WordPress
WordPress scores 45/100. Consider migrating to: astro, nextjs, hugo.
11334 total CVEs on record. 387 critical severity. 23 actively exploited (CISA KEV).
Average performance. Room for optimization.
19,500 GitHub stars. 450 contributors. 8 releases in the last year.
Poor AI-readiness. Built for human-browser consumption. Bloated HTML output, plugin-injected content, weak or bolted-on API support.
Adequate developer experience. Established patterns but some friction.
High cost. Significant hosting, maintenance, and security patching burden.
7 confirmed vulnerabilities being actively exploited in real attacks right now. Source: CISA Known Exploited Vulnerabilities.

Post SMTP error log could store attacker scripts on open WordPress Multisite
October 8, 2026 · 4 min
Patching Ninja Forms does not remove the hidden admin an attack can leave
October 7, 2026 · 4 min
WordPress MP3 plugin flaw: exploitation seen in 2023, NVD entry in 2026
October 5, 2026 · 4 min
JetAppointment flaw lets anonymous visitors plant code in admin screens
October 5, 2026 · 4 min
A WordPress backdoor rebuilt itself after cleanup, Sucuri finds
October 4, 2026 · 4 min
WordPress AI connector plugin flaw lets a basic user become administrator
October 3, 2026 · 4 min
Two WordPress backup plugins could expose data on servers that ignore .htaccess
October 2, 2026 · 4 min
Sucuri: SC WordPress malware hides in at least 8 places and rebuilds itself
October 1, 2026 · 4 min
WordPress Patches Unauthenticated RCE Path Spanning Decade of Releases
September 27, 2026 · 4 min