Skip to main content
Research brief · September 2026

The real risks of running a WooCommerce store in 2026.

WooCommerce is flexible because you own the whole stack. You also own every plugin update, every PHP upgrade, the speed of your server and the security of your checkout page. This brief collects what independent datasets and security researchers measured over the last two years.

11,334new WordPress ecosystem vulnerabilities in 2025, 91% of them in pluginsPatchstack1
5 hrsweighted median time to first exploit for heavily exploited flawsPatchstack1
58active plugins on the average WooCommerce storeMetorik, 6,000+ stores7
39.5%of WooCommerce sites pass Core Web Vitals on mobileHTTP Archive, Aug 20269

In brief

  • Patchstack recorded 11,334 new WordPress ecosystem vulnerabilities in 2025, 91% of them in plugins, and a weighted median of 5 hours to first exploit for heavily exploited flaws.1
  • The average WooCommerce store runs 58 active plugins, based on a March 2026 sample of more than 6,000 stores by Metorik.7
  • About 38% of WordPress sites run a PHP version that no longer receives security fixes, by Mufatech Studio's calculation from WordPress.org and php.net data.56
  • Only 39.5% of WooCommerce sites pass Core Web Vitals on mobile, compared with 76.5% of Shopify sites, in HTTP Archive's August 2026 data.9
  • WooCommerce's own documentation states that PCI DSS compliance is ultimately the store owner's responsibility; Shopify states it is certified Level 1 PCI DSS compliant for all stores.1617

1. Plugins are where WordPress gets breached

WordPress core is rarely the problem. Patchstack recorded 11,334 new vulnerabilities in the WordPress ecosystem in 2025, up 42% on 2024. 91% were in plugins, 9% in themes and only 6 in core.1 Wordfence's independent database tells the same story for 2024: 8,223 vulnerabilities published, 96% affecting plugins, 5 in core.2

The window between disclosure and attack is short. Patchstack puts the weighted median time to first exploit for heavily exploited vulnerabilities at 5 hours, and reports that about half of high-impact vulnerabilities are exploited within 24 hours.1 Patching is not guaranteed either: 46% of 2025 vulnerabilities had no fix available at public disclosure,1 and Wordfence found roughly 35% of those disclosed in 2024 still unpatched in 2025.2

MeasureFigureSource
New vulnerabilities, 202511,334Patchstack1
Share in plugins, 202591%Patchstack1
Not fixed by public disclosure, 202546%Patchstack1
Vulnerabilities in software with under 10,000 installs, 202458%Wordfence2
WordPress share of infections cleaned, 202395.5%Sucuri3

Patchstack, Wordfence and Sucuri sell WordPress security products. Their totals differ because Patchstack counts each affected product while Wordfence counts one record per CVE.

On Shopify

There is no server, database or plugin code on your store to patch. Most apps run on their developers' infrastructure and reach your store through permissioned APIs, and the platform itself is updated by Shopify without any action from you.

2. Your checkout page is the target

Card skimmers inject JavaScript into the checkout to copy payment details as customers type them. In Sucuri's analysis of 39,594 cleaned sites, 1.34% of infected websites contained credit card skimmers, and the most common e-commerce skimmer was WooCommerce-specific: it was found on 37.5% of sites compromised with e-commerce malware.3

Checkout plugins themselves become entry points. In May 2026 Sansec reported an actively exploited flaw in the FunnelKit Funnel Builder plugin (CVE-2026-47100, CVSS 8.7) that it said threatens more than 40,000 WooCommerce checkouts, with fake Google Tag Manager scripts loading a card skimmer.4

What it means for you

A skimmer usually leaves the store working normally. You find out from chargebacks, a payment processor notice or a customer complaint, weeks later.

3. The maintenance load grows every year

58 plugins to keep compatible

Metorik sampled more than 6,000 WooCommerce stores in March 2026: the average store runs 58 active plugins.7 Every one of them has its own update cycle, licence renewal and compatibility matrix with WooCommerce, WordPress, PHP and your theme.

Many of those plugins are no longer maintained. An independent analysis of the WordPress.org directory in June 2026 found that 45.6% of plugins had not shipped an update in 24 months or more, including 192 plugins with 10,000+ active installs.8 In 2024 alone, 1,614 plugins and themes were removed from the WordPress repository because of unpatched security issues.10

38% of WordPress sites run PHP that no longer gets security fixes

PHP 8.1 reached end of life on 31 December 2025, and PHP 8.2 follows on 31 December 2026.6 Combining those dates with WordPress.org's live version statistics, 38.25% of reporting WordPress sites run an end-of-life PHP version today, and 22.9% run PHP 7.4 or older.56

Our calculation from WordPress.org PHP version shares (fetched 16 Sep 2026) and php.net support dates. When PHP 8.2 loses support at the end of 2026, the unsupported share rises to about 63% unless sites upgrade.

Upgrading PHP is exactly where 58 plugins become a problem: one outdated plugin can block the upgrade for the whole store.

On Shopify

  • No PHP, MySQL, caching layer or hosting plan to manage.
  • Features like subscriptions, bundles, search filters and gift cards come from Shopify's own apps or the platform.
  • Apps update on the developer's side without breaking the core store.

4. Slow stores leak revenue

Core Web Vitals measure what real Chrome users experience: loading, responsiveness and visual stability. In HTTP Archive's technology report for August 2026, 39.5% of WooCommerce origins passed all three on mobile, compared with 76.5% of Shopify origins.9

Share of origins with good LCP, INP and CLS on mobile. Our percentages from HTTP Archive counts: Shopify 339,448 of 443,647; WooCommerce 220,276 of 557,369.

The gap is stable, not a one-month blip. The 2025 Web Almanac, built on July 2025 data, put mobile pass rates at 76% for Shopify and 35% for WooCommerce, noting that WooCommerce's pass rates "lag behind SaaS-heavy ecosystems".11

What speed is worth

In a study of 37 brands and 30 million sessions commissioned by Google and run by 55 and Deloitte, a 0.1-second improvement in mobile site speed was associated with an 8.4% increase in retail conversions and a 9.2% increase in average order value.12 Google's earlier research found that as mobile load time goes from 1 to 3 seconds, the probability of a bounce increases 32%; from 1 to 5 seconds it increases 90%.13

Both studies are Google research and show correlation across many sites, not a guarantee for one store.

5. Payment page compliance is on you

On self-hosted WooCommerce, WooCommerce's own documentation is direct: PCI DSS compliance is "ultimately the responsibility of the store owner", and the core plugin is not PCI certified. Taking card payments, even through a hosted gateway, brings the site into PCI DSS scope, which reaches hosting, plugins, user access, updates and security scans.16

The bar rose in 2025. PCI DSS v4.0.1 requirements 6.4.3 (authorising and checking every script on payment pages) and 11.6.1 (detecting unauthorised changes to them) became effective on 31 March 2025.14 For merchants filling in the simpler SAQ A, the PCI Security Standards Council replaced those two requirements with a new eligibility criterion: the merchant must confirm its site is not susceptible to attacks from scripts. The Council added that the change does not remove or diminish the underlying requirements.1415

That criterion is hard to confirm on a WordPress site running dozens of plugins that can each add scripts to checkout, which is exactly the path the skimmers in section 2 use.

On Shopify

Shopify states it is certified Level 1 PCI DSS compliant and that this compliance extends by default to all stores on the platform, covering the store, its cart and hosting.17 Shopify also says its checkout meets PCI DSS version 4 requirements with no additional merchant work required.18 Both statements are Shopify's own.

6. When the risk is manageable

None of this makes WooCommerce a bad platform. The risk is manageable when you have a developer or agency on retainer, a managed WordPress host with a web application firewall, a lean plugin list reviewed every quarter, and a real need for something Shopify cannot do, such as deep custom checkout logic without Shopify Plus or content-heavy sites where commerce is secondary.

If that is not your store, the risk is being carried by whoever happens to log in next. That is the conversation worth having.

Find out what moving would take, in 20 seconds.

  • Free readiness scan of your store
  • Plugin-by-plugin Shopify replacements
  • Redirect count and complexity score
  • Fixed price, preview before you pay
Scan my store freeReads public data only. No login.

Sources

  1. Patchstack. State of WordPress Security in 2026 (covers 2025). security vendor
  2. Wordfence. 2024 Annual WordPress Vulnerability and Threat Report, April 2025. security vendor
  3. Sucuri. 2023 Hacked Website & Malware Threat Report, 39,594 cleaned sites. security vendor
  4. Sansec. Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts, 14 May 2026. security vendor
  5. WordPress.org. PHP version statistics, fetched 16 September 2026.
  6. The PHP Group. Supported versions and unsupported branches.
  7. Metorik. How Many Plugins Does the Average WooCommerce Store Use? 2026 data from 6,000+ stores. WooCommerce analytics vendor
  8. Chris Morris. Almost half the WordPress plugin directory has not been updated in two years, 27 June 2026. independent analysis
  9. HTTP Archive. Core Web Vitals Technology Report data, August 2026, based on the Chrome UX Report.
  10. Patchstack. State of WordPress Security in 2025 (covers 2024). security vendor
  11. HTTP Archive. Web Almanac 2025: Ecommerce, July 2025 crawl.
  12. Google, 55 and Deloitte. Milliseconds Make Millions, 2020. commissioned by Google
  13. Google/SOASTA Research. Find Out How You Stack Up to New Industry Benchmarks for Mobile Page Speed, 2017–2018.
  14. PCI Security Standards Council. Important Updates Announced for Merchants Validating to Self-Assessment Questionnaire A, 30 January 2025.
  15. PCI Security Standards Council. FAQ Clarifies New SAQ A Eligibility Criteria for E-Commerce Merchants, 28 February 2025.
  16. WooCommerce. PCI-DSS compliance and WooCommerce. published by WooCommerce
  17. Shopify. Is Shopify PCI compliant? published by Shopify
  18. Shopify. Simplifying PCI DSS Version 4 Compliance with Shopify's Checkout. published by Shopify

Figures are quoted as published. Where we calculated a percentage from published counts, the page says so. Mufatech Studio migrates stores to Shopify, so read our conclusions with that in mind; the numbers are from the sources above.