WooCommerce to Shopify
You are not running WooCommerce. You are running fifty-eight plugins.
That is the average across a sample of 6,000+ stores, rising to 66 for shops over a million in revenue1. Each one is written by a different person, updated on their schedule, and abandoned on their schedule.
Nothing here argues that WooCommerce is bad software. It is not — WordPress core had 6 vulnerabilities in all of 2025, every one low priority2. The argument is about everything you had to bolt on around it, and who is looking after that.
The 2025 record
Core is fine. The add-ons are the surface.
One year of catalogued vulnerabilities across the WordPress ecosystem, split by where they were found2.
91%
In plugins
Of 11,334 new vulnerabilities found in 2025, up 42% on the year before.
6
In core
Six, across the entire year, all of them low priority. WordPress itself is not the weak point and this page will not pretend it is.
46%
Public before a fix
Nearly half received no developer fix in time for disclosure. The exploit is public; the patch is not.
That last number is the one that matters operationally. A patched vulnerability is a maintenance task you can schedule. An unpatched, publicly disclosed one is a decision you have to make the same day: disable the plugin and lose the function, or accept the exposure until somebody you have never met decides to ship a fix.
What it costs to hold together
Four things about the assembly, not the part
Fifty-eight suppliers, not one
Every plugin is written by somebody else, released on their schedule, and abandoned on their schedule too. The store works when all of them agree with each other, and an update to any one can break that agreement on a Tuesday morning without warning.
Evidence: Average of 58 active plugins per store, rising to 66 on stores over $1M; the busiest store in the sample ran 237.1
The risk is in the plugins, and it is measured
This is the part worth being precise about, because it cuts both ways. WordPress core is not the problem and neither is WooCommerce itself. The problem is the surface area you added to make the shop do what you needed.
Evidence: Of 11,334 new WordPress ecosystem vulnerabilities in 2025, 91% were in plugins and 9% in themes. 6 were in core, all low priority.2
Nearly half go public unfixed
A disclosed vulnerability with no patch available is the worst case for a small merchant: the exploit is public, the fix is not, and the only remedies are disabling the plugin or paying for virtual patching. You cannot schedule that around your week.
Evidence: 46% of vulnerabilities did not receive a fix from the developer in time for public disclosure. 1,966 were high severity — more than the previous two years combined.2
The attack surface grew 42% in a year
Not because WordPress got worse, but because the ecosystem got bigger and researchers got busier. Either way the number of things that can go wrong under your store went up by nearly half in twelve months, and the number of people watching it on your behalf probably did not.
Evidence: 11,334 new vulnerabilities in 2025, a 42% increase on 2024.2
None of this is unmanageable. It is a role: somebody who reads advisories, tests updates on a staging copy, and keeps a stack of nearly sixty components in agreement with each other. Plenty of businesses pay for that and are perfectly happy. The question worth answering honestly is whether yours does, or whether it has simply been lucky.
Against this argument
Four reasons to stay, including a strong one
Merchants move towards WooCommerce too. Over a recent ninety-day window 23,807 stores left for other platforms and 17,771 arrived from them — a net movement of about 0.15% of a base of more than four million. 6,130 of those arrivals came from Shopify3. Traffic runs both ways and this page will not pretend otherwise.
An audit is cheaper than a migration. Metorik’s own framing is that the number matters less than whether each plugin is current and justifies its place1. Removing what is inert and updating the rest costs a fraction of moving, and if that fixes your problem it is the correct answer.
You own it, and that is worth something. Your data, your code, your hosting, no platform fee, and nothing that can be repriced from somewhere else. Shopify is rented; that is the trade being proposed, and for some businesses it is the wrong way round.
Some things WooCommerce does, Shopify charges for. Complex tax rules, unusual product types, bespoke checkout logic written once and owned forever. If your store depends on something genuinely custom, moving means renting it back as an app subscription or losing it.
The honest trigger is narrow. If nobody owns updates, if the stack has grown past what anyone can hold in their head, or if the last two incidents both started with a plugin, this is worth costing. If none of that is true, stay and do the audit instead.
If you do move
Five things a WooCommerce store carries
The plugin audit is the migration
Before anything moves, every active plugin gets marked: native on Shopify, replaced by an app, genuinely lost, or — most commonly — no longer doing anything anybody remembers asking for. That list is the scope. Stores routinely find a third of the stack is inert.
Products move cleanly; the meta is the work
Core product data exports and maps without much drama. What takes the time is everything stored as post meta by a plugin: custom fields, badges, bundle rules, subscription terms. Each needs deciding on rather than transforming, and that is a conversation, not a script.
Subscriptions and memberships need planning first
If you run WooCommerce Subscriptions or a membership plugin, existing agreements and their billing tokens are the most delicate part of the whole project. It is doable and it is not automatic, and it is the first thing to look at rather than the last.
Your content is an asset, not an obstacle
WooCommerce stores often sit on years of genuinely good blog content, which is usually the source of whatever organic traffic the shop has. It moves, it keeps its URLs where possible, and where it cannot it gets redirected. Nobody is asking you to abandon it.
The hosting bill and the maintenance retainer both stop
Managed WordPress hosting, a security service, a backup service, and whoever applies updates each month all come off the list. Against Shopify's monthly fee that is the comparison worth making, and for a store carrying a real plugin stack it is often closer than people expect in Shopify's favour.
The method is the crawl, redirect map and rebuild set out on the migration page, and what the destination involves is on the Shopify page. Because so much of a WooCommerce site is content, the search side matters more on this move than on most.
A WooCommerce store is a WordPress site with a shop bolted to it, so half of what is written here applies whether or not you sell anything. If the store is the smaller half of your problem, start on the WordPress page instead.
Fair challenges
What WooCommerce owners ask back
If it works and somebody is keeping it current, you may not need to. This page is not arguing that WooCommerce is bad software — it is not, its core had six low-priority vulnerabilities in all of 2025, and it powers more stores than anything else. The argument is about what you have assembled around it. The average store runs 58 plugins from 58 different suppliers, 91% of ecosystem vulnerabilities are in plugins, and 46% of those go public before a fix exists. If nobody at your business owns that, you are carrying a risk you have not priced.
Partly, and it is the cheaper answer if it works for you. Metorik make the point themselves: the concern is less the raw number than whether each plugin is current and earning its place. Auditing the stack, removing what is inert and updating the rest is a real alternative to migrating, and it costs a fraction as much. The reason it often does not hold is that the plugins are there because WooCommerce alone did not do the thing — so removing them means losing the function, and you are back to the same problem next quarter.
Barely, and it would be dishonest to claim otherwise. It has over four million live stores, more than any other platform. Over a recent ninety-day window 23,807 stores left for other platforms and 17,771 arrived from them — a net movement of about 0.15% of the base. More to the point, 6,130 of the arrivals came from Shopify. Merchants move in both directions and plenty are happy. This is a question about fit, not about a platform in trouble.
Worth knowing about, not worth panicking about, and still unresolved. The litigation between Automattic and WP Engine remains in progress with no ruling on the merits, and a federal court granted a preliminary injunction requiring WordPress.org access to be restored after it was cut off. The durable point for a merchant is structural rather than legal: the update and plugin infrastructure your store depends on is controlled by a single party, and in 2024 that party demonstrated it could withhold access. Whether that matters to you is a judgement call, and it should not be the main reason you move.
Not if the move is done properly, and this is the part WooCommerce merchants are right to care about most. Years of posts are usually where the organic traffic actually comes from. The content moves, URLs are preserved wherever the structure allows, and everything else gets a one-to-one redirect built from a crawl of the live site rather than from an export. Expect some movement in the first two to four weeks while Google reprocesses, and expect it to settle.
Four to eight weeks for a typical store, and the variable is the plugin stack rather than the catalogue. Cost sits in the $5,000 to $15,000 Shopify range, more where subscriptions or memberships are involved because those need careful handling. The first step is the plugin audit, and that alone is worth having even if you decide to stay — it tells you what you are actually running.
Sources
Where these numbers came from
Three sources and no vendor marketing. Plugin counts come from a WooCommerce analytics company measuring its own customers’ stores. The vulnerability data comes from a WordPress security firm that catalogues the ecosystem for a living. The source marked in ochre is the one whose data argues against moving.
- 1How many plugins does the average WooCommerce store use?
Metorik · 6 July 2026 · Randomised sample of 6,000+ WooCommerce stores, data from March 2026
- 2State of WordPress Security in 2026
Patchstack · 2026, covering calendar year 2025 · 11,334 vulnerabilities catalogued across the WordPress ecosystem
- 3The state of WooCommerce
Store Leads · Updated 18 September 2026 · Independent tracking of live storefronts and platform switching
Cited against this argument
The governance dispute referred to in the questions above is active litigation with no ruling on the merits, so it is described rather than characterised here and is not part of the argument. Figures are current to September 2026; the vulnerability totals in particular are an annual count and will be superseded.
Start by finding out what you are running
Send your store URL and you will get back the plugin list, which of them are behind, which are no longer maintained, and what each one would become on Shopify. Useful whether or not you move, and that is rather the point.