As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.
As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.
I've been building https://github.com/Qbix since 2008 and let me tell ya, I took a lot of great ideas from Drupal, Kohana, Symfony, etc. But never Wordpress. It's just ... a mess. Wordpress just won by being first, basically. Kind of like Bitcoin.
PS: Years ago, I hired a guy in Pakistan to work with me on some Wordpress sites, for clients. I thought that the Divi theme and basic Wordpress would be secure. Every one of those sites got pwned, badly. Sure, maybe it was the plugins. But why take the chance? In 2026 it's way past time to not have to worry about basic security.
Drupal admin was not for humans back then.
This is the problem WordPress faces - it's powerful enough for people to get stuff done on a shoestring. But the professionals who want to do things on a shoestring are also likely cutting corners elsewhere (hosting, backups, security, etc). In many cases there's money changing hands and it's easier to blame WordPress than poor decision making.
I have more sympathy for those building with it on a shoestring for personal/charitable projects who may lack the skills/experience to follow https://developer.wordpress.org/advanced-administration/secu.... They're probably better off on Wix or Squarespace.
If you run WordPress, you should be aware of this already. Either upgrade to the latest versions, constantly and quickly, or have extremely restrictive WAFs up and ready. Especially if you have any plugins installed (as those are usually where the WordPress exploits are coming from).
I'd recommend everyone unhappy only finding out about WordPress' long-standing support policy to ask their money back.