software maintenance security patch vulnerability

WordPress Has Thousands of Maintainers. Does Your Replacement?

By John Locke on August 27, 2026

Last month, a critical WordPress vulnerability triggered emergency patching across the web and reignited a familiar argument: if WordPress keeps having security issues, why not let AI build something new instead?

It's a reasonable question.

It's also the wrong one.

The real question isn't whether AI can build software faster. It can. The real question is who's going to maintain that software after launch.

That's not an abstract debate. It's the exact argument playing out on LinkedIn right now and in agency sales pitches. One recent post argues that WordPress "no longer makes sense" in the AI era. A competing CMS vendor describes it as little more than a relic of 2003-era web publishing. Another agency touts a static-site-plus-AI approach that cut tooling costs by 60-70%. Different conclusions, same premise: mature CMS platforms are becoming unnecessary because AI makes custom software cheap.

WordPress runs on code that gets looked at, tested, and patched by a global community, thousands of developers deep, every single week. When you leave it for something an AI built from scratch, that code has exactly one maintainer: you. And "you" usually means whoever happens to be available, not whoever originally wrote it.

That's the part a growing wave of "AI instead of WordPress" pitches tends to leave out. The cost of creating software is falling fast. The cost of maintaining it isn't.

None of that math counts the maintainers you're giving up, or what happens after launch. A friend of mine - not a developer, just someone who wanted a small tool for other artists to use - started vibe-coding an app a few months back. When I checked in this week, he still hadn't shipped it. Not stuck exactly, just quietly moved to the back burner: it was deceptively easy to get something working at first, but the list of details he needed to handle to get from "working demo" to something he'd trust in production kept growing - details a mature open source project already worked out years ago, for everyone, for free. That's not a knock on him, or on AI tools - it's just what the data shows happening at every scale, from a side project to a funded startup.

We already have a real-world example of an "AI" provider leaving clients stranded. Builder.ai spent years promising organizations AI-built custom software - and then collapsed in 2025, leaving clients locked out of tools they had paid to have built, with no other vendor who understood the custom architecture well enough to pick it up.

Builder.ai was more a symptom of the hype around AI, and a cautionary tale. From a security standpoint, there are plenty of problems with neglected softfware. All of these represent risk to your business, depending on what you're running:

  • abandoned WordPress plugins
  • abandoned Drupal modules
  • abandoned npm packages
  • abandoned SaaS products
  • abandoned internal business applications

-- if nobody maintains a chunk of software in use, it can become a liability, more "surface area" for an attacker to probe. If AI now gives you the ability to generate a lot more software a lot more quickly -- why won't that just create a bigger problem for you in 18 months, when you've long forgotten what you've built?

Build time is shrinking faster than maintenance time.

The problem is that software isn't expensive because it's hard to create. It's expensive because somebody has to maintain it.

And it's not just us pointing this out. A WordPress developer with twenty years in the ecosystem wrote a direct rebuttal to this exact wave of "we're moving everything to AI" posts, describing what's actually happening to the clients of the agencies making the switch: they've traded a well-understood maintenance burden for a poorly-understood one. Same conclusion, arrived at independently, from someone who's watched this industry long enough to recognize the pattern.

Still, the case the hype is built on is real. We patched the critical WordPress vulnerability across every client site in under four hours -- the kind of thing we do quietly, all the time, that's genuinely worth mentioning once in a while. 

In the same LinkedIn feed, WordPress consultant Jean Galea posted stats pulled straight from WordPress.org: 39% of WordPress sites aren't on the current version. Around 8% are still on a release from several years back. 28% are running end-of-life PHP that gets zero security patches, no matter what's discovered against it.

His conclusion, and ours: almost none of that is a WordPress problem. It's a maintenance problem. The patches exist. The work is to apply them, and that's exactly the work that gets skipped once a site is "done" and nobody's watching it anymore.

The solution isn't "create a bunch more software." It's engineering discipline: testing, documentation, monitoring, patching, incident response, and the boring maintenance work that keeps systems healthy long after launch.

AI can help with that. We use it every day to write tests, generate documentation, review code, and automate parts of the maintenance process. Used well, it can make engineering teams more effective and help enforce practices that often get skipped when budgets get tight.

What AI doesn't do is make maintenance disappear. It just changes how the work gets done.

Add new comment

The content of this field is kept private and will not be shown publicly.

Filtered HTML

  • Web page addresses and email addresses turn into links automatically.
  • Allowed HTML tags: <a href hreflang> <em> <strong> <blockquote cite> <cite> <code> <ul type> <ol start type> <li> <dl> <dt> <dd> <h1> <h2 id> <h3 id> <h4 id> <h5 id> <p> <br> <img src alt height width>
  • Lines and paragraphs break automatically.

Drupal Canvas — Block HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href> <p> <br> <ul> <ol> <li>

Drupal Canvas — Inline HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href>

About the Author

Profile picture for user John Locke

John Locke is the lead developer and founder of Freelock, LLC. In addition to being a proficient web developer, he is an experienced technical writer, network administrator, and all around problem solver. He has worked with computers since 1984, and currently advises small businesses on open source software.

More Like This

Website management, Drupal, WordPress, security, automation, configuration management.
🕑May 28, 2026 🖋John Locke 💬0

Every Night, Argo Watches

While your site is running, things change. A content editor tweaks a configuration setting. A security vulnerability surfaces in a dependency. A production fix gets applied directly instead of going through the normal release process.

Bloody crime scene, gumshoe detective, magnifying glass, dusty office
🕑May 22, 2026 🖋John Locke 💬0

The Night the Internet Tried to Kill Your Website

May 2026
My name doesn't matter. Call me the op. I run a small shop — we keep websites alive, patch the holes before the wrong people find them, and make sure that when something goes sideways, there's always a way back. It's not glamorous work. But this spring? This spring was something else.
AI vulnerabilities, security incidents, resilience, Drupal WordPress, cybersecurity
🕑May 18, 2026 🖋John Locke 💬0

The Rules Have Changed: Security in the Age of AI-Assisted Attacks

Security is getting dramatically harder and more expensive. AI is simultaneously driving an explosion in vulnerability discovery and weaponizing the exploits that follow. The question for every organization with anything online is no longer whether to invest in resilience — it's whether that investment is already in place before the next incident arrives.
Code monster
🕑Mar 29, 2018 🖋John Locke 💬3

Drupalgeddon2: Should I worry about critical security updates?

No, you should not. You should let us worry about them, and go back to your business.

Seriously, we're getting questions from all kinds of people about whether this matters. I'm a bit surprised that there is any question about that. Would you be concerned if your top salesperson was selling for somebody else? If your cashiers were jotting down credit card numbers when they charged a card? If your office became a well-known spot for illicit drug or gun dealers? If your office had a bunch of scammers squatting and running a pyramid scheme? If your confidential client information could be revealed as easily as using a bic pen on an old Kryptonite lock?

Bic Pen vs Kryptonite Lock

We've seen some variation of every single one of those scenarios. And all of them are possible with a remote code execution flaw in a web application, like yesterday's Drupal security vulnerability.

And yet people still