FTFY.
Quick, now tell us how secure Adobe products are.
That critique would be fair if I was talking about my one WordPress site but I'm talking about hundreds, maybe even a thousand if you count sites I've built that came and went. It's a pretty decent sample size (IMHO) both for the number of instances but also the time period (10+ years). And it's also not 300 clone sites, each one was built unique, and each has their own mix of plugins & themes.
YOU, are a technical person and understand the value of updates, vetting plugins, etc, yet a majority of these sites aren't run by people like you/me. They are run by end users, with all of the baggage.
You have a point, to an extent. I wholly disagree with your stance on WP though. It's got issues, numerous issues, and a majority of the sites aren't professionally managed.
You're worried about your fleet and that's great. I'm more concerned with the internet as a whole and Wordpress is just vuln after vuln.
I'm happy your systems are secure. That's great.
Unfortunately, that doesn't apply to the 1000s of installations done by amateurs, lax IT, etc. etc. that make the WP vulns a much bigger issue than the 300 you manage.
Manage on, friend.
It is amazing how much time and effort in the world that has been lost because somehow it became the standard.
Quality WYSIWYG editors and hosting tools will come back with a vengeance soon. As soon as austerity and efficiency returns to the economy.
I mostly think it's due to updating quickly, generally I update the next day and manage it all with a central service, and just not using unknown plugins that don't get updates.
* Using a plugin written by a someone who has no idea how SQL injection attacks works.
* Failure to update WP/plugins after a known security vulnerability.
* Poor general security practices. Tip: don't use your domain name with the "o"s replaced by "0"s. Also, don't create a secret backdoor into your site because the owner has trouble remembering his password.
* Your web host itself has been hacked (https://www.bleepingcomputer.com/news/security/godaddy-hacke...)
I've always done my own hosting too, just a minimal setup of nginx, php-fpm, and mariadb on a 1GB RAM VPS. That way I can keep the server side up to date with security patches, instead of relying on a webhost that may not do it.
Backups run nightly offsite, and I monitor the sites with Change Detection so if a plugin update does break something or in the worst case a site gets hacked, I know fairly soon and can either fix it or roll back to a backup.