WordPress in crisis: governance, security and the rise of headless CMS.
Matt Mullenweg used his WordCamp keynote to call WP Engine a cancer. What followed damaged trust across the entire WordPress ecosystem. About the governance crisis, the growing security burden, and the alternatives that are becoming increasingly mature.
On 20 September 2024, Matt Mullenweg took the stage at WordCamp US. The founder of WordPress, the CMS behind 42% of the web, used his keynote to call hosting company WP Engine "a cancer to WordPress". What followed was a series of decisions that damaged trust in the entire WordPress ecosystem in ways nobody had anticipated.
A year and a half later, the consequences are still being felt. Automattic's valuation has fallen by two-thirds. A fifth of its staff have left. The lawsuit is still ongoing. Meanwhile, the stream of security vulnerabilities continues, and headless alternatives are becoming increasingly mature. This is an attempt to lay out the facts.
How a personal conflict shook an ecosystem
The background matters. WordPress is open-source software, but the .org infrastructure (plugin repository, theme repository, update mechanism) is effectively managed by Automattic, Mullenweg's commercial company. That arrangement was always an awkward one, but it worked as long as nobody pushed it to the limit.
Following the keynote, Automattic published a licensing demand for 8% of WP Engine's gross monthly revenue. Within five days, Mullenweg blocked WP Engine's access to WordPress.org. Plugin and theme updates for more than a million websites were disrupted. Not as a side effect, but as leverage.
On 2 October, WP Engine filed a lawsuit with 20 counts, including extortion and computer fraud. Ten days later, WordPress.org took over the Advanced Custom Fields (ACF) plugin, a tool with more than 2 million active installations, and renamed it without permission. The ACF team described it as a first in WordPress' 21-year history.
"Automattic is doing open source dirty."
David Heinemeier Hansson, creator of Ruby on Rails
What makes it more uncomfortable still: recently released documents revealed that Mullenweg planned to approach 10 competing hosting companies with similar royalty demands. He described it internally as "all-out nuclear war". As of March 2026, 13 of the 20 counts still stand.
The underlying problem goes beyond this conflict. WordPress presents itself as a community project, but its governance structure gives a single person disproportionate power over the infrastructure on which millions of sites depend. That was already visible for some time. What's different is that Mullenweg has now explicitly used it as a weapon, and in doing so has made the vulnerability visible to everyone.
The damage in numbers
A day after the lawsuit, Mullenweg offered all employees an "Alignment Offer": $30,000 or six months' salary, on the condition that they leave immediately. 159 employees accepted, including the Executive Director of the WordPress project. Six months later, a further round of redundancies followed, affecting another 281 people at WooCommerce, Tumblr and marketing.
BlackRock had invested at $85 per share, a valuation of roughly $7.5 billion. By June 2025, that stood at $27.74. In January 2025, Automattic reduced its WordPress core contributions from 3,988 to just 45 hours per week. The Linux Foundation responded by launching the FAIR Package Manager as a decentralised alternative to WordPress.org.
The security problem that was always there
Setting the governance drama aside, WordPress has a more structural security problem. The plugin architecture that made the platform so flexible is also the web's largest attack surface. Patchstack has documented this year after year, and the trend is not encouraging.
The architectural cause is clear. An average WordPress site runs 15 to 20 plugins, each with its own quality level and update cycle. Of all the plugins in the WordPress.org repository, 59% haven't been updated in over two years. In 2023, a single XSS vulnerability in the Freemius framework cascaded to 1,248 plugins at once. That isn't a bug; it's an architectural problem.
Sucuri's annual report confirms the picture: WordPress is responsible for 96.2% of all CMS-related infections they cleaned up in 2024. That is partly a function of market share. But it is also a function of an ecosystem in which quality control is largely absent, and where only 12% of sites run an actively supported PHP version.
The alternatives that didn't exist five years ago
Headless CMS isn't new as a concept, but it has only recently become genuinely practical for more than enterprise budgets. The market is worth roughly $0.8 to 1.5 billion, with annual growth rates between 15% and 23%. A Hygraph survey of 400 technology leaders found that 44% already use a headless CMS.
A mature landscape
Contentful leads the enterprise segment with $339 million in funding. Sanity is growing fastest, from $10.6 million in revenue in 2021 to over $40 million in 2024. Strapi dominates open source with around 60,000 GitHub stars. Directus offers a similar open-source model, with clients such as Adobe and AT&T.
Documented migrations report 50% faster page loads and 30% lower infrastructure costs. To be fair, those figures often come from the platforms themselves. What is objectively true is that headless architecture frees you from PHP lock-in, drastically reduces your attack surface (no public admin, no plugin execution), and leaves your frontend choice entirely open.
An honest look ahead
WordPress is not going away. Not with a 42% market share, not with millions of existing sites, not with an ecosystem of thousands of developers and agencies who depend on it. It would be naive to suggest otherwise.
But the situation has fundamentally changed. The governance crisis has shown how vulnerable an ecosystem is when it depends on the decisions of one person. The security figures get worse every year, not better. And for the first time, the alternatives are mature enough to offer a realistic migration path, not only for enterprise budgets but also for mid-sized projects.
For new projects, the trade-off has shifted. Five years ago, the question "why not WordPress?" had few good answers. Now there are several: governance risk, a growing security surface, PHP dependency, and the availability of better architectures for modern content delivery.
For existing WordPress sites, it is more nuanced. Migrating a working site purely on principle is rarely sensible. But at every major revision or redesign, it is the moment to take alternatives seriously. Not because WordPress is bad, but because the conditions under which it was the obvious choice are changing.
Thinking about your CMS strategy?
We are happy to help you weigh up the options. No preferred outcome, just an honest conversation about what suits your situation.
Get in touch