
As of April 2026, Hestia is a WordPress theme with 80K+ active installations and a 4.8/5 rating from 560 reviews. It has been downloaded 4.6M+ times in total. Requires WordPress false+ and PHP 5.4.0+. Available on WordPress.org since 2017. Offers a premium version with additional features. Top alternative: Twenty Twenty-Five.
I love the simple, yet elegant design.
Apos atualizar as pagina principal o tema quebra e não volta mais algo muito estranho acontece
Support ignores vulnerabilities that have existed for month/years, which pose a potential threat to every Hestia and Hestia Pro user. According to support, these are not critical vulnerabilities, but network scanners still detect them. Finally, support informed me that they would not fix these vulnerabilities, even though my website was still under a valid support contract.
CVE2024-6484 is particularly problematic because it is rated medium, not low, and security measures on the web server cannot be migrated. Since Heatia’s customizer only works if ‘unsafe-inline’ and ‘unsafe-eval’ are set in the CSP, this potentially increases the risk. The other CVE’s are not medium or critical, but would be easy for support to fix!
However, according to EU regulations, they are obligated to close these vulnerabilities and are liable if websites are demonstrably compromised due to these vulnerabilities. Support refused to acknowledge this. It’s a shame. I cannot recommend the theme for the security reasons stated and behavior of the support.
Here are existing vulnerabilities:
CVE-2024-6484, CVE-2018-14040, CVE-2018-14042, CVE-2018-20676, CVE-2016-10735
Detailed explanations and ratings can be found at cve.org
As evidence test you website with on pentest-tools.com – Website Scanner (light)
Hestia has an attractive cover, but it’s like a closed box. You can’t modify the structure, style, or layout. Even if you pay, you don’t have the freedom to customize headers, paths, or visual content. The design is outdated. I wanted to make something modern and visual to keep visitors engaged longer… but it’s impossible. They tell you you have control, but you can only change colors and text. Nothing else.
Great theme even in free edition
Theme data sourced from WordPress.org. Analysis and metrics by PluginSift.