Small Business SEO904-447-0750Take a Test Drive
About100K AI WebsiteGuidesBlogReviewsFAQsContact904-447-0750Take a Test Drive

WordPress · Security · Small Business

Updating WordPress Won't Save Your Site. Hundreds of These Holes Have No Fix.

At the end of March, Wordfence counted 747 known WordPress holes with no patch available at all. Not "Bob forgot to update." There is nothing to update to. And no screen in WordPress will tell you if one of them is on your site.

I charge in shouldering a chrome minigun while a grey alien in coveralls hauls a red plug-shaped sledgehammer and a battered robot head stamped with the WordPress logo pushes through a torn steel wall, a Barred Rock hen lunging across the foreground with a steel lever in its beak. Updating WordPress won't save your site. Hundreds have no fix.

For ten years, every person who has ever touched Bob's website told him the same thing.

Keep it updated and you will be fine.

His web guy said it. His host says it in the welcome email. The little badge on his dashboard says it every month without using words. Update, and you are doing your part. It is decent advice and I have given it myself, in writing, more than once.

Here is the part nobody says out loud. It only works when there is something to update to.

At the end of the first quarter of 2026, Wordfence counted 747 known WordPress vulnerabilities still sitting there with no patch available. (Wordfence, 2026) Not late. Not ignored. Not shipped and unclicked. Nobody has written a fix.

There is no button for those. There is no badge. There is no screen anywhere in WordPress that will tell you if one of them is on your site right now.

747 gaps, and nothing to pour into them.

There is no update to install.

That is not a warning. That is the whole situation.

TL;DR (the short answer)

No, updating WordPress does not cover you, because some holes have no update. At the end of the first quarter of 2026, Wordfence reported 747 known WordPress vulnerabilities that remained unpatched, meaning no fixed version exists. That number is falling, from 950 at the end of Q3 2025 and 905 at the end of Q4 2025, so the situation is improving. Wordfence's own advice when there is no patch is to remove the software. Nothing in the WordPress dashboard tells you whether one of your plugins is on that list.

3 Things to Remember

1
747 known WordPress holes had no fix available at the end of March 2026. Updating does nothing about any of them.
2
When there is no patch, the only move left is taking the software off your site.
3
WordPress has no screen that tells you if one of your plugins is on that list. You have to go look.

747 Holes. Nothing to Click. Nothing to Install.

I brace barefoot inside a huge steel ring stamped 747 HOLES, a blue tunnel of glowing empty bubbles behind it and a red plate below reading NOTHING TO INSTALL, while a grey alien in coveralls taps a tablet at the left and a chrome robot with a WordPress logo on its brow stands beside a Barred Rock hen at the right. 747 holes. Nothing to click. Nothing to install.

Wordfence publishes a threat report every quarter, and one line in it does not get talked about enough.

At the end of Q1 2026, 747 vulnerabilities remained unpatched. (Wordfence, 2026)

Every other WordPress security story you have read is about a gap in time. A hole gets found, a fix gets written, and the danger lives in the days or months before you install it. I wrote a whole post about that gap, because it is real and it is most of the problem.

This is a different thing. For these 747, the gap never closes. There is no version to move to. The developer walked away, or shut down, or read the report and decided not to bother, or never saw it at all.

The dashboard cannot help you with this. It is built to compare what you have against what exists, and when nothing exists, it has nothing to say. So it says nothing, which looks exactly like being fine.

747

known WordPress vulnerabilities with no patch available at the end of Q1 2026. (Wordfence, 2026)

2,738

WordPress vulnerabilities published in that same quarter, up 23.7% on the quarter before. That is the pile the 747 came out of. (Wordfence, 2026)

158

of those were rated high threat, the ones attackers are most likely to actually use. (Wordfence, 2026)

A Plugin Doesn't Announce That It Died.

I press defibrillator paddles onto a chrome robot laid out on a blue diagnostic board whose chest readout shows 0%, the banner above reading A PLUGIN DOESN'T ANNOUNCE and the red plate below reading THAT IT DIED, while a grey alien eats popcorn under a flatline monitor at the left, a Barred Rock hen drags an unplugged power cable across the floor, and a WordPress-badged cart robot holds up a blank clipboard at the right. A plugin doesn't announce that it died.

Here is how a plugin ends up in that 747, and it is not dramatic.

Somebody built a useful thing in 2016. It did one job well. Thirty thousand people installed it, including whoever built your site. For a few years the developer shipped updates.

Then life happened. A job, a kid, a business that never made enough money. The updates got further apart, then stopped.

Nothing on your site changed the day that happened. The plugin still works. It still shows a green checkmark. It sits there doing its job, and the only difference is that there is now nobody on the other end.

Then somebody finds a hole in it. They report it properly. The report goes out into the world with a tracking number. And the email to the developer bounces, or lands in an inbox nobody opens anymore.

Now the hole is public, the code is on your site, and there is no fix coming. Ever.

The mistake: thinking a plugin that still works is a plugin that is still maintained.

The fix: check the last-updated date on every plugin you run. It is on the plugin's own page on WordPress.org.

The payoff: you find the dead ones before somebody else does.

I have said for years that the plugin pile holds you hostage because you cannot safely pull anything out of it. This is the other half of that. Some of what is in the pile is not just risky. It is abandoned.

Nobody has touched this one in years. There is no update coming.

Wordfence's Own Advice Is to Delete It.

I haul back on a long red lever bolted to a steel machine whose housing reads WORDFENCE'S OWN ADVICE, the lever's red arm plate reading IS TO DELETE IT, while a Barred Rock hen bites down on the same lever, a grey alien in coveralls holds a clipboard in the shadows behind me, and a robot wearing the blue Wordfence shield is fed into a blue-lit chute at the right. Wordfence's own advice is to delete it.

This is the part I want you to sit with, because it comes from the security company, not from me.

In their own Q1 2026 report, writing about these unpatched vulnerabilities, Wordfence says the action to take is remedial action "like removing the software." (Wordfence, 2026)

That is a security firm telling site owners that for hundreds of known holes, the fix is not a patch. It is a shovel.

Think about what that means on a real site. Bob has fifteen plugins. Some of them are load-bearing. The form one, the booking one, the one his checkout runs through. "Remove the software" is an easy sentence to write and a hard afternoon to live through, because on a WordPress site you often cannot tell what else breaks when you pull one out.

That is the trap, and it is worth naming plainly. The recommended fix for these holes is the one action a stacked WordPress site makes most expensive.

The mistake: assuming there is always a safe middle option between "patch it" and "pull it."

The fix: find out today which of your plugins you could actually remove without breaking the site.

The payoff: when you do have to pull one, it is a decision instead of a crisis.

When there is no patch, the only move left is taking it off the site.

How to Check Your Own Fifteen.

I crank a heavy iron handwheel beside a conveyor of black canisters, each stamped with a different plugin icon, feeding into a blue-lit tunnel under a wall sign reading HOW TO CHECK, with a red camera lens ring in the foreground lettered YOUR OWN FIFTEEN. A grey alien raises a multi-lens scope beside a rusted robot at the left, and a Barred Rock hen leans in over the lens at the right. How to check your own fifteen.

You cannot look up the 747 as a list and match it against your site. That is the honest answer and I am not going to pretend otherwise.

What you can do is find the plugins most likely to be in it, and it takes about fifteen minutes.

  • Pull your plugin list. Dashboard, then Plugins. Write down every name and version.
  • Open each one's page on WordPress.org. Put the plugin's short name on the end of wordpress.org/plugins/. Two things matter on that page. The last updated date, and whether there is a red closure bar at the top.
  • Flag anything over a year old. A plugin that has not shipped anything in a year is not necessarily vulnerable. It is the profile that ends up in the 747.
  • A red closure bar means stop. That plugin was pulled from the directory. It does not disappear from your site on its own. If you have it, you still have it, running, today.
  • Ask what breaks. For each flagged plugin, find out what on your site depends on it before you touch anything.

That list will not be perfect. It will find the worst of it, which is the part that matters.

Do it yourself

Find the Plugins on Your Site That Nobody Is Maintaining

Open your WordPress dashboard, go to Plugins, and copy the list. Paste it in and hit a button. Claude or ChatGPT checks each one against its page on WordPress.org and tells you which ones look abandoned, which are closed, and what breaks if you pull them. Takes about three minutes.

Prompt · Which of my plugins are dead
You are a plain-talking website helper. Here is every plugin on my WordPress site: [PASTE YOUR PLUGIN LIST].

For each one, check its page on WordPress.org and show me a simple table.
1) The plugin name and its page address on WordPress.org.
2) The date it was last updated.
3) Whether that page shows a red closure notice, and if it does, the date and the reason word for word.
4) How many sites run it.
5) A plain-English guess at what my site uses it for.

Then give me three short lists.
A) Plugins with no update in over a year.
B) Plugins that have been closed or removed from the directory.
C) For each plugin in A and B, what is likely to break on my site if I remove it, and what a replacement would be.

Rules: short sentences, 5th grade words. If you cannot confirm something, say you cannot confirm it instead of guessing.

Paste your plugin names where it says PASTE YOUR PLUGIN LIST.

You get: a list of the plugins on your own site that nobody is looking after, and a straight answer on what breaks if you pull each one.

The Number Is Going the Right Way, and That Deserves Saying.

I lean back hard on a wrench against the geared rollers of a giant press, its top drum lettered THE NUMBER IS GOING THE RIGHT WAY and a red band around the lower drum reading AND THAT DESERVES SAYING. A small grey alien in a tuxedo sits on top blowing a blue air horn, an oversized Barred Rock hen hauls a red bar in from the left, and a chrome robot with the WordPress logo on its face reaches in from the right. The number is going the right way, and that deserves saying.

I am not going to run a scary number past you and skip the context.

747 is the lowest of the last three quarters. It was 950 at the end of Q3 2025 and 905 at the end of Q4 2025. (Wordfence, 2026)

Quarter endStill unpatched
Q3 2025950
Q4 2025905
Q1 2026747

That is a real drop, and it happened while the total number of reported vulnerabilities went up. More holes are being found and more of them are getting fixed. The people doing that work are winning ground.

Plenty of the 747 are also in plugins almost nobody runs, and plenty are low severity. The odds that one specific abandoned plugin is on one specific small business site are not high.

I Didn't Just Write About It. I Left.

This is not a number off somebody's chart. I moved 1,300+ of my own posts off a dying WordPress stack, and the reason was not one big scare. It was getting tired of being the guy responsible for other people's abandoned code.

I have built more than 10,000 sites in 25 years. I have pulled dead plugins out of enough of them to know how that phone call starts. It always starts with somebody saying the site has been fine for years.

You are reading one of those rebuilt pages right now. Nothing on it was written by somebody who stopped answering their email in 2019.

You Can't Abandon Code That Isn't There.

I drag a heavy chain and wrecking ball out through the open faceplate of a giant chrome robot head, its brow lettered YOU CAN'T ABANDON CODE and the red plate under the opening reading THAT ISN'T THERE. A grey alien in coveralls runs a jackhammer into the rubble inside, a WordPress-badged robot holds the other end of the chain at the right, and a Barred Rock hen drags a steel panel across the front. You can't abandon code that isn't there.

The reason my builds do not have this problem is boring. There is nothing on the site written by somebody who could walk away from it.

A WordPress site is a stack of businesses. Fifteen plugins is fifteen companies that can fold, get sold, or quietly stop caring, and your site keeps running their code either way. You did not sign anything with any of them.

The sites I build are already built. The pages are finished files sitting on a fast network. The features are part of the build, so there is no third party to go quiet on you.

That is not me being clever. It is fewer moving parts, and none of them belong to a stranger. That is the whole idea behind the 100K Website, and it is why I say the old machine is done for real business sites.

And keeping it current is my job, not yours. You go run your business.

Where Staying Updated Genuinely Is Enough.

Most weeks this points you right. That is the honest half.

Let me give the other side its full due, because most weeks it is right.

Updating is still the single highest-value thing a WordPress owner does. The overwhelming majority of WordPress sites that get hacked were running something with a patch available that nobody installed. If you do nothing else, do that.

And the reporting system around WordPress works. Researchers find these holes, they get tracking numbers, security firms publish them, and the unpatched count has fallen for three quarters running. That is a lot of people doing unglamorous work well.

Now the turn. All of that good work still lands on one person's shoulders, and for these 747 it lands there with nothing in its hands. Bob has no idea whether one of his fifteen plugins is on that list. There is no screen that will tell him. And the recommended fix, pulling the software off the site, is the exact thing his site is built to make impossible.

You should not have to audit fifteen strangers' software between jobs.

Keeping a website current is a real job. It is just not your job, and it should not be the thing standing between your business and a hole nobody is going to fix.

Let me show you what a site with nothing on it to abandon actually feels like, built on your own market.

Take a Test Drive →

You get a real look at your own market. No obligation, and nothing to cancel.

Want the whole playbook first? Plan your attack. Balls Out Marketing.

FAQ

Does updating WordPress keep my site safe?

Mostly, but not completely. Updating covers every hole that has a fix, and that is most of them. At the end of Q1 2026 there were 747 known WordPress vulnerabilities with no patch available at all, and no update covers those.

What is an unpatched WordPress vulnerability?

It is a known security hole in a plugin, theme or core with no fixed version available. Somebody found it and reported it publicly, but no fix was ever written, usually because the developer stopped maintaining the software.

How many WordPress vulnerabilities have no fix?

Wordfence reported 747 still unpatched at the end of the first quarter of 2026. That is down from 905 at the end of Q4 2025 and 950 at the end of Q3 2025.

What do I do if a plugin on my site has no patch?

Wordfence's own advice is to remove the software. Before you do, find out what on your site depends on it, because on a stacked WordPress site pulling one plugin can take features down with it.

How can I tell if a plugin has been abandoned?

Open its page at wordpress.org/plugins/ and look at the last updated date. Anything over a year old is worth flagging. If there is a red closure bar at the top, that plugin was pulled from the directory, and it does not remove itself from your site.

Will WordPress warn me about an unpatched vulnerability?

No. The dashboard compares your version against the newest available version. When no fixed version exists, there is nothing for it to compare against, so it shows you nothing at all.

Are all 747 of these dangerous to me?

No. Many are in plugins almost nobody runs and many are low severity. The problem is not the size of the number, it is that nothing on your site tells you whether one of yours is in it.

This is post 5 in a run on WordPress security. Post 4 covered the fix that shipped in March and was still being attacked in June. That one was about a patch nobody installed. This one is about the holes where there is no patch to install.

Check Out My Last 3 Builds

Real sites, built with this exact system. Tap any one and poke around.

Two Men and a Truck
Moving company
See it live →
Learn Euphoria
Education & courses
See it live →
SoFresh
Fast-casual food
See it live →
Small Business SEO · Jacksonville, FL · Go Balls Out.

Get 2 Must-Read Resources Every Week

No spam. No pitch. Just 2 Must Read Resources a Week.

By downloading, you agree to our Privacy Policy. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.