cms

WordPress

WordPress powers a very large share of the world’s websites, which also makes it the single most-targeted CMS. ScanMalware identifies it from its generator meta tag, wp-content and wp-includes paths, and theme and plugin asset fingerprints.

The platform’s huge plugin ecosystem is its main attack surface: outdated plugins are a leading cause of site compromise, defacement and malware injection. A WordPress detection is a strong cue to look closely at injected scripts, unexpected redirects and the overall security verdict.

Public scans
62,961
Category
cms
Co-detected technologies
14
Versions observed
185

Commonly deployed alongside WordPress

Of the 62,961 public scans where WordPress was detected, these are the technologies most often present on the same site. The share is the percentage of WordPress sites that also ran each one.

TechnologyCategoryShare of WordPress sites
PHPwappalyzer
78.56%
MySQLwappalyzer
78.31%
MetaGeneratormiscellaneous
66.6%
JQuerymiscellaneous
61.5%
jQuerywappalyzer
60.03%
Open-Graph-Protocolmiscellaneous
59.67%
HTTP/3wappalyzer
39.76%
Google Analyticswappalyzer
35.52%
Cloudflarewappalyzer
34.07%
Cloudflare Bot Managementwappalyzer
29.97%
Google-Analyticsmiscellaneous
28.24%
PoweredBymiscellaneous
27.05%
HSTSwappalyzer
26.45%
Google Tag Managerwappalyzer
21.64%

How ScanMalware detects WordPress

WordPress is detected from generator meta tags, characteristic URL paths and login endpoints, and the theme and plugin asset fingerprints it exposes.

From any scan you can pivot into related signals — JARM TLS fingerprints, ASN ownership and BGP routing, certificate history, JavaScript analysis and the overall security verdict — to understand not just that WordPress is present, but how it is being used. Open the full search interface for WordPress →

Recent public scans featuring WordPress

A rolling sample of recent public scans where WordPress was detected. Listing a site here is not a safety judgement — open a scan to see its full verdict.

SiteScanned
Home | Minimum HRA
https://sarki.se
2026-09-26
Hem
https://hkhassle.se
2026-09-26
Tillgänglighet på autopilot - Semantivo
https://semantivo.se
2026-09-26
www.fastighetsjuridik.se
https://lj-fastighetsjuridik.se
2026-09-26
Boka Flyttstäd/Flyttstädning i Göteborg - Göteborgs Flyttstäd ✅
https://goteborgsflyttstad.se
2026-09-26
Byta/Lägga nytt avlopp i Borås, Skene & Härryda - Bytaavlopp.se
https://bytaavlopp.se
2026-09-26
Västerviktorget.se - Annonsera gratis på Västerviks bästa och största köp & sälj marknad
https://vasterviktorget.se
2026-09-26
Gothenburg Free Fencers Guild | Diversity equals strength
https://gffg.se
2026-09-26

Frequently asked questions about WordPress

Does using WordPress mean a website is unsafe?
No. WordPress is a stack component, not a verdict. ScanMalware scores the whole page — its scripts, redirects, certificates, threat-intelligence matches and behaviour — so a site using WordPress can be perfectly safe or actively malicious.
How many sites using WordPress has ScanMalware scanned?
WordPress has been detected in 62,961 public scans on ScanMalware.com. Each scan is a real headless-browser visit, and the figure updates as new URLs are submitted.
What technologies are commonly used with WordPress?
Across scanned sites, WordPress is most often seen alongside PHP, MySQL and MetaGenerator. The full co-occurrence breakdown is listed on this page.

Browse all profiled technologies on the technology index, or scan a URL to see its full stack.