Site compromise
Someone changes your files, redirects or code. No personal information needs to be stored for this to hurt customers.
HONEST RISK, WITHOUT THE SCARE TACTICS
A neat percentage feels reassuring. It only helps when we know what was measured, whose data it represents, and over what period.
THE DIRECT ANSWER
There is no defensible public annual breach rate for “one indie author with static HTML” versus “one jeweler on old WordPress.” Traffic, patch state, plugins, credentials, host isolation, data retention and the providers used all change the outcome.
Our low / moderate / elevated judgments describe relative exposure under stated assumptions. They are editorial architecture assessments, not measured probabilities or insurance quotations.
of breaches in Verizon’s 2026 DBIR findings began with vulnerability exploitation.
This does not mean a 31% chance your website will be breached.Sources: Verizon: 2026 Data Breach Investigations Report findings (external) ↗
Someone changes your files, redirects or code. No personal information needs to be stored for this to hurt customers.
Personal information is exposed in a database, provider account, device, email or export. Exposure can exist without an observed theft.
An attacker actually obtains that person’s information. A compromised site does not imply every visitor’s data was taken.
HYPOTHETICAL MATH · NOT A RISK ESTIMATE
You choose the annual probability of at least one incident. This calculator does not measure your site or connect these values to any technology.
of at least one incident over 5 years, if the chosen assumptions were true.
1 − (1 − p)yearsAssumes independent years and an unchanged annual probability. Real threats, controls and exposures change. This is not the percentage of customers whose data would be stolen.
These numbers are hypothetical inputs chosen to demonstrate the calculation. None is assigned to WordPress, React, HTML or any provider.
| Assumed annual incident probability | Calculated chance over five years | Evidence about your own site? |
|---|---|---|
| 0.1% | 0.5% | No—illustration only |
| 1% | 4.9% | No—illustration only |
| 5% | 22.6% | No—illustration only |
| 20% | 67.2% | No—illustration only |
| Business / sensitive asset | Outdated WordPress | Static React, many dependencies | Simple HTML + JS | Actual annual theft % |
|---|---|---|---|---|
| Indie game designerSubscriber list + store identity | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
| Jewelry resellerAddresses + order histories | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
| Online hypnotherapistIntake + appointment metadata | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
| Indie musicianFan list + purchase records | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
| Educational nonprofitDonor + membership records | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
| Self-published authorLinks; optional reader list | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
| Hobby merch makerShipping + fulfillment records | Elevated avoidable exposure | Lower local storage exposure; moderate maintenance complexity | Lower local exposure with external collection | Unknown for all three |
Assumptions: the static options collect no payment PII and use hosted services; large React dependency trees get maintained; outdated WordPress contains unsupported or known-unpatched components. Extra forms, APIs, trackers or bad account practices can reverse these judgments. This is not a measured ranking.