2019-03-10 00:00:00

Security|TechnologyCMS|hacker|infected|malware|plugin|virus|vulnerability|Wordpress

90 percent of hacked web sites were powered by WordPress

WordPress is so popular software package for online publications, e-commerce, business sites, blogs, and all types of web sites that it has the major problem that comes with success: hackers. Sucuri, a business specialized in web site security, analyzed infected web sites that they had restored in 2018. WordPress was running on 90% of the infected sites.

Sucuri analyzed 18302 infected websites for the report where they summarize their findings. In 2018, web sites infected by malware or successfully accessed by hackers were powered by:

  • 90% of the web sites were running on WordPress
  • 4.6% Magento
  • 4.3% Joomla
  • 3.7% Drupal

Once infected, a web site is in trouble. Approximately 11% of the infected websites were marked dangerous by a blacklist authority whose listing is likely to affect negatively to Google search results.

It is fair to add that even though WordPress is the most hacked content management system, it is also – by a wide margin - the most popular system with millions of live installations.

locked door - restricted area. photo by Nguyen Nguyen.
Photo by Nguyen Nguyen.

The most common threats to WordPress and other content management systems

All content management systems, like WordPress have a similar problem that hackers are taking advantage of: third-party add-on modules, plugins, themes, and extensions are the most vulnerable element in a system.

It may take a long time before someone who has created a plugin is aware of a vulnerability, and before it is patched. Yet, open source content management systems want to provide add-on modules because they extend the functionality of the core system.

Common issues causing vulnerabilities:

  • Improper deployment of the content management system.
  • No security configuration.
  • Overall site maintenance lacking knowledgeable resources.
  • Broken authentication and session management.
  • Pirated software with backdoors and other malware.
  • Reuse of leaked passwords.
  • Cross-site contamination.

By and large, plugins with known and unknown vulnerabilities are the primary attack route affecting tens of thousands of sites a year.

Three most desired files by hackers in WordPress

Index.php, functions.php and wp-config.php files are the most popular targets for attackers. These php scripts are loaded every time a site is accessed. They belong to a group of core files in WordPress.

The common types of infections in WordPress and other web sites

Sucuri detected the following type of hacks on infected WordPress sites:

  • 68% of infected sites had a Backdoor. This is an access point to the system only known to the party who created the piece of software, such as a plugin.
  • 56.4% Malware
  • 51.3% SEO spam
  • 44.4% Non-classified
  • 18.9% Hack tool
  • 12.5% Mailer
  • 10.1% Defaced
  • 8.9% Phishing
  • 4.4% Dropper (a way to infect with a virus)
Sucuri wordpress security scan report
An extract from Sucuri WordPress security scan results.

What can a WordPress site admin do to prevent hacking?

In 2018, 36.7% of infected sites had an outdated core WordPress version. It means the majority of hacked sites had an up-to-date WordPress configuration. Although constant updating of WordPress is encouraged, regular updating is clearly not the only protection method against hackers.

Multiple types of security and firewall plugins are available for making a WordPress site less vulnerable, as well as cloud services that monitor the health of a site.

The first step is to scan a WordPress site for known vulnerabilities. Free online scanners are available that can detect common problems and vulnerabilities hackers are looking for. Wpbeginner has reviewed a number of Wordpress security scanning services. Many of these provide a subscription service that automates the scanning, and can conduct a deeper inspection inside the system.

We were worried about the status of WordPress security and privacy after December 2018 Wordcamp keynote speech State of the Word by Matt Mullenweg. He didn't even mention security or privacy during his talk. If it is a sign of strategic direction for WordPress, it is a very risky one.

The news for the report via Info Security.

News

2025-06-11 16:24:00

Let's go.#streetphotographyflic.kr/p/2r3EuJNhttps://flic.kr/p/2r3EuJN


News

2025-06-04 18:08:00

A #photographer has been using sunglasses with a camera and loudspeakers for 8 months: "I quite enjoy them, and they’ve quickly become my daily wear as far as sunglasses are concerned."https://fstoppers.com/artificial-intelligence/ray-ban-meta-glasses-photographers-perspective-701899


News

2025-06-02 14:42:00

Today, digital nomads recognize the benefits but also risks of their lifestyle. An extensive study among traveling workers reveals the highs and lows of the nomad life. #remotework #digitalnomadhttps://klaava.com/digital-nomads-feel-powered-by-their-lifestyle-but-recognise-inevitable-downsides-as-well/


Aland archipelago

2025-05-30 16:59:41

Aland archipelago


Highway across a swamp.

2025-05-30 11:14:51

arihak

Highway across a swamp.


News

2025-05-26 16:29:00

Flower market, but she is selling fruit trees.#streetphotographyhttps://unsplash.com/photos/TfQ6uYmI9QQ


News

2025-05-22 14:19:00

In Spain, the Balearic government asked influencers to help ease pressure on overcrowded hotspots by promoting less-visited areas. Instead, influencers have unintentionally drawn large crowds of tourists to remote, ecologically sensitive locations. #photography #selfiehttps://petapixel.com/2025/05/21/spanish-islands-ban-influencers-after-4000-tourists-flock-to-tiny-beach-for-selfies/


News

2025-05-18 18:23:00

Most travelers already knew that south Europe is the warm and sunny zone of #Europe, and this ranking confirms it. Spain and Italy have most cities in the top 30, followed by France and Portugal. #travelhttps://klaava.com/sunniest-cities-in-europe/


Popular sight in Sevilla

2025-05-16 17:51:34

Popular sight in Sevilla


News

2025-05-14 16:03:00

Bordeaux is ready for hot summer days.#streetphotographyhttps://pixelfed.social/p/arihak/827854641319295061


Cooling zone.

2025-05-13 12:38:47

arihak

Cooling zone.


Hochosterwitz castle

2025-05-10 15:23:05

Hochosterwitz castle


News

2025-05-07 14:39:00

A meeting in winter sun.#streetphotography #travelphotographyflic.kr/p/2qey2NHhttps://flic.kr/p/2qey2NH


News

2025-04-30 17:01:00

Shady character.#streetphotography #travelphotography #StreetPhotography


Not in space, but firmly on the ground in Valencia.

2025-04-25 17:47:30

arihak

Not in space, but firmly on the ground in Valencia.


News

2025-04-24 15:17:00

According to a survey, football (a sport where you are supposed to kick the ball instead touching the ball with a hand) is the most popular sports that fans want to follow live on site even if it means traveling overseas. #travelhttps://klaava.com/sports-events-are-trending-among-travelers/


News

2025-04-23 14:19:00

An unexpected recognition for analog #photography : UNESCO Cultural Heritage designation suggests a renewed appreciation for the craftsmanship and cultural significance of analog methods.https://www.diyphotography.net/analog-photography-recognized-as-intangible-cultural-heritage-by-unesco/


News

2025-04-17 13:18:00

New restriction on Flickr #photo sharing: Free #Flickr accounts will be restricted from downloading original and large-size images. While users will still be able to upload photos of all sizes, free account holders will only be able to download medium and small photos.https://petapixel.com/2025/04/16/flickr-restricting-download-sizes-for-free-accounts/


News

2025-04-16 10:54:00

Morning commute.#streetphotography#travelphotography


News

2025-04-12 09:17:00

The region in #Europe where you will get more #travel days for your euro (or whatever the local currency happens to be). The difference in the average cost is vast between the cheapest and the most expensive European countries.https://klaava.com/here-are-the-cheapest-countries-to-travel-in-europe/