Across 260 practice WordPress sites indexed by TLDWP, compared to the all-WordPress average.
Grade A 1%Grade B 0%Grade C 1%Grade D 0%Grade F 98%
Fail the header check (F)98%vs 82.5% avg
Leak usernames4%vs 38.5% avg
Expose a sensitive file0.4%vs 1.8% avg
Use HTTPS97%vs 96.2% avg
What stands out
TLDWP currently associates 260 indexed WordPress sites with practice, equivalent to 0% of the current WordPress dataset.
The largest measured difference is username enumeration: 4.2% versus 38.5% overall (-34.3 percentage points).
Header-grade F is 97.7% vs 82.5% overall (+15.2 pp); Sensitive-file exposure is 0.4% vs 1.8% overall (-1.4 pp); HTTPS adoption is 97.3% vs 96.2% overall (+1.1 pp).
These are observational associations among sites where TLDWP detected practice, not evidence that the technology, provider, or domain attribute caused a security outcome. See the overall WordPress security baseline.
Infrastructure patterns
Infrastructure detected alongside practice. Percentages are within sites where that specific signal was detectable; the baseline compares the same signal across detected WordPress sites overall.
Co-occurrence describes technologies observed on the same sites. Detection coverage varies by signal, and an association does not imply that one technology caused or selected another.
Similar security profiles
Closest among widely detected themes by average difference across header-grade F, username enumeration, exposed-file, and HTTPS rates.