Post

Tech Security – New Zealand: every 8th website runs with a known security flaw!

Tech Security – New Zealand: every 8th website runs with a known security flaw!

Source: Piperic Research

We analysed 59 million websites with the help of AI. The result is dismal.

We examined 120,989 live websites in New Zealand. Of these, 35,158 use WordPress, and where the version number was also visible (26,955 sites), 14,583 — that is 54.1% — run a plugin or theme that contains a publicly known security flaw.

Across the websites examined in New Zealand that means 1 in 8, and this is only the lower bound: sites that hide their version number were not counted at all. This shows how poorly these systems are kept up to date!

We requested each homepage once: HTTPS first, plain HTTP only if that failed, and nothing after it. No password was tried, no port was scanned, no form was submitted.

  • 13.1% of the live sites we reached answered over plain HTTP — HTTPS was attempted first on both the apex and the www host.
  • 50 pages present a password field on a page that was itself delivered without encryption.
  • 39.1% of the measured WordPress sites publish a component version whose record carries CVSS “privileges required: none” — documented as needing no account. We tested reachability nowhere.
  • 21 sites carry hidden blocks of links to unrelated domains. A homepage cannot tell us whether the owner knows about them.
  • 3 sites display text pointing to deliberate destruction of the web page — known in the trade as defacement. This is a snapshot, not a rate of break-ins over time.

Full report for New Zealand: New Zealand security report
Global report and all 59 countries: Global security report
Methodology — definitions, denominators and every bias we know about: Methodology

MIL OSI