A big draw of WordPress is that non-developers can customise it with all the plugins that are available, so saying WordPress is secure as long as you avoid plugins nullifies this. It's terrifying that a contact form or caching plugin that you need to install because the functionality isn't built-in could result in a remote code execution exploit.
IMO the problem with the plugin ecosystem is not that they're required, but that so much of the well-known plugins are bloated crap.
Popular SEO plugins don't stop at inserting SEO tags into your <head>. They come with AMP integration, an online robots.txt editor, automatic content generator, competitor site analyzer, spam blocker, and even a rudimentary caching feature to speed up your site! Meanwhile, caching plugins offer to minify your javascript, photo galleries include a Stripe payment gateway, and contact forms come with their own markup language. Everyone is trying to do everything, everyone is stepping on everyone else's toes, and it's impossible for anyone to maintain all the unrelated features that are bundled together in each plugin.
There are really neat plugins that do one thing, do it well, and are easy to audit. Sadly, they are buried under all the spammy alternatives. WordPress really needs to invest in a better plugin search & ranking system that discourages bloat and offers incentives for high-quality code, perhaps by integrating some sort of static analyzer.
> ... Everyone is trying to do everything, everyone is stepping on everyone else's toes, and it's impossible for anyone to maintain all the unrelated features that are bundled together in each plugin.
If these plugins were in core though, they'd likely have much better security and be less bloated. The problem with the plugin ecosystem you mention I think stems from monetization - there's the incentive to stuff freemium plugins with functionality so you can charge for paid features. I really don't know how WordPress can reign this in.
I think the WordPress core that plugins build upon has bad security fundamentals as well e.g. the default PHP templating language doesn't even escape strings by default, most theme and plugin file permissions aren't locked down to read-only, Git-based versioning and deploys isn't built-in or widely practiced.
> There are really neat plugins that do one thing, do it well, and are easy to audit.
What plugins would you recommend? I find you can get pretty far with Advanced Custom Fields and an SEO plugin.
When you find yourself fixing bugs in plugins or trying to unlimit their functionality, because in their design someone introduced an unnecessary limitation via the chosen primitives and abstractions, then you are already clearly above the level of skill or knowledge, that Wordpress targets and are able to use more advanced tools to better effect.
Since Wordpress targets that not so experienced developer or simply hobby blogger audience and aims to make it simple for them to create a blog, that is also the group, from which most people arise to become plugin developers. That in turn leads to inexperienced developers using PHP, which has its own set of problems. For example treating HTML as a string by default, allowing for countless injection and XSS vulnerabilities. Or the incessant spam of PHP open and close "tags" in the code, intermingling PHP, HTML, CSS and JS in the same files, switching context so much, that, given a point in the code, you are no longer sure what context you are really in, instead of them using a proper template engine, or starting to not treat HTML as a string in other ways.
The problem is the knowledge and experience gap that is between a person, who can write a secure and useful plugin and a person, who starts writing plugins, because they are a WP user and got some motivation to start with plugin writing. PHP does nothing to reduce that gap.
Another problem in Wordpress itself is, that its recommended or assumed theme architecture encourages concattenation instead of composition. HTML is again treated as a string, that is to be concattenated from smaller parts. Instead what any good templating engine would do is to have blocks of things, which you define elsewhere and keep every part independent. No stuff like head tag open in one document and closing it in another, making the parts not reusable. Most people creating themes do not even think about this stuff. They just go with whatever WP assumes them to do.
> The problem is the knowledge and experience gap that is between a person, who can write a secure and useful plugin and a person, who starts writing plugins, because they are a WP user and got some motivation to start with plugin writing. PHP does nothing to reduce that gap.
That's my feeling. Anybody used to working with secure and well written codebases with CD/CI, tests and just basic Git versioning will want to run away when they see how typical WordPress sites work under the hood.
I would say, if you have a choice in the matter (many do not have that on the job or when a friend asks them to help them with their blog or shop built on top of WP), that at the point, where you start using a proper template engine and switch from the WP-assumed concattenation way of building things to a style of using composition, you are well beyond the point, where you should switch to something more appropriate for the job.
React makes user stylesheets more difficult to write and in my experience often creates tons of overhead in the DOM tree. Often sites do not use SSR, so all they show me is a white screen (because why care about adding any note about the site only working with tons of JS?) and I close the tab. When React sites actually work somewhat, they are usually sluggish and break basic browser functionality like the back button, bookmarkability and others. It takes a lot of care to avoid these issues, when developing with React, so I am not a fan of React or things based on React.
For me personally React is somewhat of a plague of the "modern web". I am sorry to express it this harshly. React and its ilk create a lot of pain for me. Not everything has to be a SPA. Most things actually do not have to be a SPA.