As a WordPress user, I’m noticing just how quickly plugin, theme and core updates are coming out — and how vulnerability notifications are increasing. In this video, I talk openly about why AI is making it easier to find and exploit WordPress vulnerabilities, what that means for site owners (especially client sites), and why we need to be more selective about what we install and maintain.
I also discuss concerns around certain plugins effectively creating “backdoor” style access (such as automatic application passwords being created and sent to a company’s servers without clear opt-in), plus the risk of running plugins that haven’t been maintained for years. I share a couple of ways to audit plugin risk, including checking the WordPress repo details and using Vimsy’s Plugin Graveyard.
Finally, I explore when WordPress still makes sense — and when it might be better to use alternatives, particularly for brochure-style sites. I cover options like generating static versions of WordPress sites with Simply Static / Simply Static Studio, and more technical workflows using tools like Instatic, Astro, and Phantom Studio (formerly Phantom WP) to keep WordPress as a CMS but deploy a static front end.
I’d like your thoughts in the comments: are you sticking with WordPress, moving away, or adopting a hybrid/static approach?
Links Mentioned:
Simply Static Studio:
Simply Static:
Plugin Graveyard:
Phantom Studio:
Instatic:
Astro:
#WordPress #WordPressSecurity #WPPlugins #WebsiteSecurity #WebDesign #WebDevelopment #StaticSite #SimplyStatic #AstroJS #CMS #WPTuts
Take your WordPress website and skills to the next level!
► The Essential Web Designer’s Documents Pack
Looking to take your web design business to the next level? The Essential Web Designers Documents collection has got you covered! With handcrafted, professionally designed documents that have generated tens of thousands in revenue, you’ll have everything you need to impress clients, streamline your workflow, and boost your bottom line.
► Buy the Essential Web Designer’s Documents Pack Now:
► THE TOOLS I LOVE ◄
If you like what we do and would like to support us, please consider using these affiliate links when purchasing any of the plugins covered in our tutorials. Thank you for your support.
► EXCLUSIVE WPTUTS DISCOUNTS ◄
✅ WPVivid Backup Pro: (use WPTUTS20 for 20% off)
✅ Project Huddle: (WPTUTS for 20% off – Exclusive)
✅ Flowmattic: (WPTUTS for 20% off annual plans)
✅ Clickwhale: (WPTUTS20 for a 20% discount on all plans)
► MY PREFERRED HOSTING PROVIDERS ◄
✅ Kinsta:
✅ Hostinger:
✅ CloudWays:
✅ SiteGround:
► WORDPRESS VISUAL PAGE BUILDERS ◄
✅ ELEMENTOR PRO:
✅ Bricks Builder:
✅ Brizy Pro:
✅ GenerateBlocks:
✅ DIVI Page Builder:
► WORDPRESS THEMES ◄
✅ GeneratePress Premium:
✅ Blocksy:
✅ DIVI Theme:
✅ Astra Pro:
► WORDPRESS TOOLS ◄
✅ InstaWP:
✅ Crocoblock:
✅ CSSHERO:
► WORDPRESS PLUGINS ◄
✅ SEOPress Pro:
► SUBSCRIBE ◄
► LETS CONNECT: ◄
👉 Twitter:
👉 Facebook Group:
SUPPORT: Our website offers additional information and perks. Please check it out!
source

Why don't developers check for vulnerabilities with AI and fix them before uploading to the WP repo?
Static websites, lol, it's like being back in 1998! Slightly misleading vid IMHO, wp core vulnerabilities make up less than 1%, themes sit at approx 5%. The rest is all plugins.
There has been an explosion of ground up vibe coded plugins that are utter dog shite, alongside a diabolical incorporation of vibe coding in long standing plugins from lazy/money oriented studios.
AI has broken the ecosystem, allowing amateurs to code crappy plugins and flood the repo at the same time, autonomous scanners unmask these vibe coded flaws.
About 70% of my work now is fixing/reverting diy'er attempts at vibe coding website features/plugins. It's tiring and tedious.
Role on retirement!
I think anything online is vulnerable to AI. It's a case of just trying to stay ahead of the threat.
Hey man, loved your content! As a thumbnail designer, I noticed that improving the text positioning, contrast, and face retouching could make your thumbnails stand out more and boost CTR—I can help you fix that, let,s connect ?
Patchstack’s 2026 data says 91% of new vulnerabilities were in plugins and 9% in themes.The real problem is the sprawling third-party extension ecosystem, not WordPress itself.
What I think is that plugin authors should conduct a quarterly security audit with companies like Patchstack or similar security providers.
I have been hearing about WordPress security issues for the past 10 years, and I have been using WordPress throughout this period. Despite the ongoing security concerns, I am still using WordPress and will continue to do so.
Wow Paul, tell me this is an April Fools video.
I’m pretty sure you know that WordPress is used for commerce, membership, donations, churches, digital media, and thousands of other applications for which static sites are not feasible.
So I wonder why the article/video. Why not put energy in helping figure out how to improve and mitigate the risks instead of misleading some folks in thinking they can just migrate to static sites or just vibe code everywhere.
Sorry.
WordPress plugins were a liability a long time ago. A hacker installed a directory plugin and I can’t have that liability with clients. On top of that, so many moving parts to WP things always break.
Why still use WP in 2026 when Laravel and Filament exists? Tools like elementor and even WordPress in general has so much friction to use, I haven’t looked back.
If you must continue to use WordPress, develop your own plugins with AI. The hackers benefit from widely used vulnerabilities in common plugins. Writing your own prevents blanket attacks. Even with Laravel, my server still gets spammed with bots trying to access wp-admin.
Our servers have been getting slightly more loads in recent months and the types of hack attemps seem to have prolifirated.
Most clients host WP sites and most never update them. It is becoming a problem.
But then again, ultimately everything fails!
An the problem is not only abandoned plugins, I got a site infected because Code Snippets pushed a version with a vulnerability, in a span of 3 days my site got infected. WordPress MUST change they way they manage plugins, just like Instatic.
Right on the money. I think this is kind of vibing with my mood as well.🙂
I'm hosting on a service that has daily backups, automatic updates and very easy restore options, and no user or financial info stored – so I'm not really worried.
worst thing is a site get hacked, going back online in 5 minutes.
Hi Paul, Thank you for the video you have been making for us. After I watched on of your video on PhantomWP, I purchase the PhantomWP … I am still not sure of … is the PhantomWP same as Phantom Studio?
I got hacked only once, when I used Cerber Security plugin. After I switched to Wordfence (free version), I’m good. You can use WP inside Docker container and it will be near impossible to get hacked. So I think security is not a good reason to switch from WP. Good reason would be – better features on some other software. But nothing outside WP can beat Bricks for me right now.
Will get interesting when AI starts to find all the security holes on all those vibe coded non static sites and apps, and all those vibe coders will have to fix their creations
I think that Instatic software will be the next future for all WordPress users when it release. Paul by the way you can make a video about Novamira Design option is very promising.
I bought a wordpress theme from envato (ecomall) and the developers deleted all their sites leaving theme users with no updates, is there any way i can update the theme?
WordPress is causing so many issues, many people don´t even know. For example: You delete a WordPress Plugin which is not maintained anymore in wordpress, there will be still many entries in MYSQL Database which can cause security issues and bloats too. Older WordPress Websites have Database entries from plugins deleted 10 years ago
In considering potential alternatives to WordPress, it is important to think about the essentials. 1) there is the technical side of setting it all up; 2) there is the design and visual appeal; 3) there is the knowledge catalog. Google is massively changing SEO for 2027 and websites are just a spoke for a portion of the knowledge catalog. It's important and should be considered carefully.
One of the most useful feature for website builders (cms) is being to build collections. Instatic has it, payload cms has it and for those in the Mac venue, RapidWeaver Elements also has it. WordPress can be used to build the knowledge catalog but is very limited, although some plugins can be helpful.
It is important to consider using WordPress for a portion of a website and build most pages as static using another tool such as Astro for static pages. You can do a mix and match for the majority of the site being static while using posts (with comments) in the same domain. I've already done this on a test basis.
vibecoded static sites are the new thing
Probably the most important video you've made Paul.
TFA your sites.
AI can already hack any web platform, bank accounts, etc. Two AI versions banned in the US already. Wix, SS, Weebly, etc are open for abuse, at least with WP you can spin up your site again within minutes. Saas platforms will be down for weeks or months.
I always tried to keep a small tech stack – using 4-6 Plugins max. But even with that it is increasingly annoying how many vulnerabilities turn up daily. I'm at the point now, where I'm thinking about writing my own GDPR-Plugin and SEO-Plugin to replace Complianz & Rankmath for good, so I only need to rely on ACF and Bricks, which have been quite decent in regards to security afaik..
WordPress still of benefit. But updates remain an issue. However cloud hosting can be an issue. WordPress still has its place
Sort of a double hit; AI makes exploiting vulnerabilities easier, while at the same time wrecking the business model for many plugin developers, which can lead to more orphaned plugins, and more vulnerabilities.
TOp video
What about Framer ?
I'll be using WordPress for a while yet. I've had a couple of issues with plugins no longer being updated on websites that will never be static, and had AI review and update them. It's not ideal, but it's (hopefully) better than keeping the unpatched versions of the plugins.
Astro is King
It all starts with good hosting. I had hosting, where everything got hacked, even static sites, and have another hosting where nothing got hacked, for years. There's even a site, Elementor even, that I have not maintained for more than a year.
Of course I agree that good maintenance is essential, but it does not help if the server isn't safe.
WordPress is dead. You all need to move on. What Color is your Dinosaur?
So RankMath, too, is evil now?
Vulnerability is one thing, reaching to this vulnerability and exploit it is another. I use custom tuned Cloudflare firewall and I never get hacked. One client still run plugin and theme with vulnerability from 2019, never compromised. Now I i'm saying fixing vulnerability is not important. Of course it is, but with few blocking rules, I prevent infection. The last thing what I do it fail2ban IP that's doing anything suspicious, what normal user doesn't do. You see, a hacker first has to know what runs on the server, it's doing discovery process. If you make impossible to discover and ban everything that is suspicious, you pretty safe to go. If you want I can share url of my blog that I'm using for testing, you can go ahead and be my guest to try ;). I'm too busy but I planning to make site filled with all plugins and themes with many compromised plugins and themes.
So, I stay with WP, none of my clients consider change, we will use it for a while.
The funny thing is, the WP2Shell attack could have been prevented by simply deactivating the O-Embeds in WordPress, which is likely the case for anyone using Perfmatters or any other plugin with a bloat remover. So, my takeaway is: deactivate everything from the WordPress core that isn't necessarily needed. For smaller projects, using a static solution actually makes more sense than WordPress nowadays. And as always, thanks for the video, Paul!
I see Kevin Geary is developing Etch Studio which seems to combine static and dynamic features. It is a move away from wordpress on his part. I use bricks and enjoy wordpress as im comfortable with it. It will be sad to see it die. I hope it doesnt.
WordPress is becoming obsolete, cumbersome and a liability. Glad I was able to replace it seamlessly for all my clients with few prompts
Great overview of the current plugin fatigue and security landscape, my answer to this is Studio Code in WordPress Studio. Being able to build custom, lightweight plugins tailored specifically to my exact needs—and client requirements—without relying on bloated or unmaintained third-party plugins is a game-changer. It feels like "Claude Code for WordPress." For me, reducing plugin dependency while staying strictly within the native WP environment is the future of WordPress development.