Small Business SEO904-664-6144Take a Test Drive
100K AI WebsiteSEOLeave WordPressGuidesBlogReviewsFAQsAboutContact904-664-6144Take a Test Drive

WordPress · Security · Websites

281 AI JSX Sites Later. I Still Hate WordPress. Here's Why.

Four weeks ago I wrote up what I learned at 252 builds. I'm at 281 now. In those same four weeks WordPress had one of the ugliest runs I've seen in 25 years. I wrote about every piece of it as it landed.

I crouch in a wet alley at night holding a box labeled OLD PLUGIN, pulled out of a rusted cabinet stuffed with cables and boxes marked SEO, CACHE and SECURITY, under a giant WordPress logo, with a Barred Rock hen and a blue merle Australian Shepherd beside me. 281 AI JSX sites later, I still hate WordPress. Here's why.

On August 16 I published a post called 252 JSX Sites Later. Here's What I Learned.

Today the number is 281.

Twenty nine more sites in four weeks.

Here's the part that got under my skin.

While I was building those twenty nine, I kept having to stop and write about WordPress. Not because I went looking. Because it kept happening.

Six posts in four weeks. A plugin supply chain attack. A core hole the feds put a three day clock on. Five million sites running a backup plugin that was wide open. A plugin that shipped with a backdoor in it.

I didn't plan a series. WordPress wrote it for me.

So people ask why I still hate it after 10k+ sites and 25 years. I don't reach for an opinion anymore. I hand them the last four weeks.

Four weeks. This is just the stuff that made the news.

I don't hate WordPress because it's old. I hate it because there are holes in the floor and holes in everything you stacked on top of it.

Core is not the safe part. It's just the part with a team.

TL;DR (the short answer)

The whole stack is the problem. In July 2026 a hole in WordPress core let people in with no password. CISA gave federal agencies three days to patch it. That's core, this year, failing badly. On top of that, 2025 brought 11,334 new WordPress vulnerabilities, up 42% on the year before. 91% in plugins, 9% in themes (Patchstack, State of WordPress Security in 2026). WordPress is now bringing AI in to hunt its own bugs. That tells you core has bugs worth hunting. You're running software with holes in the floor and thousands more in everything bolted on top.

3 Things to Remember

1
91% of new WordPress vulnerabilities in 2025 were in plugins, 9% in themes (Patchstack, 2026).
2
46% were public before the developer shipped a fix. There was nothing to update to (Patchstack, 2026).
3
Core is not the safe part either. A core hole in July 2026 needed no password and CISA gave federal agencies three days.

Twenty Nine Sites. Four Weeks. Here's the Tape.

I won't spin this part. Here's what I wrote, in order, while the build count went from 252 to 281.

August 16, the same day as the 252 post: 270 WordPress vulnerabilities in a single week. Nearly all of them in plugins. That's one week of one tracker.

August 21: somebody bought 30 plugins on Flippa and shipped a backdoor to every site running them. It sat quiet for eight months. WordPress.org closed 31 plugins in one day.

August 22: a hole in WordPress core that needed no password. CISA gave the feds three days to patch it. When they put a clock on your website software, that's not a small thing.

September 1: a backup plugin on five million sites, wide open in every version up to 7.109. Nobody emailed the five million people running it.

September 3: a plugin shipped with a backdoor already in it. Plus two 9.8 severity takeovers still sitting with no fix, handing out admin with no password. 246 new holes in seven days.

September 4, and this one is the odd one out: nobody hacked you, Google just stopped sending people. Different failure, same silence. Nobody sends you an email either way. The phone just goes quiet.

That's four weeks. Not four years.

Everybody's guarding the vault. The stuff worth taking is in the hallway.

They're Fixing Core. Core Had Six Bugs Last Year.

I brace a long steel bar against a riveted industrial door stamped with the WordPress logo while a Barred Rock hen pulls at the other end of the bar, next to a small lit panel holding six numbered tags. They're fixing core. Core had six bugs last year.

WordPress announced a Core Security Initiative in late August. Ship security releases faster. Clear the backlog. Use AI to find bugs before the researchers and the attackers do.

Good. They should.

But read what that is. You don't bring in AI to hunt bugs in something with no bugs.

That initiative is WordPress telling you core has holes worth hunting. And that they aren't finding them fast enough by hand.

That is an admission, not a reassurance.

And they are right to make it, because core bit hard this year.

In July a hole in WordPress core let people in with no password at all. Not a plugin. Core. CISA gave federal agencies three days to patch it. CISA does not hand out three day clocks for things that don't matter.

The feds put a countdown on the software running your website. Nobody gets to call that part safe.

Now, here's the number people quote at me.

6

WordPress core vulnerabilities in all of 2025, all rated low priority. Source: Patchstack, State of WordPress Security in 2026.

Six, all low priority, across 2025.

People wave that around to argue core is solid. I won't. Two reasons.

One, that's a single year of data and it's already behind. It covers 2025. The no-password hole was July 2026. A clean year does not promise you the next one. And the next one already went badly.

Two, low priority is a severity score, not a promise. It's what a researcher graded it. It says nothing about what it costs you when somebody chains it to something else.

So no. I'm not going to tell you core is the safe part and your plugins are the dirty part. That's the comfortable version. It's wrong.

Core has real holes. It had a bad one this year. And then there are thousands more sitting on top of it.

The mistake: hearing "WordPress is investing in security" and reading it as "WordPress is secure."

The fix: read it as what it is. They are hunting bugs because the bugs are there.

The payoff: you stop grading the floor on a curve and start counting every hole you own.

91% of It Lives in the Plugins You Forgot About.

I drag a heavy chain hauling a leaning pallet stacked with crates stamped with the WordPress logo down a row of storage lockers at night, with a Barred Rock hen pulling the front of the chain and a blue merle Australian Shepherd nosing a fallen crate. 91% of it lives in the plugins you forgot about.

So that's the floor. Now here's what's stacked on it.

11,334

new WordPress vulnerabilities in 2025, up 42% on 2024. 91% were in plugins, 9% in themes. Source: Patchstack, State of WordPress Security in 2026.

Eleven thousand, three hundred and thirty four. In one year. Up 42%.

Ninety one percent of that is plugins.

Read that number the right way. It does not mean core is clean. It means the pile on top of core is huge.

You have holes under you and eleven thousand more above you. The 91% tells you the size of the second pile. Not the safety of the first.

Think about what a plugin is. It's code some other guy wrote. You installed it. It runs on your site and it can reach your data.

And you're trusting a stranger to keep patching it for free. Forever.

Now count how many you have. Most sites I get handed run between fifteen and forty of them. Half were installed to fix a problem that's long gone. A contact form. A slider nobody scrolls to. An SEO plugin from two web guys ago.

Every one of those is a door. You did not build any of them and you cannot fix any of them.

That's the whole reason I stopped. Not because WordPress is ugly. Because I got sick of being on the hook for code I didn't write and couldn't fix.

The mistake: counting plugins as features.

The fix: count them as doors, then count how many you actually use.

The payoff: every one you remove is a door that can never be opened again.

Half the Serious Ones Get Hit Before You Finish Lunch.

People hear "there's an update available" and picture a comfortable window. A weekend. A quiet Tuesday when they get to it.

5 hrs

median time to mass exploitation for heavily exploited WordPress vulnerabilities. Source: Patchstack, State of WordPress Security in 2026.

Five hours.

Take the ones that get hammered. Half are being mass exploited within five hours of going public.

That's not a weekend. That's lunch.

And it gets worse. There isn't always something to update to.

46%

of WordPress vulnerabilities in 2025 were published before the developer had a fix ready. Source: Patchstack, State of WordPress Security in 2026.

Nearly half. The hole is public. The clock is running. And there is no patch.

You could be the sharpest owner on earth, updating everything the day it drops. You'd still be wide open on 46% of them.

I watched that play out on September 3. Two 9.8 severity takeovers, no fix available. Handing out admin with no password. Nothing to click. Nothing to update.

You cannot patch your way out of a problem when there is no patch.

Nobody Patches the Plugin Whose Developer Quit.

A Barred Rock hen stands over a scatter of dusty crates stamped with the WordPress logo in a dark yard while I look down at one of them. Nobody patches the plugin whose developer quit.

Here is the thing nobody tells you when you install something free.

There is no contract. The guy who wrote it owes you nothing.

He can stop answering. Get a job. Have a kid. Lose interest. Die.

And the plugin sits there doing its job. Right up until somebody finds a hole in it.

Then it just sits there. Open. Forever.

That's what 46% unfixed at disclosure really means. A big share of that isn't developers being slow. It's developers being gone.

And there is a version of this that is worse than quitting, which I wrote up on August 21.

He doesn't quit. He sells. Somebody bought more than 30 plugins on Flippa and pushed an update with a backdoor in it. Every site running any of them got handed over. The backdoor slept eight months before anybody noticed. WordPress.org pulled 31 plugins in a single day.

Those owners did everything right. They kept their plugins updated. Updating is what installed the backdoor.

Read that again. It breaks the only advice most people ever got about WordPress.

The mistake: assuming somebody is still maintaining the thing running on your site.

The fix: check the last update date on every plugin you have. Anything over a year is abandoned.

The payoff: you find out who is still home before somebody else does.

Here Is What I'd Pull Off Your Site This Week.

I carry an armload of crates stamped with the WordPress logo toward a loaded dumpster in a floodlit yard at night, with a Barred Rock hen riding the stack and more crates spilling across the wet ground. Here is what I'd pull off your site this week.

Staying on WordPress for now? Fine. Do these four things and you'll be in better shape than most sites I get handed.

  • Open your plugin list and read it out loud. Every one you can't explain in a sentence comes off. Not deactivated. Deleted. A deactivated plugin still has its code sitting on your server.
  • Check the last updated date on the ones that stay. Over a year means nobody is home. Find a maintained one or do without it.
  • Count how many you could live without. Sliders, popups, counters, share buttons. Each one is a door for a thing nobody clicks.
  • Ask who fixes it at 2am. If the answer is you, and you don't write code, you don't have an answer.

That's the audit. Takes an afternoon. It really does help.

But I'd be lying if I said it solves it.

You'll do it this week. Then 11,334 more holes show up next year.

46% of them land with no fix. Half the bad ones get hit in five hours.

And you run this audit again every quarter for as long as you own that site.

I did the math on my own work and quit. I moved 1,387 posts off WordPress myself. Not for a client. For me. Because I got sick of the quarterly audit.

281 Builds In, Here's What Changed.

The sites I build now have no plugin folder. They also have no WordPress under them.

That second part matters. It's the whole reason I'm not just telling you to delete plugins.

The federal government put a clock on core. So pulling the plugins off a WordPress site still leaves you standing on it.

So there's nothing to update. Nothing bolted on that somebody else maintains. No stranger's code with database access. No admin login to find.

When Patchstack publishes next year's number, I won't have to go read it. None of that surface exists on the sites I ship.

That's not me being clever. That's what happens when you stop bolting a site together out of other people's parts. And start building the thing itself.

Twenty nine builds ago I wrote up what I'd learned at 252. The thing I'd add at 281 is this. The best security feature is a smaller site. Not a hardened one. A smaller one.

You cannot exploit code that isn't there.

Let me show you what that looks like in your own market.

Take a Test Drive →

You get a real look at your own market. No obligation, and nothing to cancel.

Want the whole playbook first? Plan your attack. Balls Out Marketing.

FAQ

Is WordPress actually insecure, or is this overblown?

It's a real problem, and it's a problem at both levels. In July 2026 a hole in WordPress core let people in with no password. CISA gave federal agencies three days to patch it. That's core failing, this year. On top of core, 2025 brought 11,334 new vulnerabilities. 91% in plugins, 9% in themes (Patchstack, State of WordPress Security in 2026). Anybody telling you core is the safe part, and plugins are the only issue, is handing you the comfortable version.

Doesn't keeping plugins updated solve this?

It helps and you should do it. It does not solve it. 46% of vulnerabilities in 2025 went public before the developer had a fix ready. There was nothing to update to. And in August 2026 a buyer picked up more than 30 plugins and pushed a backdoor out as an update. The owners who updated fastest were the ones who got hit.

How fast do attackers actually move?

For the heavily exploited ones, the median time to mass exploitation is five hours (Patchstack, State of WordPress Security in 2026). That's the window between a hole going public and it getting attacked at scale. It is not a weekend project.

What is the WordPress Core Security Initiative?

It's a program WordPress announced in late August 2026. Ship security releases faster, clear the backlog, and use AI to find bugs before researchers or attackers do. Good work, and overdue. It's also an admission. You don't bring AI in to hunt bugs in something that has none. Read it as WordPress saying core has holes worth finding, and that hunting by hand wasn't keeping up. July 2026 proved that.

How many plugins is too many?

There's no magic number. But every plugin is code you didn't write, running on your site, with access to your database. And it's kept up by somebody who owes you nothing. Good test: read your plugin list out loud. Anything you can't explain in one sentence comes off. Delete it, don't deactivate it. Deactivated code still sits on your server.

What do you build instead?

Static JSX sites. No CMS, no plugin folder, and no WordPress core underneath. That last part is the point. Stripping plugins off a WordPress site still leaves you standing on core, and core is where July 2026 happened. Nothing to update. No third party code with database access. No admin login to find. I've built 281 of them, and I moved my own 1,387 posts off WordPress to do it.

This is the follow up to 252 JSX Sites Later, written 29 builds later. Want the longer argument about leaving? I wrote that one too: I moved 1,387 posts off WordPress and it took less than you think.

Check Out My Last 3 Builds

Real sites, built with this exact system. Tap any one and poke around.

Two Men and a Truck
Moving company
See it live →
Learn Euphoria
Education & courses
See it live →
SoFresh
Fast-casual food
See it live →
Small Business SEO · Jacksonville, FL · Go Balls Out.

Get 2 Must-Read Resources Every Week

No spam. No pitch. Just 2 Must Read Resources a Week.

By downloading, you agree to our Privacy Policy. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.