SEO & Website Marketing

How many WordPress sites are hacked?

Estimate of WordPress sites hacked but not discovered

There is no census of “hacked but nobody noticed.” This is an estimate from market size, scanner data, and how long infections typically sit before an owner finds out.

What we can measure

How many WordPress sites exist

Counts diverge because “a WordPress site” can mean a live, visited site or every hostname that once ran WordPress:

  • Crawlers of live sites typically land in the ~23–38 million range.
  • Applying WordPress’s ~41–43% share of all websites to billions of hostnames produces hundreds of millions, including parked, staging, and dead properties.

For hacks that matter (spam, redirects, backdoors, skimmers), the useful base is active sites, roughly 30–40 million.

How many get infected

Vendor numbers are not a global count, but they bound the problem:

  • Wordfence reported just under 1 million WordPress sites infected with malware in 2024, with ~325,000–350,000 infected on a typical day.
  • Wordfence’s Q1 2026 telemetry still showed ~474,000 sites with malware in that quarter.
  • Sucuri SiteCheck (all platforms, 2024) found infections in 1.66% of ~71 million scans.
  • Marketing pieces often repeat ~13,000 WordPress hacks per day (~4.7 million/year). That is widely cited and almost certainly inflated relative to Wordfence’s infection counts. Treat it as an upper-bound rumor, not a measurement.

A defensible point-in-time stock of currently compromised active WordPress sites is on the order of a few hundred thousand to about a million (about 0.4–1.0 million), not tens of millions.

How many of those are still unknown to the owner

Most WordPress compromises are not homepage defacements. They are SEO spam, conditional redirects, form skimmers, and backdoors designed not to be obvious. Owners usually learn from Google Safe Browsing, a host, a customer, or a traffic drop—not from watching logs.

A 2025 study of 600 hacked business sites found:

Time until the business noticed Share
Less than 1 week 2%
1–4 weeks 16%
1–2 months 38%
3–6 months 24%
7–12 months 15%
1+ year 5%


So ~82% took more than a month and ~44% took 3+ months.

Typical WordPress owners have no security team. Small-site writeups commonly describe weeks to many months before anyone looks. Security plugins help, but they do not close the gap: researchers have found large numbers of infected sites that already ran Wordfence or similar tools.

A reasonable split of currently infected sites:

  • ~20–40% already known or about to be (scanners, hosts, Google)
  • ~60–80% still unknown to the owner

Estimate

For active WordPress sites, right now:

Piece Low Mid High
Currently compromised 300,000 550,000 1,000,000
Owner still unaware ~200,000 ~350,000–450,000 ~700,000


Best single estimate: on the order of 300,000–500,000 WordPress sites are compromised today without the owner knowing.

If you include abandoned and barely maintained installs, the “hacked and nobody is looking” pool is larger—easily high six figures to low seven figures—because those sites can sit with backdoors for years.

Why the range is wide

  • “Hacked” mixes malware, SEO spam, stolen admin sessions, and one-off defacements.
  • Scanner datasets over-sample people who already suspect a problem, or under-sample sites with no security plugin.
  • New infections arrive continuously; old ones linger. The stock of unknown hacks is mostly dwell time, not the daily “hacked today” headline.
  • No organization measures every WordPress compromise on the public web.

So: not “millions of secret hacks on half a billion sites,” and not a rounding error either. For living WordPress sites, a few hundred thousand quiet compromises is the most honest current estimate.