WordPress Plugins Expose Sites to Increased Risk, Report Finds

1 - WordPress Plugins Expose Sites to Increased Risk, Report Finds

Average Site Hit by 63 Attacks per Day

Across its sample size of over 6 million websites, SiteLock reported that in the second quarter of 2017, websites experienced an average of 63 attacks per day. The majority of those attacks are malicious bot access attempts.

Spam Is Common Malware Type

Comparing the number of infected files by malware type, SiteLock found that spam represented 62 percent of total malware files across the entire sample group.

Search Engines Don’t Detect All Infected Sites

While popular search engines like Google regularly identify potentially malicious sites, SiteLock’s analysis found that 77 percent of infected websites had no search engine warnings to visitors.

Website Security Responsibility

SiteLock also conducted a survey of 20,000 website owners to find out who they perceived should be responsible for website security. Forty percent of surveyed website owners believe their hosting provider should be responsible for the security of their site.

WordPress Sites Updated but Not Secure

The core WordPress content management system is regularly updated with security patches via an automated system. However, SiteLock found that 69 percent of infected WordPress websites were running the latest security patches for the WordPress core at the time of compromise. The implication is that noncore elements of WordPress, including themes and plugins, are largely the cause of infections.

There Are Many Outdated Plugins

Among the security challenges with WordPress plugins is the simple fact that there are many plugins that are not regularly updated. SiteLock reported that 44 percent of the plugins in the WordPress plugins repository have not been updated in more than a year.

More Plugins Equals More Risk

SiteLock’s analysis found a correlation between the number of plugins installed on a WordPress site and the risk of a site to compromise. WordPress websites with six to 10 plugins are approximately two times more likely to be compromised than the average website. WordPress websites that have 11 to 20 plugins are nearly 2.5 times more likely to be compromised than the average website, according to SiteLock.

7 Security Risks User and Entity Behavior Analytics Helps Detect

Organizations are increasingly using User and Entity Behavior Analytics, or UEBA, thanks to the technology’s ability to find these seven security risks.