Across 1,147 cpm-holy-kit WordPress sites indexed by TLDWP, compared to the all-WordPress average.
Security metrics currently cover 1,136 matching records in the cached metrics snapshot.
Grade A 0%Grade B 0%Grade C 9%Grade D 90%Grade F 0%
Fail the header check (F)0%vs 82.6% avg
Leak usernames61%vs 38.6% avg
Expose a sensitive file0%vs 1.8% avg
Use HTTPS98%vs 96.3% avg
What stands out
TLDWP currently associates 1,147 indexed WordPress sites with cpm-holy-kit, equivalent to 0% of the current WordPress dataset.
The largest measured difference is header-grade F: 0.4% versus 82.6% overall (-82.2 percentage points).
Username enumeration is 60.8% vs 38.6% overall (+22.2 pp); Sensitive-file exposure is 0% vs 1.8% overall (-1.8 pp); HTTPS adoption is 97.9% vs 96.3% overall (+1.6 pp).
These are observational associations among sites where TLDWP detected cpm-holy-kit, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.
Infrastructure patterns
Infrastructure detected alongside cpm-holy-kit. Percentages are within sites where that specific signal was detectable; the baseline compares the same signal across detected WordPress sites overall.
Co-occurrence describes technologies observed on the same sites. Detection coverage varies by signal, and an association does not imply that one technology caused or selected another.
Similar security profiles
Closest among widely detected plugins by average difference across header-grade F, username enumeration, exposed-file, and HTTPS rates.