Answer: http://www.reddit.com/r/IAmA/comments/1jg781/i_am_matt_mulle...
Nothing is going to dethrone Wordpress unless it's at least as easy to cargo cult, and anything that does will more or less by definition annoy experienced developers more than what it replaced.
You can of course go full comp sci implementing clever algorithms in Go, but you could do that in PHP, too, and none of content creators is usually interested in this.
1. Edit the project's files.
2. Open the (scary and alienating) command line.
3. Run `go build` and hope it works right.
4. Find and stop the old running server process and start the new version
Oh, and you'd better hope step 3 goes smoothly, because a tiny mistake anywhere in your application will cause this weird thing called a "compiler error" that means that the entire thing will break. Editing a Wordpress site, on the other hand, looks like this: 1. Edit the project's files.
2. There is no step 2.
As developers, we're comfortable with the first workflow. We happily accept the added complexity because of all the other nice things it gives us and because we're probably using other tools like version control that end up making our experience much more uniform between the two. But to a user whose primary experience is with editing Word documents there is a huge jump there.This probably has to do with the majority of cheap web hosts out there offering only PHP, Perl, and (if you're really lucky) Rails.
I sound like a bad person. I can't help it.
In my experience, most vulnerabilities tend to come from insecure, poorly written, unvetted third party plugins and libraries.
Someone writes a plugin that creates a widget, security is either a non-thought or an afterthought. They think someone else might like the widget so they publish it. Thousands of people find it useful, even years after originally released. They are all unknowingly using an insecure piece of software.
I guess most people, like me, choose the language they know/like and then setup the server accordingly.