WordPress security

Is WordPress secure? The core is. What runs on it is the risk.

WordPress itself is looked after well: only 6 of the 11,334 vulnerabilities found around WordPress in 2025 were in WordPress itself. 91% were in plugins, and a new one is typically attacked within hours of becoming known. A site is as secure as the least cared-for plugin on it — unless its visitors never reach WordPress at all.

By pressing the button you confirm the site is yours, or that you are allowed to copy it. We copy one page, keep it for 4 hours, and search engines never see it.

A copy that works like your site

An HTML export writes each page out with the files it names. What a page only loads once it is open — a picture that appears as you scroll, a menu that fills in, content a script fetches, a link that forwards to another address — is often missing, and you find out from a visitor.

A copy from MakeStatic works like your site, not only looks like it. You try it yourself, side by side with your site, before you decide anything — and if a page of the copy ever works differently from yours, write to [email protected] and we fix it.

  • Pictures that load as you scroll, in every size your site has for phones and large screens.
  • Fonts, icons and everything your theme or page builder brings along.
  • Content a script loads once the page is open, and menus that fill in as you move over them.
  • Links on your pages that forward to another address still forward.
  • Videos that play and let you skip ahead.
  • Contact forms that deliver, and a search box that answers.

WordPress itself is looked after

WordPress has a security team, and since version 3.7 it installs its own security releases in the background. In 2025, only 6 vulnerabilities were reported in WordPress itself.

That does not make it immune. wp2shell, in July 2026, was a flaw in WordPress itself that anyone could use, and WordPress pushed the fix to sites as a forced update. It is the exception, not the rule.

Where the risk sits

  • 91% of the vulnerabilities found in 2025 were in plugins, 9% in themes.
  • 46% had no fix available when they became public.
  • The first attack on a new vulnerability comes after a median of 5 hours, and about half of the serious ones are attacked within a day.
  • Plugins and themes update themselves only where someone switched it on for each of them, or when WordPress's security team forces an update.
  • In the last published study of hacked sites, 39.1% of the systems were out of date when they were infected.

Why updating is not the whole answer

An update closes a hole once there is a fix. For almost half of them there is none when they become known, and the attacks start within hours.

A small company's website is rarely picked out. It is found by programs that try the same known flaw on every WordPress they reach — and WordPress runs 40.2% of all websites.

What a security plugin does

A security plugin such as Wordfence looks at the requests that reach WordPress and blocks the ones that match its rules; in its extended mode, its firewall runs before WordPress does. That helps against every attack it has a rule for.

Every visitor still reaches WordPress and its plugins, though, and the security plugin is one more of them to keep up to date.

When visitors never reach WordPress

A static copy answers every visitor from files. No plugin runs for them and no database answers them. The contact form still arrives — it is received by us and mailed to you — and the search still answers, in the visitor's browser.

A flaw in a plugin can only be used where WordPress answers, and at your public address it no longer does.

What stays yours to look after

The WordPress you edit in stays online at its own address, so it still needs its updates. A missed one no longer puts the site your visitors see at risk, and nothing from it reaches them until you publish. Your domain, your email and your passwords are yours to keep safe, as before.

Sources

Patchstack, State of WordPress Security in 2026 (figures for 2025); Sucuri, 2023 Hacked Website & Malware Threat Report; the WordPress documentation on automatic updates; W3Techs, September 2026. Checked on 28 September 2026.

Questions people ask

Is WordPress safe enough for a small company's website?
WordPress itself, yes, if it is kept up to date. What decides it is the plugins on it and how quickly each of them is updated — or whether visitors reach them at all.
Do I still have to update WordPress if my public site is a static copy?
Yes. The WordPress you edit in still needs its updates. What changes is what a missed update puts at risk: your editing installation, not the site your visitors see.
Is a security plugin still worth having?
On the WordPress you edit in, it can be: that one stays online. On the public site, a static copy leaves it nothing to guard.
Which is more secure, a static site or WordPress?
A static site gives an attacker far less to use: files, and nothing that runs for a visitor. That is why the copy is static and WordPress stays where you edit.

See it on your own site

About twenty seconds, and nothing to sign up for. You will have your site and the copy open next to each other, and can try the copy yourself before you decide anything.

By pressing the button you confirm the site is yours, or that you are allowed to copy it. We copy one page, keep it for 4 hours, and search engines never see it.