In brief
- Patchstack recorded 11,334 new WordPress ecosystem vulnerabilities in 2025, 91% of them in plugins, and a weighted median of 5 hours to first exploit for heavily exploited flaws.1
- The average WooCommerce store runs 58 active plugins, based on a March 2026 sample of more than 6,000 stores by Metorik.7
- About 38% of WordPress sites run a PHP version that no longer receives security fixes, by Mufatech Studio's calculation from WordPress.org and php.net data.56
- Only 39.5% of WooCommerce sites pass Core Web Vitals on mobile, compared with 76.5% of Shopify sites, in HTTP Archive's August 2026 data.9
- WooCommerce's own documentation states that PCI DSS compliance is ultimately the store owner's responsibility; Shopify states it is certified Level 1 PCI DSS compliant for all stores.1617
1. Plugins are where WordPress gets breached
WordPress core is rarely the problem. Patchstack recorded 11,334 new vulnerabilities in the WordPress ecosystem in 2025, up 42% on 2024. 91% were in plugins, 9% in themes and only 6 in core.1 Wordfence's independent database tells the same story for 2024: 8,223 vulnerabilities published, 96% affecting plugins, 5 in core.2
The window between disclosure and attack is short. Patchstack puts the weighted median time to first exploit for heavily exploited vulnerabilities at 5 hours, and reports that about half of high-impact vulnerabilities are exploited within 24 hours.1 Patching is not guaranteed either: 46% of 2025 vulnerabilities had no fix available at public disclosure,1 and Wordfence found roughly 35% of those disclosed in 2024 still unpatched in 2025.2
| Measure | Figure | Source |
|---|---|---|
| New vulnerabilities, 2025 | 11,334 | Patchstack1 |
| Share in plugins, 2025 | 91% | Patchstack1 |
| Not fixed by public disclosure, 2025 | 46% | Patchstack1 |
| Vulnerabilities in software with under 10,000 installs, 2024 | 58% | Wordfence2 |
| WordPress share of infections cleaned, 2023 | 95.5% | Sucuri3 |
Patchstack, Wordfence and Sucuri sell WordPress security products. Their totals differ because Patchstack counts each affected product while Wordfence counts one record per CVE.
On Shopify
There is no server, database or plugin code on your store to patch. Most apps run on their developers' infrastructure and reach your store through permissioned APIs, and the platform itself is updated by Shopify without any action from you.
2. Your checkout page is the target
Card skimmers inject JavaScript into the checkout to copy payment details as customers type them. In Sucuri's analysis of 39,594 cleaned sites, 1.34% of infected websites contained credit card skimmers, and the most common e-commerce skimmer was WooCommerce-specific: it was found on 37.5% of sites compromised with e-commerce malware.3
Checkout plugins themselves become entry points. In May 2026 Sansec reported an actively exploited flaw in the FunnelKit Funnel Builder plugin (CVE-2026-47100, CVSS 8.7) that it said threatens more than 40,000 WooCommerce checkouts, with fake Google Tag Manager scripts loading a card skimmer.4
What it means for you
A skimmer usually leaves the store working normally. You find out from chargebacks, a payment processor notice or a customer complaint, weeks later.
3. The maintenance load grows every year
58 plugins to keep compatible
Metorik sampled more than 6,000 WooCommerce stores in March 2026: the average store runs 58 active plugins.7 Every one of them has its own update cycle, licence renewal and compatibility matrix with WooCommerce, WordPress, PHP and your theme.
Many of those plugins are no longer maintained. An independent analysis of the WordPress.org directory in June 2026 found that 45.6% of plugins had not shipped an update in 24 months or more, including 192 plugins with 10,000+ active installs.8 In 2024 alone, 1,614 plugins and themes were removed from the WordPress repository because of unpatched security issues.10
38% of WordPress sites run PHP that no longer gets security fixes
PHP 8.1 reached end of life on 31 December 2025, and PHP 8.2 follows on 31 December 2026.6 Combining those dates with WordPress.org's live version statistics, 38.25% of reporting WordPress sites run an end-of-life PHP version today, and 22.9% run PHP 7.4 or older.56
Our calculation from WordPress.org PHP version shares (fetched 16 Sep 2026) and php.net support dates. When PHP 8.2 loses support at the end of 2026, the unsupported share rises to about 63% unless sites upgrade.
Upgrading PHP is exactly where 58 plugins become a problem: one outdated plugin can block the upgrade for the whole store.
On Shopify
- No PHP, MySQL, caching layer or hosting plan to manage.
- Features like subscriptions, bundles, search filters and gift cards come from Shopify's own apps or the platform.
- Apps update on the developer's side without breaking the core store.
4. Slow stores leak revenue
Core Web Vitals measure what real Chrome users experience: loading, responsiveness and visual stability. In HTTP Archive's technology report for August 2026, 39.5% of WooCommerce origins passed all three on mobile, compared with 76.5% of Shopify origins.9
Share of origins with good LCP, INP and CLS on mobile. Our percentages from HTTP Archive counts: Shopify 339,448 of 443,647; WooCommerce 220,276 of 557,369.
The gap is stable, not a one-month blip. The 2025 Web Almanac, built on July 2025 data, put mobile pass rates at 76% for Shopify and 35% for WooCommerce, noting that WooCommerce's pass rates "lag behind SaaS-heavy ecosystems".11
What speed is worth
In a study of 37 brands and 30 million sessions commissioned by Google and run by 55 and Deloitte, a 0.1-second improvement in mobile site speed was associated with an 8.4% increase in retail conversions and a 9.2% increase in average order value.12 Google's earlier research found that as mobile load time goes from 1 to 3 seconds, the probability of a bounce increases 32%; from 1 to 5 seconds it increases 90%.13
Both studies are Google research and show correlation across many sites, not a guarantee for one store.
5. Payment page compliance is on you
On self-hosted WooCommerce, WooCommerce's own documentation is direct: PCI DSS compliance is "ultimately the responsibility of the store owner", and the core plugin is not PCI certified. Taking card payments, even through a hosted gateway, brings the site into PCI DSS scope, which reaches hosting, plugins, user access, updates and security scans.16
The bar rose in 2025. PCI DSS v4.0.1 requirements 6.4.3 (authorising and checking every script on payment pages) and 11.6.1 (detecting unauthorised changes to them) became effective on 31 March 2025.14 For merchants filling in the simpler SAQ A, the PCI Security Standards Council replaced those two requirements with a new eligibility criterion: the merchant must confirm its site is not susceptible to attacks from scripts. The Council added that the change does not remove or diminish the underlying requirements.1415
That criterion is hard to confirm on a WordPress site running dozens of plugins that can each add scripts to checkout, which is exactly the path the skimmers in section 2 use.
On Shopify
Shopify states it is certified Level 1 PCI DSS compliant and that this compliance extends by default to all stores on the platform, covering the store, its cart and hosting.17 Shopify also says its checkout meets PCI DSS version 4 requirements with no additional merchant work required.18 Both statements are Shopify's own.
6. When the risk is manageable
None of this makes WooCommerce a bad platform. The risk is manageable when you have a developer or agency on retainer, a managed WordPress host with a web application firewall, a lean plugin list reviewed every quarter, and a real need for something Shopify cannot do, such as deep custom checkout logic without Shopify Plus or content-heavy sites where commerce is secondary.
If that is not your store, the risk is being carried by whoever happens to log in next. That is the conversation worth having.
Find out what moving would take, in 20 seconds.
- Free readiness scan of your store
- Plugin-by-plugin Shopify replacements
- Redirect count and complexity score
- Fixed price, preview before you pay
Sources
- Patchstack. State of WordPress Security in 2026 (covers 2025). security vendor
- Wordfence. 2024 Annual WordPress Vulnerability and Threat Report, April 2025. security vendor
- Sucuri. 2023 Hacked Website & Malware Threat Report, 39,594 cleaned sites. security vendor
- Sansec. Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts, 14 May 2026. security vendor
- WordPress.org. PHP version statistics, fetched 16 September 2026.
- The PHP Group. Supported versions and unsupported branches.
- Metorik. How Many Plugins Does the Average WooCommerce Store Use? 2026 data from 6,000+ stores. WooCommerce analytics vendor
- Chris Morris. Almost half the WordPress plugin directory has not been updated in two years, 27 June 2026. independent analysis
- HTTP Archive. Core Web Vitals Technology Report data, August 2026, based on the Chrome UX Report.
- Patchstack. State of WordPress Security in 2025 (covers 2024). security vendor
- HTTP Archive. Web Almanac 2025: Ecommerce, July 2025 crawl.
- Google, 55 and Deloitte. Milliseconds Make Millions, 2020. commissioned by Google
- Google/SOASTA Research. Find Out How You Stack Up to New Industry Benchmarks for Mobile Page Speed, 2017–2018.
- PCI Security Standards Council. Important Updates Announced for Merchants Validating to Self-Assessment Questionnaire A, 30 January 2025.
- PCI Security Standards Council. FAQ Clarifies New SAQ A Eligibility Criteria for E-Commerce Merchants, 28 February 2025.
- WooCommerce. PCI-DSS compliance and WooCommerce. published by WooCommerce
- Shopify. Is Shopify PCI compliant? published by Shopify
- Shopify. Simplifying PCI DSS Version 4 Compliance with Shopify's Checkout. published by Shopify
Figures are quoted as published. Where we calculated a percentage from published counts, the page says so. Mufatech Studio migrates stores to Shopify, so read our conclusions with that in mind; the numbers are from the sources above.