PSA: Get Your Business Off WordPress

Unless you're a teenager blogging about your goldfish, we really need to have a talk.
This one is Andy's fault.
My longtime friend Andy sent me an article this morning about another massive WordPress vulnerability with a note that essentially said: I know how much you love WordPress.
Andy knows. He has personally been on the receiving end of my WordPress rant for years.
A long time ago, before anybody was seriously talking about AI building entire websites for you, Andy was considering WordPress for production sites. He wasn't just kicking the tires. He had installed it, built a couple of test sites and probably put ten or twenty hours into learning the ecosystem.
Every time it came up, I gave him approximately the same nuanced technical assessment: don't use that shit, you're gonna get hacked.
He pushed back. And honestly, he had a point.
WordPress was incredibly convenient. Templates were cheap. Plugins could make it do almost anything. You could Lego together a decent-looking, reasonably sophisticated website without being a serious web developer.
That's exactly why it exploded.
Andy eventually tested enough of it himself to reach his own conclusion. As he put it today, the testing basically confirmed what I had been telling him: securing the thing properly was difficult enough that security trumped ease of use.
So he abandoned WordPress. And remember, this was before the current generation of AI coding tools changed the entire equation.
Which brings us to today.
3.2 Million Reasons to Have This Conversation Again
The latest problem involves the enormously popular All-in-One WP Migration and Backup plugin. More than five million active installations.
Researchers discovered a serious SQL injection vulnerability that could ultimately be chained into remote code execution and complete compromise of the website. A patch was released. And yet, weeks later, roughly 3.2 million installations were still running the vulnerable version.
That number is almost the perfect explanation of my problem with WordPress.
People always tell me: WordPress can be secured. Of course it can. So can a Windows XP machine connected directly to the internet if you throw enough expertise, monitoring, patch management and sacrificial goats at it.
The question isn't whether WordPress can be secured. The question is why a normal business should voluntarily inherit this security problem in the first place.
WordPress Was a Blog That Ate the Internet
WordPress was built to make publishing easy. For that, it was awesome.
Then we kept bolting shit onto it.
Need payments? Plugin. Forms? Plugin. SEO, membership, backups, migration, calendars, analytics, authentication, caching, customer data, e-commerce? More plugins.
Security? Ironically, another plugin.
Pretty soon what the business owner thinks is "a website" is actually WordPress core, a theme, a page builder and a pile of independently developed software components all running together and all needing to remain patched, compatible and secure.
That is not a website. That is a software supply chain wearing a nice homepage. And most of the people who own these sites have absolutely no idea that's what they bought. That's the nightmare.
Every additional component is another developer you're trusting, another codebase that can have a vulnerability and another update somebody needs to monitor. You don't necessarily know which Lego brick has the razor blade inside it until somebody starts bleeding.
I Know This Particular Neighborhood
I'm not going to turn this into a résumé paragraph. If you want to know what I've done professionally, there's an About page for that. Suffice it to say, cybersecurity, infrastructure and digital forensics are not subjects I wandered into last Tuesday. I've worked on WordPress systems, hosted them, hardened them, fixed them and investigated what happened when things went wrong.
So when I get unusually animated about this platform, there's some scar tissue behind it. Andy can confirm the animated part.
The Civilian Yugo Problem
We found the analogy today. WordPress is like taking a civilian Yugo to war and then being surprised when the thing breaks down on the battlefield.
The Yugo wasn't necessarily defective. You used it for something it was never designed to do. That's the part being missed, or not disclosed. WordPress solved a legitimate problem extraordinarily well. Publishing on the internet used to be difficult. WordPress made it easy. Then we decided to scaffold enormous portions of the commercial web on top of it.
Corporate sites. E-commerce. Customer databases. Membership platforms. Lead-generation systems. Payments. Authentication.
We just kept bolting things onto the Yugo. At some point, you don't need another accessory. You need a different vehicle.
And Now the Last Good Argument Is Gone
This is where the whole conversation changes in 2026.
Years ago, WordPress had one enormous argument in its favor: it was easy.
I get that. Building a custom website used to mean either knowing how to build software or paying somebody who did.
WordPress let agencies and ordinary people grab a template, install some plugins and produce something functional without reinventing everything. There was real value in that. Today? Building a website with AI is almost a parlor trick. I can describe what I want and have an AI-assisted development environment generate the frontend, backend, database, authentication and deployment architecture, often from my phone.
Managed platforms handle huge portions of the infrastructure. Modern models can write code, review it, refactor it, test it and increasingly help identify security problems. In many cases, building a modern AI-assisted site is now easier than managing the WordPress ecosystem required to produce the equivalent thing.
That destroys WordPress's best historical argument.
Andy summed it up perfectly while we were talking: "why would you still use that shit with the AI tools we have today?"
Exactly.
Years ago, he was willing to tolerate some technical ugliness because WordPress made building the site dramatically easier. Even then, after testing it, he decided the security tradeoff wasn't worth it. Now you don't even get the ease-of-use advantage.
So what exactly are we defending?
The Agency Problem
And yes, agencies are going to yell at me. I understand.
WordPress is free. The ecosystem is enormous. Agencies have spent years developing workflows around it, and once you have your preferred templates and plugin stack, you can reproduce websites cheaply and efficiently.
Great business model. That does not automatically make it the right architecture for the client. Those are two completely different questions.
If an agency recommends WordPress in 2026, I want to know why WordPress actually won the technical evaluation. Not because that's what they've been selling for fifteen years. Not because their designer knows Elementor. Why is this the best architecture for this business?
Because I'm struggling to imagine many serious modern requirements where WordPress comes out of an honest evaluation as the best answer.
So Here's the PSA
If your company is already running WordPress, I'm not suggesting you unplug the server this afternoon. But you should have an exit plan.
Figure out what you're running, what it touches, who maintains it and what happens to your business if that website gets compromised tomorrow. Then start moving toward something appropriate for the actual job.
I've been making this argument for years. The difference now is that the last reasonable defense of WordPress has collapsed. The security burden is still there. The plugin problem is still there. The constant patching is still there. The giant target painted on the ecosystem is definitely still there. What disappeared is the excuse that building something better is too difficult. It isn't anymore.
At this point, continuing to choose WordPress for a new business-critical deployment isn't just technologically conservative. I think it's irresponsible.
If Goldie the goldfish needs a blog, WordPress is perfect. Give her an About page. Install an aquarium theme. Start a newsletter. Let us know how Goldie is doing. But if Goldie starts processing credit cards or running a company?
We're migrating Goldie. Immediately.
Sources
SecurityWeek — Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/
WordPress.org — All-in-One WP Migration and Backup https://wordpress.org/plugins/all-in-one-wp-migration/
W3Techs — Usage Statistics and Market Share of WordPress https://w3techs.com/technologies/details/cm-wordpress
Rich Washburn — WordPress Sites Are a Problem: A Nerd’s Candid Rant https://www.richwashburn.com/post/wordpress-sites-are-a-problem-a-nerd-s-candid-rant
Rich Washburn — Perpetual Weakness: Yet Another WordPress Security Issue https://www.richwashburn.com/post/perpetual-weakness-yet-another-wordpress-security-issue
Rich Washburn — Is WordPress the Internet’s Biggest Liability?https://www.richwashburn.com/post/is-wordpress-the-internet-s-biggest-liability

Rich Washburn is a technologist, strategist, and Founder & Chief AI Architect of ARIA AI Labs, working at the intersection of AI, infrastructure, communications, and capital. He also serves as Managing Partner and Chief AI Officer at Eliakim Capital.






Comments