WordPress powers 43% of all websites. The popular open-source CMS can be extended with plugins, which are files containing code executed when visitors browse your website. But plugins also increase the attack surface of a website. To reduce the risk of a breach, a plugin selection strategy can be useful.