Do they automatically fixing themes to CMS'es? Updating the engine is one thing, WorPress, CME, and so on, but that only takes care of a tiny portion of the attack vectors. In my experience, if a wordpress or a phpbb forum was hacked, then its the user installed/programmed theme that was the cause and not the engine itself.