Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Incidents & Breaches Awesome Motive

OptinMonster CDN breach exposes WordPress sites to backdoors

A supply-chain attack on Awesome Motive’s CDN compromised three WordPress plugins, installing rogue admin accounts and hidden backdoors on affected sites.

OptinMonster CDN breach exposes WordPress sites to backdoors
Clay Banks · Unsplash

A security breach in Awesome Motive’s content delivery network (CDN) has exposed WordPress sites using OptinMonster, TrustPulse, and PushEngage plugins to a supply-chain attack. The incident, discovered by e-commerce security firm Sansec, involved malicious JavaScript served to users of these plugins, enabling attackers to gain full control over compromised websites. The attack highlights risks associated with third-party CDN dependencies and the challenges of securing plugin ecosystems at scale.

What happened

On June 12, attackers exploited a known vulnerability in the UpdraftPlus WordPress plugin to gain access to a non-production server within Awesome Motive’s environment. While the server hosted only a marketing website and was isolated from production systems, it contained credentials for the company’s CDN account. The intruders stole these credentials and used them to modify JavaScript files distributed via the CDN, injecting malicious code into three plugins: OptinMonster, TrustPulse, and PushEngage.

The malicious scripts activated when WordPress administrators visited pages on infected sites, harvesting authentication tokens and nonces. These were used to create rogue administrator accounts, such as developer_api1 or dev_xxxxxx, and install a self-hiding backdoor plugin. The backdoor, disguised as legitimate tools like Content Delivery Helper or Database Optimizer, provided attackers with remote access capabilities, including a web shell and arbitrary PHP code execution. Sansec noted that the plugin’s logic remained identical across renames, suggesting a deliberate effort to evade detection.

OptinMonster, the most widely affected plugin with over 1.2 million active installations, served malicious code between 22:17 UTC and 22:42 UTC on June 12. TrustPulse was similarly compromised during this window, while PushEngage continued delivering infected JavaScript until 19:02 UTC the following day. Awesome Motive confirmed the breach in a security advisory, stating that the attack did not compromise its application servers, source code, or customer data storage systems.

Key facts
  • Affected plugins: OptinMonster, TrustPulse, PushEngage
  • Malicious files: JavaScript served from a.omappapi.com, a.opmnstr.com, a.optnmstr.com, a.trstplse.com
  • Attack window: June 12, 22:17–22:42 UTC (OptinMonster/TrustPulse); until June 13, 19:02 UTC (PushEngage)
  • Rogue admin accounts: developer_api1, dev_xxxxxx
  • Backdoor plugins: Disguised as Content Delivery Helper (v2.7.1) or Database Optimizer (v2.9.4)

Impact and remediation

The attack’s design—targeting administrators specifically—allowed attackers to bypass traditional security measures and establish persistent access to compromised sites. The rogue admin accounts and backdoor plugins remain active even after the malicious CDN content was removed, requiring manual intervention from site owners. Awesome Motive has since rotated all credentials, migrated the affected marketing site to a new server, and revoked the compromised CDN API key.

Site owners are advised to take immediate steps to mitigate the breach’s effects. These include scanning for and removing rogue admin accounts, inspecting the wp-content/plugins directory for hidden backdoor plugins, and running server-side malware scans. Additionally, rotating administrator passwords, API keys, database credentials, and WordPress security salts is critical to prevent further unauthorized access. Failure to remove the backdoor plugins leaves sites vulnerable to ongoing exploitation, even after the CDN-level threat has been neutralized.

For professionals

For professionals: This incident underscores the importance of segmenting non-production environments from critical infrastructure, even when they appear low-risk. CDN credentials should be treated as high-value targets, with strict access controls and monitoring for unusual activity. Plugin developers should also consider implementing integrity checks for distributed files to detect unauthorized modifications early.

Broader implications

The breach reflects growing risks in the WordPress plugin ecosystem, where supply-chain attacks can rapidly scale due to widespread adoption of popular tools. OptinMonster’s large user base—over a million sites—amplified the attack’s reach, demonstrating how a single vulnerability can cascade across thousands of unrelated websites. The use of a CDN to distribute malicious code further complicates detection, as the attack leverages trusted infrastructure to evade scrutiny.

Sansec’s findings also highlight the sophistication of modern supply-chain attacks. By impersonating legitimate services (e.g., a domain mimicking Tidio) and rotating backdoor disguises, attackers can maintain access long after the initial breach. This incident serves as a reminder for security teams to monitor not only direct threats but also indirect vectors, such as third-party dependencies and CDN-delivered content.

Companies mentioned

Awesome Motive OptinMonster PushEngage Sansec TrustPulse UpdraftPlus

Discussion · coming soon

Be the first to join the thread when community discussion launches.