← Field notes

WordPress Is Dead. Let's Make It Official.

Jon DelcaroSeptember 29, 20267 min read

I will start with the honest part. WordPress still runs about 40% of the websites on the internet. It is not going to vanish next Tuesday.

But as the default choice for a small business website, it is done. Dead. The promise that made it popular was "easy, cheap, and you can run it yourself." None of those three things is true anymore, and the evidence piles up every single month.

So let's make it official.

The promise versus the reality

The pitch goes like this: install WordPress, pick a theme, add a few plugins, and you are in business. No developer needed.

Here is what actually happens. You add a plugin for the contact form. One for SEO. One for speed. One for backups. One for security, because the other plugins keep getting hacked. One for the page builder, because the theme cannot do what you wanted. Before long you have 20 or 30 plugins, each written by a different company, each updating on its own schedule, and each with full access to your website and your database.

Then you log in and see this: "12 updates available."

Do you click update? If you do, something might break. If you do not, something might get hacked. That is the choice WordPress gives you every week. That is not easy. That is a second job.

One update can break everything

This is not a rare event. It happens to the biggest names in the ecosystem.

In May 2025, WooCommerce, the shop plugin behind a huge share of online stores, pushed bad data from its own servers. It caused fatal errors. Some store owners could not open their own admin panel or their storefront until a fix came out on 6 May. (WooCommerce)

Twelve months later it happened again. The update from WooCommerce 10.7 to 10.8 threw a fatal PHP error on upgrade, and a patch followed on 28 May 2026. (WooCommerce)

In May 2026 the Kirki plugin, with more than 500,000 installs, shipped a critical security flaw inside a routine update to version 6.0.0. Owners who did the "right thing" and updated promptly were the ones who got the hole. Attackers used it to hijack admin accounts. (BleepingComputer)

Read that one again. Updating is how you stay safe on WordPress, and in this case updating is how you became unsafe.

Your plugins can be taken away from you

In September 2024, a fight broke out between Automattic, the company run by WordPress co-founder Matt Mullenweg, and WP Engine, one of the largest WordPress hosts. On 25 September, WordPress.org blocked WP Engine customers from getting plugin and theme updates. Access did not come back properly until a court ordered it on 10 December 2024. (WP Engine)

Those were ordinary business owners. They picked a popular host. Then, for reasons that had nothing to do with them, their security updates stopped.

It got stranger. On 12 October 2024, WordPress.org took over Advanced Custom Fields, one of the most popular plugins in existence, and replaced it with a fork called "Secure Custom Fields." Sites with auto-updates turned on were switched to the new plugin without being asked. (WP Tavern)

If the people who run the plugin directory can swap out the code on your website overnight, you do not control your website.

The security numbers keep getting worse

Patchstack tracks WordPress vulnerabilities every year. Their numbers are not a scare story. They are a trend line, and it only goes one way.

  • 2024: 7,966 new vulnerabilities. That is about 22 a day. 1,614 plugins and themes were pulled from WordPress.org because they were never patched. 43% of the flaws needed no login at all to exploit. (Patchstack 2025 report)
  • 2025: 11,334 new vulnerabilities, up 42%. High-severity flaws more than doubled, up 113%. 91% were in plugins and 9% in themes. WordPress core itself had just 6, all low priority. (Patchstack 2026 report)

Two more numbers from that same 2026 report matter most to a business owner:

  • 46% of vulnerabilities had no patch available when they were made public. You cannot update your way out of a hole that nobody has fixed yet.
  • The median time to mass exploitation was 5 hours for the heavily targeted flaws. About half of high-impact flaws were attacked within 24 hours.

Five hours. Most small business owners do not log into their website once a week, let alone every five hours.

And notice where the problem lives. Not in WordPress. In the plugins. The exact thing that makes WordPress "easy" is the thing that gets you hacked.

A short list of recent disasters

These are not obscure plugins. One of them is a security plugin.

  • LiteSpeed Cache, August 2024. A caching plugin on 5 million+ sites. A critical flaw let an attacker with no login take over an admin account. (Patchstack)
  • GiveWP, August 2024. A donation plugin on 100,000+ sites, used by charities and non-profits. The flaw scored 10.0 out of 10 and allowed full remote code execution. (Cloudways)
  • Five plugins backdoored, June 2024. Attackers slipped malicious code into five plugins on the official WordPress.org directory. It created hidden admin accounts on 35,000+ sites and injected spam. The plugins came from the "trusted" source. (BleepingComputer)
  • Really Simple Security, November 2024. A security plugin on 4 million+ sites had an authentication bypass. The plugin you install to protect your site was the way in. (BleepingComputer)
  • OttoKit (SureTriggers), April 2025. An automation plugin on 100,000+ sites. Attackers were exploiting it within hours of disclosure. (Security Affairs)
  • Post SMTP, November 2025. An email plugin on 400,000+ sites, severity 9.8 out of 10. Patched on 29 October, attacked by 1 November. (Cybersecurity News)
  • Burst Statistics, May 2026. An analytics plugin on 200,000 sites. Wordfence blocked more than 7,400 attacks in 24 hours, and about 115,000 sites were still unpatched after the fix came out. (BleepingComputer)

That last number tells the whole story. The fix existed. More than half the sites still did not have it.

"Free" costs more than you think

WordPress is free the same way a free puppy is free.

Here is what one small business site commonly pays each year, using the vendors' own published prices in US dollars:

ItemYearly cost (USD)
ACF PRO, one site$49
WP Rocket (speed), one site$59.95
Gravity Forms (forms), one site$59
Yoast SEO Premium, one site$118.80
Kinsta managed hosting, one site$350
Total$636.75

That is before a security plugin, a backup service, a premium theme or page builder, and before anyone spends an hour doing updates. It is also before the emergency call when an update breaks the checkout on a Friday afternoon.

Every one of those plugins is a subscription. Stop paying and you lose updates. Lose updates and you lose security. It is a tax you pay to stand still.

Sources: ACF, WP Rocket, Gravity Forms, Yoast, Kinsta.

The platform itself is slowing down

In January 2025, Automattic cut its paid contributions to WordPress to about 45 hours a week, and named the WP Engine lawsuit as one reason. (Automattic)

In April 2025, WordPress went from three major releases a year to one, because company contributions had dropped. About 13,000 tickets sat open at the time. (heise)

WordPress 7.0 then slipped from 9 April to 20 May 2026. (WordPress.org)

And the lawsuit is still going. On 24 September 2026, the court let WP Engine's antitrust claims proceed. (WP Engine) Two years on, the future of the software under millions of business websites is still being argued in a US courtroom.

The market has noticed

W3Techs measures what websites run on. WordPress peaked at 43.6% of all websites at the start of 2025. Today, 29 September 2026, it sits at 40.2%. (W3Techs, history)

A drop of more than three points in under two years, after more than a decade of steady growth. People are leaving, and the ones leaving first are the ones who have had to maintain it.

I wrote about the numbers side of this in July in WordPress Is Expensive, Vulnerable, and Shrinking. Since then it has only got worse.

So what do you use instead?

A website built for your business, with no plugin marketplace bolted to the side of it.

No 30 plugins from 30 different companies. No "12 updates available." No page builder that loads a megabyte of code to show a phone number. The site does what you need, it loads fast, and there is nothing sitting in it for an attacker to find in five hours.

You still get to edit your own pages, add your own photos and post your own news. You just do it in an editor built for your site, not in a dashboard that needs a security guard.

That is what I build. Every site I make is coded for the business it belongs to, owned by that business, and hosted for a fraction of managed WordPress hosting.

Fair is fair

If your WordPress site works, someone competent maintains it, and the bill does not hurt, you do not need to panic. Keep it patched and keep backups.

But if you are the one clicking "update" and holding your breath, if you have been hacked before, or if your plugin renewals now cost more than your hosting, it is time.

WordPress had a great run. It is time to let it rest.

Want an honest read on your WordPress site? Send me the address. I will tell you if it is worth keeping, and if it is not, what it would take to move.

Want this done properly on your site?

Ready to take your business to the next level with a custom digital solution?