SEO & Website Marketing

WIX sites hacked

Estimate: Wix sites hacked but still undiscovered

Wix is a different problem from WordPress or Joomla. Owners do not patch a CMS. Wix hosts the site. A “hacked Wix site” almost never means a core exploit. It usually means the owner’s Wix account was taken over, or custom code / a third-party embed was abused.

How many Wix sites there are

Counts split the same way other platforms do:

  • Wix itself: ~304 million registered users and ~6.1 million premium subscriptions (end of 2025).
  • Industry write-ups: ~8–8.5 million live Wix websites.
  • BuiltWith-style live detections are lower, around ~2.9 million.
  • W3Techs: Wix is about 4.3% of all websites and ~6.1% of the known CMS market.

The useful base is published live sites, not 300 million signups. Call that about 3–8 million, midpoint ~5 million.

What “hacked” can mean on Wix

Wix’s own line is that platform sites are malware-free unless the owner adds unapproved third-party code (HTML embed / Velo). That is marketing, but the architecture is real: there is no public plugin directory for attackers to mass-scan.

The actual channels are:

  1. Account takeover — reused passwords, infostealers, phishing that impersonates Wix Support. This is the main one.
  2. Custom code / apps — HTML widgets, Velo, tracking scripts, form tools.
  3. Connected SaaS — email, payments, booking apps with stolen OAuth or API keys.
  4. Attacker-built Wix pages — criminals create Wix sites for phishing. Those are not victim sites that were hacked.

There is no Wordfence-style “N Wix sites infected this year.” Public incidents are thin: a 2023 log leak of ~425,000 emails/IPs (no passwords), fake “your Wix site has malware” phishing, and a 2025 Base44 auth-bypass that Wix said it found no customer impact from.

So infection rate should be far below self-hosted CMS rates (those were ~1–5% at a point in time). A hosted builder is closer to fractions of a percent.

A working range for currently compromised victim sites (taken-over account or injected content, not attacker-owned scam pages):

  • Low: ~2,000 (0.04% of 5 million)
  • Mid: ~8,000–15,000 (0.15–0.3%)
  • High: ~25,000–40,000 if you count every quiet SEO-spam / form-skimmer account takeover on free and neglected sites

That is a guess anchored in SaaS account-takeover rates, not a scan of the Wix fleet.

How many owners still do not know

Detection is worse than on WordPress in one way and better in another.

Worse: most Wix owners are small businesses and hobbyists. They notice a hack when Google flags the domain, checkout breaks, or customers complain — often weeks later.

Better: Wix can lock an account, strip malware from custom code, and see platform-wide abuse. Defacements and obvious malware get cleaned faster than on a neglected Joomla 3 box.

Same dwell-time pattern as other small-business sites still applies: most owners do not catch a quiet compromise in the first week. SEO spam, a hidden form, or a redirected mobile visitor can sit for months.

A fair split of current victim compromises:

  • 25–45% already known or about to be (Wix notice, Google, payment processor)
  • 55–75% still unknown to the owner

Estimate

For live Wix sites right now:

Piece Low Mid High
Currently compromised (victim sites) 2,000 10,000 30,000
Owner still unaware ~1,500 ~6,000–8,000 ~20,000


Best single estimate: on the order of 5,000–10,000 Wix sites are compromised today without the owner knowing.

That is much smaller than WordPress (hundreds of thousands) and smaller than Joomla (tens of thousands), even though Wix has more live sites than Joomla. The platform removes the plugin/EOL-core attack surface. What remains is mostly stolen logins and custom code.

If you also count attacker-created Wix phishing pages, the number of malicious Wix URLs is larger. Those are not undiscovered hacks of honest site owners.

Why this number is the softest of the three

  • No public scanner publishes a Wix infection census.
  • Wix does not report how many accounts it suspends for takeover.
  • “Hacked site” and “phishing page hosted on Wix” get mixed together in the wild.
  • Free, abandoned Wix sites can be taken over and never checked again.

So the honest statement is: Wix is not immune, but quiet victim compromises are likely in the low thousands to low tens of thousands, not a hidden epidemic on millions of sites.