# Security & Privacy Scorecard

## WordPress - Website Builder

## What This Means for You

Activity and crash data is shared with Firebase, Sentry, and Google. Support interactions go through Zendesk, a third-party service. Several serious code-level problems were found that put account and stored data at elevated risk.

## Recommendation: Use With Caution

**Best For:** WordPress users comfortable with standard analytics

## Key Findings

**Data Security** - 3 findings (1 critical, 1 high, 1 medium)

**Network Security** - 2 findings (1 high, 1 medium)

**Code Safety** - 0 findings

**Privacy** - 3 findings (2 high, 1 medium)

## Privacy Concerns

### What Data is Collected

WordPress collects in-app activity, device information, crash reports, and error logs. Any content shared during a support session is handled by Zendesk, a third-party customer service platform. Profile images are loaded through Gravatar, which may log requests associated with user email addresses.

### Third-Party Data Sharing

Data is shared with the following services:

- **Firebase** (Google): Activity tracking and crash reporting
- **Sentry**: Error and crash data collection
- **Zendesk**: Customer support interactions
- **Google Play Services**: Core platform functions
- **Tenor GIF**: GIF search and content delivery
- **Gravatar**: Profile image display

## Understanding the Scores

| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 55/100 |
| Data Security | 30/100 |
| Network Security | 50/100 |
| Code Safety | 35/100 |
| Data Collection | 60/100 |
| Data Sharing | 55/100 |
| User Control | 75/100 |

## Positive Security Features

No notable positive security practices were identified in this version of the app.

## Areas for Improvement

- The protection of account data and stored content needs significant strengthening to reduce the risk of unauthorized access.
- Connections between the app and external services should be made more robust to better protect user information while it travels across the network.
- The way sensitive data is stored on the device should be reviewed and hardened to prevent potential misuse.

---

## About This Analysis

### App Details

| Field | Value |
|---|---|
| App | WordPress - Website Builder |
| Package ID | org.wordpress.android |
| Version | 26.3.1 (versionCode 1478) |
| Scan Date | 2026-01-21 |

This scorecard is generated from automated static analysis of the app's code and behavior. Scores reflect the security and privacy practices observed at the time of the scan.
