources to help you keep team members educated. Some good ones include:

But there are many other great sources online too. The key is to make ongoing security training a priority, so your team stays prepared against evolving threats. great sources online too. The key is to make ongoing security training a priority, so your team stays prepared against evolving threats.

Who we surveyed and how we ensured data quality

Our 264 respondents represent a broad and experienced cross-section of the WordPress community. Most have been working with WordPress for more than two years (with nearly 100 respondents reporting over a decade of experience). To ensure data quality, responses were validated, and incomplete/unattributable entries were removed before compiling the results.

We gathered a reasonably even mix of developers, site owners, admins, and agencies, along with smaller but important groups such as web designers and consultants. Their work spans ecommerce, blogs, membership sites, agency projects, and enterprise/brand websites.

Responses came from a variety of channels, including in-person (WCEU) and virtual third-party events, social media (organic and paid), email campaigns, and both organic and paid YouTube promotion. The survey ran from the 14th of May till the 29th of July.

Small disclaimer: As with any survey, these findings represent the perspectives of our respondents and may not capture every corner of the WordPress community. That said, the diverse mix of roles and experience levels gives us a strong snapshot of how WordPress professionals are thinking about security today. 

FIELD:
Bram Vergouwen Avatar