The Burglar Who Never Sleeps: Why We Left WordPress Before the AI Threat Arrived

Picture a burglar working your street. He's patient, but he's human. He can try one door handle at a time, and eventually he gets tired and goes home.
Now imagine a burglar who can try every door on every street in the country at once. He doesn't sleep. He doesn't get bored. And every time a locksmith publishes a note saying "this particular lock has a flaw", he's read it and reached your door within five hours.
That burglar exists now. He's software, and he's very busy. This is the story of why we saw him coming more than five years ago, and what we did about it.
The numbers have gone vertical
For years, website security was a slow-burn problem. It isn't anymore.
In 2025, 11,334 new vulnerabilities were discovered across the WordPress ecosystem, the highest number ever recorded and a 42 percent jump on the 7,966 found in 2024. More high-severity vulnerabilities were found in 2025 than in the previous two years combined.

And the burglar is getting faster. Among heavily exploited vulnerabilities, 20 percent were attacked within six hours of being publicly disclosed, and 70 percent within seven days. The median time from disclosure to first exploitation was five hours. Five hours. If your web person checks your site weekly, you're not in the race. The Repository
Then there's the AI layer on top. CrowdStrike recorded an 89 percent year-on-year jump in AI-enabled attack operations, and IBM found that one in four malicious breaches in its 2026 study were AI-enabled. This isn't a future problem. It's a this-morning problem. StingraiDeepStrike
The house with 60,000 doors
So why does WordPress cop the worst of it? Not because the core software is badly built. It isn't. Of those 11,334 vulnerabilities, just two were found in WordPress core. Plugins accounted for 91 percent. The Repository
Here's the useful way to picture it. A WordPress site is a house, and every plugin is a door. Each door was built by a different carpenter, some brilliant, some hobbyists, some who moved overseas years ago and stopped answering the phone. The official directory alone holds tens of thousands of these doors, and a typical site has 20 to 30 of them fitted.
You didn't build those doors. You can't inspect them. You're trusting that every carpenter is still awake, still patching, still around. The data says many aren't: 46 percent of vulnerabilities disclosed last year weren't fixed by the developer before the flaw was made public. That means the burglar got the locksmith's note before the door got a new lock. The Repository
Why we walked away, more than five years ago
We should be upfront: we built WordPress sites for years, and WordPress can still have its place. In the right hands, with a dedicated maintenance budget, a hardened server, and someone genuinely responsible for updates, it can be run well. Plenty of good agencies do exactly that.
But that's the point. It has to be run. A WordPress site is never finished. It's a house that needs someone walking the halls every night checking the doors: core updates, plugin updates, PHP versions, compatibility conflicts, backups, malware scans. Skip a month and you're gambling. Most small business sites we inherited back then hadn't been touched in a year or more.
So more than five years ago we made a call that raised a few eyebrows at the time: we stopped, and we directed our energy into platforms where security is handled centrally, at a scale no individual agency can match. Fewer doors. And every door built, watched, and patched by the same team that built the house.
The quieter threat nobody mentions: cheap hosting
Here's the part that gets left out of most "is WordPress safe" conversations: often it isn't the software at all. It's where the site lives.
Budget overseas shared hosting is enormously common, because the price looks great. But shared hosting means your site lives in a block of flats with hundreds of strangers, and in the worst setups, a break-in through any flat can put the whole building at risk. Ageing server software, weak isolation, and support tickets that vanish into another timezone. One analysis found 87.8 percent of exploit attempts bypass standard hosting defences, which tells you how much protection a $4-a-month plan is really buying. Hide My WP Ghost
We've been called in to rescue enough hacked sites over the years to know the pattern. It's rarely the business owner's fault. Nobody told them their beautiful new website was parked in a bad neighbourhood.
Now add frontier AI to the picture
This is where 2026 changed the conversation entirely.
The most capable AI models on the planet right now, Anthropic's Claude Fable 5 and OpenAI's GPT-5.6 Sol, are so effective at security research that OpenAI rates the GPT-5.6 family as high capability in cybersecurity, gating its cyber-focused variant to approved partners, and access to Anthropic's most capable model class was restricted partly over concerns about offensive cyber capability, with US export controls applied.
Read that again: the companies building these tools consider the capability serious enough to lock parts of it away. MindFortMedium
The safeguards on those official models are real. The problem is the same capability class in the wrong hands: jailbroken models, leaked models, open models with the guardrails filed off.
In November 2025, one AI developer reported that a threat actor had used its models to automate 80 to 90 percent of the effort involved in an intrusion, with human involvement limited to critical decision points. UK safety-institute evaluations found the length of cyber tasks AI models can complete unassisted is doubling roughly every eight months. arxivStingrai
Now put the two halves together. On one side: an ecosystem publishing 30-plus new vulnerabilities a day, half unpatched at disclosure, sitting on shared servers. On the other: automated attackers that read every disclosure instantly and work at machine speed, around the clock. The five-hour window isn't shrinking because hackers got smarter. It's shrinking because they stopped being the ones doing the typing.
The burglar who never sleeps has arrived, and the house with 60,000 doors is exactly what he's built for.

Why we chose Wix Studio
When we moved, we moved to Wix Studio, and every year since has confirmed it. A few reasons:
Security is someone else's full-time job. On a closed, managed platform, there is no plugin roulette, no PHP version anxiety, no 2am update. One security team protects millions of sites, with the resources that scale brings.
They invest in the future, visibly. We've watched Wix ship AI tooling, automatic LLMs.txt files for AI search (yes, we wrote a whole post about side gates), and serious SEO infrastructure, usually before clients even know they need it. When we bet on a platform, we're betting on its roadmap, not just its present.
Wix Headless opens the ceiling. The old knock on website builders was the ceiling: fine for brochure sites, limiting beyond that. Headless removes it. We can now use Wix as a secure backend engine (content, stores, bookings, members) while building completely custom front ends and applications on top. Enterprise-grade flexibility, without inheriting enterprise-grade security babysitting.
The backend business tools are the deal-maker. This one gets overlooked constantly. A website is the shopfront, but businesses run on the machinery behind it: bookings, payments, quotes, invoicing, CRM, email automation, member areas. With WordPress, each of those is another door from another carpenter. Here, they're built in, integrated, and covered by the same security umbrella. For a lot of our clients, that machinery matters more than the homepage ever will.
What about vibe coding?
We use AI-assisted development every day, and we love it. It has genuinely changed what a small team can build, and how fast. But it isn't a complete solution on its own, and the security data backs that up: Patchstack specifically called out AI-generated "vibe coded" plugins shipped by developers who can't audit the code the AI wrote for them. Hide My WP Ghost
That's the distinction that matters. Vibe-coded software running loose on a self-managed server is just more doors from more carpenters, faster than ever. Vibe-coded applications built on secure, managed platforms, reviewed by people who've been reading code for decades, are a different thing entirely. That's how we build: AI speed, human accountability, and a foundation someone serious is guarding.
Any downsides to the path we chose?
Fair question, and we'd rather answer it than dodge it.
Less raw flexibility than a self-hosted server? True, and that constraint is precisely why the platform is defensible. Every wall you can't knock out is a wall an attacker can't knock out either.
Platform dependence? Also true. But dependence on a profitable, publicly listed company with a world-class security team beats dependence on a plugin developer who may have stopped maintaining their code in 2021. Everything runs on trust in somebody. We chose to place ours carefully.
Ongoing subscription cost? Yes, and it's predictable, which is the part people learn to love. The alternative isn't free. It's maintenance retainers, emergency malware clean-ups, and the occasional forced rebuild, arriving on the schedule of your worst week

Where this is all heading
The same thinking that took us off WordPress now takes us somewhere more interesting. If the platform handles the security, our energy goes into what actually grows a business: complete, scalable solutions. Websites, yes, but also the automations behind them, custom business apps, and increasingly the AI business systems we design and integrate: AI assistants trained on your business, workflow automation, lead qualification, reporting that writes itself. All connected, all on foundations we trust.
We're based in Joondalup and we've been helping Perth businesses with web design, development, SEO, and digital strategy for a long time, but none of this work cares about postcodes. We build and support secure websites and AI systems for clients across Western Australia and nationwide.
So here's where the story closes the loop. You can't stop the burglar existing. He's software now, he's funded, and he's already read tonight's locksmith notes. What you control is the house. You can keep patching 60,000 doors and hope every carpenter stays awake. Or you can live somewhere with fewer doors, better locks, and a security team that never sleeps either.
We know which house we'd rather manage. If you'd like a straight answer on how yours is looking, book a free discovery call and we'll take a walk around it together.
Book a FREE Video Call





