Research on the upkeep live websites need: outdated WordPress, Drupal and PHP versions, abandoned plugins, JavaScript libraries with known security flaws, missing security headers and firewalls, SSL gaps and expiring domain names. The data comes from the public HTTP Archive crawl of 15.5 million websites, Google's Chrome UX Report popularity ranking, the WordPress.org plugin directory and release list, websites linked from US Google Business Profiles, and public domain registration (WHOIS) records. Use it to see how common each problem is and what regular maintenance is worth to you.
44.5% of WordPress sites that show their version are not on the current 7.1 release, and 29.9% are more than one major release behind. The most visited WordPress sites are behind the latest release almost as often, at 41.4%.
61.6% of websites do not send HSTS, the one-line setting that tells browsers to always use a secure connection. Even among the 10,000 most popular sites, 48.7% skip it.
48.1% of websites that publish their PHP version run PHP 8.1 or older, releases that no longer receive security fixes. That is more than a million homepages, and a third of them are still on PHP 7 or PHP 5.
About 28% of websites, more than 4.3 million homepages, load a version of a common JavaScript library with a publicly documented security flaw. Old copies of jQuery account for the most websites, on 3,428,748 homepages.
83% of PrestaShop websites that show their jQuery version run one older than 3.5.0, the release that fixed two published security flaws, against 36.1% of all websites that show a version. Self-hosted store platforms lag the web, and so do the most visited websites: 44.3% of the top 10,000 that use jQuery run a flawed version.
58% of websites outside the 10 million most visited, the long tail where most small businesses sit, have no web application firewall or similar security layer in front of them. Among the 10,000 most visited websites, 34.4% have none.
87.3% of websites that show their Bootstrap version run Bootstrap 4 or older, versions that no longer receive fixes. Bootstrap 3, unsupported since July 2019, is still the most common version, on 1,001,551 homepages.
8.4% of WordPress sites among the 500,000 most visited websites, about one in twelve, load a plugin that has not been updated in two years or that WordPress.org has closed for a security issue. The average WordPress homepage loads 5.2 plugins, and the security plugin most sites show is Really Simple SSL, installed on nearly all of the 11.4% that show one.
26.6% of Drupal websites that show their version run Drupal 7, 8 or 9, releases that have reached end of life and no longer get security fixes. Drupal 7, retired in January 2025, is still the most common of the three.
Custom-built law firm websites have no SSL certificate 5% of the time, more than 16 times the 0.3% of law firm websites on WordPress, and across six industries not one website built on Wix is without a certificate. Plumbing websites are the most likely to go without, at 3.3%, nearly twice the 1.8% of restaurant websites.
17% of accounting firm websites run outdated software, the highest rate of 15 industries and more than three times the 4.7% of restaurant websites. In every one of the 15 industries, websites built on WordPress are out of date more often than websites on other platforms.
11.5% of small business domain names were due to expire within 60 days, and 73% come up for renewal within a year. The rest of the upkeep list is just as easy to miss: 8.5% of small business websites link to their own dead pages, 3.8% fail a security certificate check and 1.4% break with a server error on an inner page.
Sep 24, 2026
Make Search Your Best Channel
Stop guessing. Start growing.
Get a tailored growth plan for your site, backed by a senior team with 20+ years shipping results.