WordPress
WordPress scores 45/100. Consider migrating to: astro, nextjs, hugo.
11334 total CVEs on record. 387 critical severity. 23 actively exploited (CISA KEV).
Average performance. Room for optimization.
19,500 GitHub stars. 450 contributors. 8 releases in the last year.
Poor AI-readiness. Built for human-browser consumption. Bloated HTML output, plugin-injected content, weak or bolted-on API support.
Adequate developer experience. Established patterns but some friction.
High cost. Significant hosting, maintenance, and security patching burden.
6 confirmed vulnerabilities being actively exploited in real attacks right now. Source: CISA Known Exploited Vulnerabilities.

Website Migration Cost in 2026: What It Actually Costs to Move Off WordPress
July 25, 2026 · 8 min
Two WordPress Core Flaws Let Attackers Plant Plugins That Outlast Cleanup
July 22, 2026 · 5 min
A WordPress RCE That Skips the Plugin Layer Entirely
July 22, 2026 · 4 min
A New Plugin Lets Shopify Store Data Flow Into WooCommerce
July 9, 2026 · 4 min
WordPress 7.0 Was Supposed to Be the AI Upgrade. Six Weeks Later, Most Sites Haven't Installed It.
July 3, 2026 · 5 min
Next.js Overtakes WordPress on the High-Traffic Web
July 3, 2026 · 6 min
Your WordPress Scan Came Back Clean. You Are Still Exposed.
July 2, 2026 · 5 min
Release Velocity This Week: Vue, Angular, and FastAPI All Ship
June 26, 2026 · 4 min
WordPress Ships Zero GitHub Releases. Every Other Framework Ships 40–50.
June 23, 2026 · 5 min