Why updating your plugins is not enough

Keeping plugins updated is the standard advice, and Patchstack found that 46 percent of vulnerabilities disclosed in 2025 had no patch available on the day they went public. The lever that actually works is having fewer plugins.
The advice everyone gives about WordPress security is to keep your plugins updated.
According to the people who track this for a living, that advice fails almost half the time.
Patchstack publishes an annual report on WordPress vulnerabilities, and the 2026 edition found that 46 percent of the vulnerabilities disclosed during 2025 had no fix available from the developer on the day they became public. Nearly half. You cannot update to a patch that does not exist.
That single number changes what you should actually be doing.
WordPress is not the problem, and this matters
People say WordPress is insecure. The data says something narrower and more useful.
Of the 11,334 new vulnerabilities found across the WordPress ecosystem in 2025, 91 percent were in plugins and 9 percent were in themes. WordPress core itself accounted for a handful, all rated low risk, out of eleven thousand.
So the core software, maintained by a team with a strict review process, is holding up fine. The risk is entirely in the thirty pieces of third party code you bolted onto it, each written by a different person, each running with full access to your database, each maintained at whatever level of care that person can afford to give it for free.
The average WordPress site runs somewhere between twenty and thirty plugins. That is twenty to thirty separate trust decisions, most of which were made in about four seconds, years ago, by someone searching for a contact form.
Five hours
Here is the other number worth knowing. For the vulnerabilities that get attacked hardest, Patchstack measured the gap between public disclosure and the first real exploitation attempt. The weighted median was five hours.
About twenty percent were under attack within six hours. Roughly half within a day. Seventy percent within a week.
Nobody is picking your salon out of a hat. These are automated scanners working through lists of sites, testing for a known hole, and the reason yours gets hit is not that it is interesting. It is that it is reachable.
If you log in and update your plugins every Sunday, you are doing better than most owners. You are also, statistically, arriving after the wave has already passed through.
Pirated plugins are still the fastest way in
There is a market for nulled plugins, which are paid plugins cracked to run without a licence, offered free on sites that exist for exactly that purpose. A premium plugin costs sixty dollars a year. The cracked version costs nothing. The arithmetic looks obvious to an owner watching every expense.
Nobody cracks and distributes software for free out of generosity. The business model is the backdoor. You are not getting a discounted plugin, you are installing someone's access to your site and paying for it with your customer data.
And do not assume paying protects you either. Patchstack ran focused research on premium marketplaces and found that 76 percent of the vulnerabilities they confirmed in paid components were exploitable in real attacks. Premium code gets less outside scrutiny, not more, because researchers cannot easily read it.
What to actually do
If patching fails half the time and attacks land in five hours, then the lever that works is not speed. It is surface area.
Open your plugin list this week and count. For each one, ask when you last used what it does. Anything deactivated should be deleted rather than left sitting there, because deactivated plugins still contain reachable code. Most sites I look at can lose a third of their plugins without anyone noticing, and every one removed is a door that closes permanently.
Then check the ones that stay. On the WordPress plugin directory each listing shows when it was last updated. Anything untouched for over a year is effectively abandoned, and abandoned is how a plugin ends up in the 46 percent with no patch.
Turn on automatic updates for the ones you keep, so you are not the person patching on Sunday. Put two factor on your admin login. Make sure backups run somewhere other than the same server, because a backup sitting on a compromised machine is not a backup.
And know where your domain and hosting logins live before you need them, because a hacked site is a bad moment to discover you cannot reach your own registrar.
The part that costs the most
Cleaning malware is usually the cheap half. The expensive half is what happens in search.
Once Google flags a site as compromised, visitors get a full red interstitial warning before they can reach you, and that stays until the site is cleaned and you have requested a review through Search Console. Meanwhile every customer who searched your name saw a security warning attached to your business, which is not a thing they forget quickly.
Deleting eight plugins you stopped using in 2023 takes twenty minutes.
When did you last look at the list?
Tags
Written by
Web Designer & Developer · Houston, TX
Founder of Ideavezy LLC and a full-stack developer with 20+ years of experience. He builds custom, mobile-first websites for salons, spas, restaurants, and local businesses across Houston and Texas — no templates, no page builders.
Book a free audit call