I’ve run WordPress sites for 15 years. The AI shift is the first thing that’s made me tell clients to move.
I want to be upfront about where I’m coming from. I’ve been building on WordPress since the days when “a plugin for that” was a feature, not a warning. I’ve shipped hundreds of sites on it, maintained more than I can count, and talked plenty of people out of leaving it when their problem was really just a bad host or a bloated theme. I run a managed service business. WordPress has paid my bills for a long time, and I still think it’s one of the most important pieces of software ever released.
So when I tell you the ground is shifting under it, I’m not saying it as someone who never liked the thing.
What Actually Changed
You’ve probably seen the headlines this month — governments stepping in over AI models that are frighteningly good at finding software vulnerabilities. Strip away the politics and the part that matters to anyone running websites is simple: the newest AI systems can read real codebases, find weaknesses, chain several small ones into a real exploit, and write working proof-of-concept code to prove it. The defenders proving this out (browser teams, major infrastructure providers) have used it to find hundreds of bugs in their own code before attackers could.
That same capability does not care which side it’s on.
For years, the thing that protected most ordinary websites wasn’t great security — it was friction. After a vulnerability was disclosed, there was a window. Days, sometimes weeks, before reliable exploit code was floating around and the mass-scanning bots picked it up. That window was the grace period a lot of us quietly relied on to get patches applied.
AI collapses that window toward zero. Disclosure to working exploit is becoming an afternoon, not a fortnight. And the boring, well-known, long-standing classes of vulnerability — the ones we’ve all shrugged at for years because exploiting them took some skill and effort — are exactly the ones that get cheap to weaponize at scale. The skill floor drops. The bots get smarter. The grace period is gone.
The gap between disclosure and exploitation — the time you actually had to patch — is collapsing from weeks to hours.
Why This Lands Hardest on WordPress
I need to be precise here, because I don’t want to repeat the lazy “WordPress is insecure” take. WordPress core is genuinely well-maintained. The core team is good and fast.
The problem was never really core. It’s the shape of the thing.
A typical WordPress site is core, plus a theme, plus a dozen or two plugins, each written by a different person or company, on different update schedules, of wildly different quality, sitting on hosting that you or your client are responsible for keeping patched. The overwhelming majority of real-world WordPress compromises trace back to that third-party layer — an outdated plugin, an abandoned one nobody updates, a “nulled” plugin with something nasty baked in, or a weak admin login. Every one of those is a separate door, with a separate lock, that you have to remember to maintain.
That architecture was a manageable risk when exploitation was slow and manual. It is a much worse risk when an automated system can scan millions of sites, fingerprint the exact plugin versions you’re running, and fire a fresh exploit the same day a vulnerability drops. The thing that made WordPress so powerful — that endless, open plugin ecosystem — is the same thing that gives an AI-accelerated attacker the broadest possible menu.
Every plugin and theme you run is a version string an automated system can match against the day’s fresh exploit. The more you stack, the more menu you offer.
And here’s the part that keeps me up at night as an MSP: it’s not the sites I actively manage that scare me. It’s the long tail. The “set it up in 2019 and never touched it” sites. The client who let the maintenance plan lapse. The agency build with eleven plugins, three of which are no longer maintained by anyone. There are tens of millions of those sites, and they were already the soft underbelly of the web. They’re about to get hunted far more efficiently.
What “Considering a Move” Actually Means
I’m not telling you to panic-delete WordPress this weekend. If you have a well-maintained, locked-down, properly-hosted WordPress site with a real patching discipline and a WAF in front of it, you can absolutely keep running it safely. That’s a legitimate path, and for a lot of people it’s the right one.
But I think a lot more people than will admit it are not in that situation — they’re in the “it’s been fine so far” situation, and “so far” was carried by the grace period that’s now disappearing.
The honest security argument for moving to a managed, consolidated stack comes down to one word: surface. Fewer separately-maintained moving parts means fewer doors. When hosting, SSL, and the CDN come built in and centrally patched instead of being something you configure and babysit, that’s not a convenience feature anymore — it’s a smaller attack surface and a faster patch path that doesn’t depend on you remembering. When there’s no sprawling third-party plugin layer to keep current, an entire category of the most-exploited vulnerabilities simply isn’t on your site to begin with.
Same goal — a working website — but a very different number of things you’re personally responsible for keeping patched.
That’s the bet behind what I’ve been building. Growth Automations is an all-in-one managed website platform — hosting, SSL, and CDN included rather than configured, no plugin pile to maintain, structured and AI-readable output by default, and a migration path off WordPress that’s designed not to be a nightmare. There’s a free tier, so “look into it” doesn’t have to mean “spend money to find out.” Whether the right answer for you is moving, or just seriously hardening what you’ve got, the point is to decide on purpose instead of inheriting the old assumption that someone will get around to the updates.
The Honest Disclaimer
I’ll say this plainly so there’s no question about it: this post is not meant to scare you, and it is not just an ad for my platform. I’d be writing the exact same warning if I had nothing to sell — I’ve been giving this advice to friends and clients before I had a product to point them at.
The shift is real whether you move to my thing, a competitor’s thing, or a tightened-up WordPress install you commit to actually maintaining. So take the AI part seriously, look at your own stack honestly, count how many plugins you’re really responsible for patching, and ask yourself whether your patching discipline can survive a world with no grace period. That’s worth doing regardless of what you decide.
Just don’t be the “it’s been fine so far” site.
If part of “deciding on purpose” is wanting to see the alternative concretely instead of taking my word for it, we’ll rebuild your current site as a free preview — no card, no obligation, and no pressure to use it for anything. See what a rebuild would actually look like.