WordPress – Website Builder Security & Privacy Scorecard
Android
Activity and crash data is shared with Firebase, Sentry, and Google. Support interactions go through Zendesk, a third-party service. Several serious code-level problems were found that put account and stored data at elevated risk.
Best for
WordPress users comfortable with standard analytics
Findings
- 3 critical
- 6 high
- 6 medium
- 2 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- SQL Injection in SavedParcelTable
- Hardcoded OAuth Client Credentials
- JavaScript Interface RCE in WebViews
Top privacy issues
- Extensive User Profiling with PII Collection
- Data Safety Disclosure Inaccurate - Third-Party Data Sharing
- Device Fingerprinting with Network Operator Tracking
Full analysis
WordPress - Website Builder
What This Means for You
Activity and crash data is shared with Firebase, Sentry, and Google. Support interactions go through Zendesk, a third-party service. Several serious code-level problems were found that put account and stored data at elevated risk.
Recommendation: Use With Caution
Best For: WordPress users comfortable with standard analytics
Key Findings
Data Security - 3 findings (1 critical, 1 high, 1 medium)
Network Security - 2 findings (1 high, 1 medium)
Code Safety - 0 findings
Privacy - 3 findings (2 high, 1 medium)
Privacy Concerns
What Data is Collected
WordPress collects in-app activity, device information, crash reports, and error logs. Any content shared during a support session is handled by Zendesk, a third-party customer service platform. Profile images are loaded through Gravatar, which may log requests associated with user email addresses.
Third-Party Data Sharing
Data is shared with the following services:
- Firebase (Google): Activity tracking and crash reporting
- Sentry: Error and crash data collection
- Zendesk: Customer support interactions
- Google Play Services: Core platform functions
- Tenor GIF: GIF search and content delivery
- Gravatar: Profile image display
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 55/100 |
| Data Security | 30/100 |
| Network Security | 50/100 |
| Code Safety | 35/100 |
| Data Collection | 60/100 |
| Data Sharing | 55/100 |
| User Control | 75/100 |
Positive Security Features
No notable positive security practices were identified in this version of the app.
Areas for Improvement
- The protection of account data and stored content needs significant strengthening to reduce the risk of unauthorized access.
- Connections between the app and external services should be made more robust to better protect user information while it travels across the network.
- The way sensitive data is stored on the device should be reviewed and hardened to prevent potential misuse.
About This Analysis
App Details
| Field | Value |
|---|---|
| App | WordPress - Website Builder |
| Package ID | org.wordpress.android |
| Version | 26.3.1 (versionCode 1478) |
| Scan Date | 2026-01-21 |
This scorecard is generated from automated static analysis of the app's code and behavior. Scores reflect the security and privacy practices observed at the time of the scan.
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #3 (current) | 45/100 | |
| #1 | 58/100 |