We already compared WordPress and Next.js on speed. This is the other, less pleasant topic: security, with sourced numbers.
The problem rarely comes from WordPress itself
WordPress runs a very large share of the world's websites. Its core software is closely watched and regularly fixed by its team. Most security flaws come from somewhere else: the plugins people install on top of it.
Patchstack, a company that tracks WordPress security flaws, publishes a report every year. In 2024, 96% of the flaws it found were in plugins, 4% in themes, and only 7 flaws in WordPress core. In 2025, plugins still made up 91% of the flaws.
So a well-kept WordPress site, with a few plugins that are all up to date, doesn't carry the same risk as a site with fifteen plugins added over the years, some of them forgotten.
Why plugins are the weak spot
There are tens of thousands of WordPress plugins, made by very different teams. Some are serious and looked after. Others were abandoned years ago.
According to the same Patchstack report, 43% of the flaws found in 2024 could be used without having an account on the site. That makes them easy to exploit in bulk: a bot tries them on thousands of sites at once. Nobody has to be after your site in particular for it to get hit.
The risk also grows with time. The older a site gets, the more plugins it collects, and the harder it becomes to know which ones are still needed and which ones are up to date.
What a hack really costs
With specialist services, just cleaning up a hacked site costs anywhere from a few hundred to a few thousand dollars, depending on how bad it is. And that is only part of the bill.
Add the days when the site is offline and no customer can find you, the Google visits you lose if the site gets flagged as dangerous, and the time spent putting everything back in order. Then there is the trust you lose when a customer opens your site and lands on a suspicious redirect or an error message.

No need to panic: just know what's running on your site
WordPress is still a good tool. Plenty of WordPress sites run for years without ever being hacked. The question to ask is simple: does anyone know what's installed on the site, and is someone really keeping it up to date?
A site left alone for years, with plugins nobody maintains anymore, is at real risk. A site that someone checks regularly is at much less.
If you already have a WordPress site
- Keep as few plugins as you can. Every extra plugin is one more door to watch.
- Update WordPress, the theme and every plugin as soon as an update comes out, not once a year.
- Delete plugins and themes you no longer use. Deactivating them isn't enough.
- Use a unique, strong password for the admin area, never one you already use somewhere else.
How we choose the technology for a new site
As we said in our WordPress vs Next.js comparison, WordPress is still a good choice for some projects, especially if you want to edit your content yourself, and we build with it too. For most of the sites we deliver, we choose Next.js. Speed comes first, then security: with fewer third-party plugins to watch, there are fewer doors to keep shut.
In the end it's a practical question: how much time will someone have to spend each month watching what runs on your site to keep it safe?
How SimplerWebs can help
- Website maintenance: we keep your site up to date and watch for signs of trouble before they turn into a hack.
- Website redesign: if your WordPress site has aged and collected forgotten plugins, we look with you at what is worth keeping.
- Custom website: for a new project, we start from a clean base that won't need hours of watching.
In short
WordPress security flaws mostly come from plugins, and the risk grows if nobody keeps an eye on what runs on the site. Fixing a hacked site often costs more, in money and time, than looking after it regularly.
Not sure where your current site stands? We can look at it with you.
Frequently asked questions
Is WordPress dangerous by itself?
No. The core software is well looked after. Most flaws come from the plugins installed on it: 96% of the WordPress flaws Patchstack recorded in 2024.
How many plugins is too many?
There is no set number. For each plugin, ask two questions instead: is it still used, and is it up to date? If the answer is no, delete it.
Do I need to drop WordPress to be safe?
Not necessarily. A well-kept WordPress site with a few up-to-date plugins is a reasonable choice. We recommend Next.js for most of our new projects, but WordPress is still a valid option.
How do I know if my WordPress site is at risk?
Start by checking how many plugins are installed, whether they're up to date, and whether you still know what each one is for. Our SEO audit also reviews the technical state of your site.
What do I do if my site is already hacked?
Act fast. The longer a site stays infected, the more the repair costs and the more trust your customers lose. We can point you in the right direction, even if we didn't build the site.