Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Incidents & Breaches ShapedPlugin

ShapedPlugin supply-chain breach infects WordPress plugins

A compromised update pipeline at a WordPress plugin vendor delivered malware to paying customers for nearly three weeks.

ShapedPlugin supply-chain breach infects WordPress plugins
David Egon · Pexels

WordPress site administrators using premium plugins from ShapedPlugin were exposed to a supply-chain attack that distributed malware through the vendor’s official update mechanism. The breach affected only paid versions of three plugins, leaving free variants and WordPress.org-hosted releases untouched. ShapedPlugin confirmed the incident after security researchers identified the malicious payloads in customer downloads earlier this month.

What happened

On 21 May 2026, attackers compromised ShapedPlugin’s build pipeline, injecting a malicious loader into three premium plugins: Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro. The first reports of suspicious updates appeared on 10 June, when customers noticed unusual behavior after installing recent plugin versions. Security firm Defiant, which operates the Wordfence firewall, confirmed the breach on 12 June after downloading and analyzing infected plugin files from ShapedPlugin’s website.

The malware operated in two stages. When a WordPress administrator logged into an infected site, a hidden loader file (LicenseLoader.php) contacted a command-and-control server, downloaded a second-stage backdoor, and installed it as a fake plugin disguised as a WooCommerce component. The backdoor then erased the loader to avoid detection. Once active, it harvested sensitive data, including WordPress credentials, database access keys, SMTP configurations, and WooCommerce order details from the previous three months. The malware also targeted two-factor authentication secrets from popular security plugins and created rogue administrator accounts.

ShapedPlugin acknowledged the breach on 16 June, stating that it had initiated an investigation and implemented measures to contain the issue. The company released patched versions of the affected plugins—Product Slider Pro 3.5.4, Real Testimonials Pro 3.2.6, and Smart Post Show Pro 4.0.2—though it waited for Wordfence to verify the fixes before notifying customers. The incident is now tracked under CVE-2026-10735, with a duplicate entry filed as CVE-2026-49777.

Key facts
  • Compromise window: 21 May – 16 June 2026 (malicious updates distributed)
  • Affected plugins: 3 premium plugins (free versions unaffected)
  • Active installations: Over 400,000 (free plugins only; paid user count undisclosed)
  • Data stolen: Credentials, 2FA secrets, database keys, WooCommerce orders
  • CVE assigned: CVE-2026-10735

How the attack unfolded

The attackers gained access to ShapedPlugin’s release infrastructure, allowing them to modify plugin builds before distribution. Unlike a recent breach at OptinMonster—where a misconfigured marketing server exposed CDN credentials—this incident stemmed from a direct compromise of the build pipeline. Evidence includes automated injection patterns, Git build references in the malicious packages, and clean releases on WordPress.org, which uses a separate distribution channel.

The fake plugin installed by the malware remained hidden from the WordPress dashboard, making manual detection difficult. It targeted a broad range of sensitive data, prioritizing credentials that could enable further exploitation, such as persistent access to the site or exfiltration of customer payment details. The attack’s focus on WooCommerce order data suggests a financial motive, though no evidence has emerged linking the breach to specific fraud or ransomware campaigns.

What site owners should do

Administrators who installed updates for the affected plugins between 21 May and 16 June should assume their sites are compromised. Recommended steps include:

  • Resetting all WordPress passwords and regenerating authentication keys in wp-config.php
  • Reviewing user accounts for unauthorized administrators
  • Rotating SMTP and database credentials
  • Scanning for the fake plugins (woocommerce-subscription or woocommerce-notification) and removing them
  • Updating to the latest patched versions of the affected plugins

ShapedPlugin has not disclosed how the attackers breached its build system, but the incident highlights the risks of supply-chain attacks in the WordPress ecosystem. Even vendors with established security practices can become targets, particularly when attackers exploit automated update mechanisms to distribute malware at scale.

Companies mentioned

ShapedPlugin Defiant (Wordfence) WooCommerce

Discussion · coming soon

Be the first to join the thread when community discussion launches.