WordPress – Website Builder Security & Privacy Scorecard

Android

45
Overall trust score
Unsafe
35
Security
55
Privacy

Activity and crash data is shared with Firebase, Sentry, and Google. Support interactions go through Zendesk, a third-party service. Several serious code-level problems were found that put account and stored data at elevated risk.

Best for

WordPress users comfortable with standard analytics

Findings

  • 3 critical
  • 6 high
  • 6 medium
  • 2 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • SQL Injection in SavedParcelTable
  • Hardcoded OAuth Client Credentials
  • JavaScript Interface RCE in WebViews

Top privacy issues

  • Extensive User Profiling with PII Collection
  • Data Safety Disclosure Inaccurate - Third-Party Data Sharing
  • Device Fingerprinting with Network Operator Tracking

Full analysis

WordPress - Website Builder

What This Means for You

Activity and crash data is shared with Firebase, Sentry, and Google. Support interactions go through Zendesk, a third-party service. Several serious code-level problems were found that put account and stored data at elevated risk.

Recommendation: Use With Caution

Best For: WordPress users comfortable with standard analytics

Key Findings

Data Security - 3 findings (1 critical, 1 high, 1 medium)

Network Security - 2 findings (1 high, 1 medium)

Code Safety - 0 findings

Privacy - 3 findings (2 high, 1 medium)

Privacy Concerns

What Data is Collected

WordPress collects in-app activity, device information, crash reports, and error logs. Any content shared during a support session is handled by Zendesk, a third-party customer service platform. Profile images are loaded through Gravatar, which may log requests associated with user email addresses.

Third-Party Data Sharing

Data is shared with the following services:

  • Firebase (Google): Activity tracking and crash reporting
  • Sentry: Error and crash data collection
  • Zendesk: Customer support interactions
  • Google Play Services: Core platform functions
  • Tenor GIF: GIF search and content delivery
  • Gravatar: Profile image display

Understanding the Scores

Category Score
Security 35/100
Privacy 55/100
Data Security 30/100
Network Security 50/100
Code Safety 35/100
Data Collection 60/100
Data Sharing 55/100
User Control 75/100

Positive Security Features

No notable positive security practices were identified in this version of the app.

Areas for Improvement

  • The protection of account data and stored content needs significant strengthening to reduce the risk of unauthorized access.
  • Connections between the app and external services should be made more robust to better protect user information while it travels across the network.
  • The way sensitive data is stored on the device should be reviewed and hardened to prevent potential misuse.

About This Analysis

App Details

Field Value
App WordPress - Website Builder
Package ID org.wordpress.android
Version 26.3.1 (versionCode 1478)
Scan Date 2026-01-21

This scorecard is generated from automated static analysis of the app's code and behavior. Scores reflect the security and privacy practices observed at the time of the scan.

Versions & scan history

ScanDateOverall score
#3 (current) 45/100
#1 58/100