top of page

The Burglar Who Never Sleeps: Why We Left WordPress Before the AI Threat Arrived

Aug 28
7 min read
Illustration of a long row of identical suburban front doors at night, with a code-like figure reaching for the handle of every door at once, representing automated website attacks.
Every plugin on a WordPress site is another door built by another carpenter. Most site owners have no idea how many are unlocked.

Picture a burglar working your street. He's patient, but he's human. He can try one door handle at a time, and eventually he gets tired and goes home.


Now imagine a burglar who can try every door on every street in the country at once. He doesn't sleep. He doesn't get bored. And every time a locksmith publishes a note saying "this particular lock has a flaw", he's read it and reached your door within five hours.


That burglar exists now. He's software, and he's very busy. This is the story of why we saw him coming more than five years ago, and what we did about it.


The numbers have gone vertical


For years, website security was a slow-burn problem. It isn't anymore.

In 2025, 11,334 new vulnerabilities were discovered across the WordPress ecosystem, the highest number ever recorded and a 42 percent jump on the 7,966 found in 2024. More high-severity vulnerabilities were found in 2025 than in the previous two years combined.


Bar chart of new WordPress vulnerabilities rising from 2021 to 2025, blue to red bars, with Patchstack source note.
Seven times more vulnerabilities than four years earlier, and 91 percent of them in plugins.

And the burglar is getting faster. Among heavily exploited vulnerabilities, 20 percent were attacked within six hours of being publicly disclosed, and 70 percent within seven days. The median time from disclosure to first exploitation was five hours. Five hours. If your web person checks your site weekly, you're not in the race. The Repository


Then there's the AI layer on top. CrowdStrike recorded an 89 percent year-on-year jump in AI-enabled attack operations, and IBM found that one in four malicious breaches in its 2026 study were AI-enabled. This isn't a future problem. It's a this-morning problem. StingraiDeepStrike


The house with 60,000 doors


So why does WordPress cop the worst of it? Not because the core software is badly built. It isn't. Of those 11,334 vulnerabilities, just two were found in WordPress core. Plugins accounted for 91 percent. The Repository


Here's the useful way to picture it. A WordPress site is a house, and every plugin is a door. Each door was built by a different carpenter, some brilliant, some hobbyists, some who moved overseas years ago and stopped answering the phone. The official directory alone holds tens of thousands of these doors, and a typical site has 20 to 30 of them fitted.


You didn't build those doors. You can't inspect them. You're trusting that every carpenter is still awake, still patching, still around. The data says many aren't: 46 percent of vulnerabilities disclosed last year weren't fixed by the developer before the flaw was made public. That means the burglar got the locksmith's note before the door got a new lock. The Repository


Why we walked away, more than five years ago


We should be upfront: we built WordPress sites for years, and WordPress can still have its place. In the right hands, with a dedicated maintenance budget, a hardened server, and someone genuinely responsible for updates, it can be run well. Plenty of good agencies do exactly that.


But that's the point. It has to be run. A WordPress site is never finished. It's a house that needs someone walking the halls every night checking the doors: core updates, plugin updates, PHP versions, compatibility conflicts, backups, malware scans. Skip a month and you're gambling. Most small business sites we inherited back then hadn't been touched in a year or more.


So more than five years ago we made a call that raised a few eyebrows at the time: we stopped, and we directed our energy into platforms where security is handled centrally, at a scale no individual agency can match. Fewer doors. And every door built, watched, and patched by the same team that built the house.


The quieter threat nobody mentions: cheap hosting


Here's the part that gets left out of most "is WordPress safe" conversations: often it isn't the software at all. It's where the site lives.


Budget overseas shared hosting is enormously common, because the price looks great. But shared hosting means your site lives in a block of flats with hundreds of strangers, and in the worst setups, a break-in through any flat can put the whole building at risk. Ageing server software, weak isolation, and support tickets that vanish into another timezone. One analysis found 87.8 percent of exploit attempts bypass standard hosting defences, which tells you how much protection a $4-a-month plan is really buying. Hide My WP Ghost


We've been called in to rescue enough hacked sites over the years to know the pattern. It's rarely the business owner's fault. Nobody told them their beautiful new website was parked in a bad neighbourhood.


Now add frontier AI to the picture


This is where 2026 changed the conversation entirely.


The most capable AI models on the planet right now, Anthropic's Claude Fable 5 and OpenAI's GPT-5.6 Sol, are so effective at security research that OpenAI rates the GPT-5.6 family as high capability in cybersecurity, gating its cyber-focused variant to approved partners, and access to Anthropic's most capable model class was restricted partly over concerns about offensive cyber capability, with US export controls applied.


Read that again: the companies building these tools consider the capability serious enough to lock parts of it away. MindFortMedium


The safeguards on those official models are real. The problem is the same capability class in the wrong hands: jailbroken models, leaked models, open models with the guardrails filed off.


In November 2025, one AI developer reported that a threat actor had used its models to automate 80 to 90 percent of the effort involved in an intrusion, with human involvement limited to critical decision points. UK safety-institute evaluations found the length of cyber tasks AI models can complete unassisted is doubling roughly every eight months. arxivStingrai

Now put the two halves together. On one side: an ecosystem publishing 30-plus new vulnerabilities a day, half unpatched at disclosure, sitting on shared servers. On the other: automated attackers that read every disclosure instantly and work at machine speed, around the clock. The five-hour window isn't shrinking because hackers got smarter. It's shrinking because they stopped being the ones doing the typing.


The burglar who never sleeps has arrived, and the house with 60,000 doors is exactly what he's built for.


Illustration of a crowded apartment block with one window leaking code up the building, next to a small single-door house, representing the risks of cheap shared hosting.

Why we chose Wix Studio


When we moved, we moved to Wix Studio, and every year since has confirmed it. A few reasons:


Security is someone else's full-time job. On a closed, managed platform, there is no plugin roulette, no PHP version anxiety, no 2am update. One security team protects millions of sites, with the resources that scale brings.


They invest in the future, visibly. We've watched Wix ship AI tooling, automatic LLMs.txt files for AI search (yes, we wrote a whole post about side gates), and serious SEO infrastructure, usually before clients even know they need it. When we bet on a platform, we're betting on its roadmap, not just its present.


Wix Headless opens the ceiling. The old knock on website builders was the ceiling: fine for brochure sites, limiting beyond that. Headless removes it. We can now use Wix as a secure backend engine (content, stores, bookings, members) while building completely custom front ends and applications on top. Enterprise-grade flexibility, without inheriting enterprise-grade security babysitting.


The backend business tools are the deal-maker. This one gets overlooked constantly. A website is the shopfront, but businesses run on the machinery behind it: bookings, payments, quotes, invoicing, CRM, email automation, member areas. With WordPress, each of those is another door from another carpenter. Here, they're built in, integrated, and covered by the same security umbrella. For a lot of our clients, that machinery matters more than the homepage ever will.


What about vibe coding?


We use AI-assisted development every day, and we love it. It has genuinely changed what a small team can build, and how fast. But it isn't a complete solution on its own, and the security data backs that up: Patchstack specifically called out AI-generated "vibe coded" plugins shipped by developers who can't audit the code the AI wrote for them. Hide My WP Ghost


That's the distinction that matters. Vibe-coded software running loose on a self-managed server is just more doors from more carpenters, faster than ever. Vibe-coded applications built on secure, managed platforms, reviewed by people who've been reading code for decades, are a different thing entirely. That's how we build: AI speed, human accountability, and a foundation someone serious is guarding.


Any downsides to the path we chose?


Fair question, and we'd rather answer it than dodge it.


Less raw flexibility than a self-hosted server? True, and that constraint is precisely why the platform is defensible. Every wall you can't knock out is a wall an attacker can't knock out either.


Platform dependence? Also true. But dependence on a profitable, publicly listed company with a world-class security team beats dependence on a plugin developer who may have stopped maintaining their code in 2021. Everything runs on trust in somebody. We chose to place ours carefully.


Ongoing subscription cost? Yes, and it's predictable, which is the part people learn to love. The alternative isn't free. It's maintenance retainers, emergency malware clean-ups, and the occasional forced rebuild, arriving on the schedule of your worst week


Illustration comparing two houses on one street, one covered in open doors and one with a single closed door and porch light, representing the choice between a self-managed site and a managed platform.

Where this is all heading


The same thinking that took us off WordPress now takes us somewhere more interesting. If the platform handles the security, our energy goes into what actually grows a business: complete, scalable solutions. Websites, yes, but also the automations behind them, custom business apps, and increasingly the AI business systems we design and integrate: AI assistants trained on your business, workflow automation, lead qualification, reporting that writes itself. All connected, all on foundations we trust.


We're based in Joondalup and we've been helping Perth businesses with web design, development, SEO, and digital strategy for a long time, but none of this work cares about postcodes. We build and support secure websites and AI systems for clients across Western Australia and nationwide.


So here's where the story closes the loop. You can't stop the burglar existing. He's software now, he's funded, and he's already read tonight's locksmith notes. What you control is the house. You can keep patching 60,000 doors and hope every carpenter stays awake. Or you can live somewhere with fewer doors, better locks, and a security team that never sleeps either.


We know which house we'd rather manage. If you'd like a straight answer on how yours is looking, book a free discovery call and we'll take a walk around it together.


Book a FREE Video Call

bottom of page