A response to Is WordPress Insecure? (May 2024)
In May 2024 I answered a question I heard often in the RFP process: isn’t WordPress less secure than other platforms? My short answer was no. My longer answer was that WordPress’s weak spots come directly from its strengths.
It is the most popular CMS in the world, which makes it a target rich environment for hackers. It is open source and invites anyone to build plugins, which opens the door to poorly built ones. And I made an observation from years of experience:
“In my experience, if a WordPress site does get hacked, it’s almost always due to a bad plugin rather than WordPress itself.”
I still believe that. WordPress core is well maintained and patched quickly. The core argument of that video holds up.
The plugins were the attack surface
Here is what I see differently now. In 2024 my advice for managing plugin risk was to pick carefully:
“Additionally, you can evaluate plugins based on how many installs they have, how they’re ranked by users, and how often updates are released.”
That was good advice, and it still is. But it assumed you needed a lot of plugins. In the low code world we did. The page builder was a plugin. Its pro version was a plugin. Its add-ons were plugins. Forms, sliders, galleries, filters, and layout tricks were each another plugin. Every one of them was code written by someone else, for thousands of other sites, that we had to trust and keep updated.
We accepted that because writing those features ourselves cost too much. Custom code was the expensive option, so we bought our features off the shelf and managed the risk.
Fewer doors to lock
AI agents now write and revise custom code under experienced direction, at a fraction of what it used to cost. That changes the security picture in a practical way.
When we rebuild a site on our AI-native theme, a lot of those plugins simply go away. The layout work the page builder used to do is in the theme. Many of the small features that used to require a plugin are now a focused piece of code that does exactly one job for that one site. There is less code overall, and far less third party code.
Less code means fewer places for a vulnerability to hide. That isn’t a marketing claim. It is just arithmetic. A site with a handful of carefully chosen plugins has fewer doors to lock than a site with forty.
We still use well-supported plugins where they are the best tool for the job. Some jobs, like security scanning, are best left to specialists. I wrote more about how we decide in Do You Still Need All Those Plugins?
So we no longer have to trade security for affordability. A lean custom build costs less and gives attackers less to work with.
Maintenance still matters
The other half of my 2024 answer hasn’t changed at all:
“First and foremost, WordPress sites must be maintained.”
Custom code doesn’t make a site immune. WordPress core still needs updates. The plugins you keep still need updates. Custom code needs to be reviewed by people who know what secure code looks like, not just accepted because an agent wrote it. That review is part of how my team works. The agents follow our playbook and standards, and we check the result.
And someone still needs to watch the site after launch. That is why every site we build comes with ongoing support, including updates and hosting.
The answer today
If a prospect asked me today whether WordPress is insecure, I would give the same short answer. No. When WordPress is deployed and supported professionally, it is very secure.
But I would add something I couldn’t say in 2024. The safest WordPress site is a lean one. And for the first time, lean doesn’t cost more.
¡Viva la Revolución!