What WordPress looks like in 2026
Still the right answer for most of our clients, for reasons that have nothing to do with plugins.
Every year someone announces that WordPress is finished, and every year it quietly runs a larger share of the web than the entire rest of the CMS market combined. We still recommend it to most of the businesses that come to us — but not for the reason it usually gets recommended. The plugin ecosystem is not the argument for WordPress in 2026. It is the part you have to manage.
The number that matters, and the one that doesn’t
As of August 2026, W3Techs puts WordPress on 41.1% of all websites, and 59.1% of every site whose content management system is known. Its nearest competitor is not close.
That is worth knowing and worth almost nothing as a reason to choose it. Popularity is not fitness for your project; it is just weather. What the number does buy you is more practical and more boring, and we will come back to it.
Core got serious
WordPress 7.0 “Armstrong” landed on 20 May 2026, built by more than 875 contributors — over 200 of them contributing for the first time — across 420-plus enhancements and fixes. The current release is 7.0.3, out on 6 August. 7.1 is due on 19 August 2026, with 7.2 scheduled for 10 December.
What actually shipped in 7.0 is more interesting than the version number:
- An AI Client and an Abilities API in core. WordPress can now talk to generative models natively, and plugins can register what they are able to do so an assistant can use them properly. Image generation, titles, excerpts and alt text sit in an optional plugin rather than being forced on you.
- A redesigned admin, with a ⌘K command palette, a proper font management screen, and revision history you can scrub through visually.
- Block-level notes — editorial comments attached to the thing being discussed, which is most of what review actually needs.
- Device-specific visibility controls, block-level custom CSS, and new Heading, Breadcrumbs, Icons and gallery lightbox blocks — several of which used to be a plugin each.
That last point is the trend worth watching. Core is steadily absorbing the jobs a stack of small plugins used to do. Every one it absorbs is one fewer thing on your site with its own update cycle, its own owner and its own risk of being abandoned.
The plugin problem, stated plainly
Patchstack’s State of WordPress Security in 2026 counted 11,334 new vulnerabilities across the WordPress ecosystem in 2025 — up 42% on the year before, with high-severity findings more than doubling. Where they were found:
- 91% in plugins. 9% in themes.
- Six in WordPress core — all of them rated low priority.
- 46% were disclosed publicly with no fix available from the developer.
- For the heavily targeted ones, the median time from disclosure to first exploit was about five hours.
Six low-priority issues in the software itself, against eleven thousand in the things people bolt onto it. When a client tells us their last WordPress site “kept getting hacked”, this is almost always the story — not WordPress failing, but a site carrying twenty-odd plugins nobody had audited since launch, two of them no longer maintained by anyone.
So the honest position is this: the extensibility everyone sells WordPress on is also its largest liability. The answer is not to fear plugins. It is to run few of them, choose them like you would choose a supplier, and know who maintains each one.
The governance question
Clients do ask about the ongoing dispute between Automattic and WP Engine. Fairly: it has been noisy, and it touches the trademark and the foundation that sit around the project.
As things stand it is unresolved. The court allowed the majority of WP Engine’s claims to proceed following a hearing in June 2026, counterclaims have been filed in the other direction, and a trial is not expected before late 2026 at the earliest. We are not going to pretend to know how it ends.
What we can say is what it means for your website, which is: very little. The software is open source and stays that way. Your content is yours, on hosting in your name. This is a dispute between companies in the ecosystem, not a question about whether the platform continues to exist — and the practical protection against any of it is the same protection against everything else: own your stack, and don’t let one vendor hold a piece of it hostage.
Why we still choose it — four reasons, none of them plugins
1. You can leave. The content is in a database you control, in an open format, on hosting in your name. Every hosted platform we are asked to compare it against fails this test in some way, and it is the single most expensive thing to discover late.
2. You can hire. That 41.1% is worth something after all — not as a popularity contest, but as a labour market. If we disappeared tomorrow, you could find someone competent to pick up your site by the end of the week. That is not true of a bespoke platform, and it is barely true of some of the newer builders.
3. The editing model finally suits non-technical teams. Structured editing means your team changes content without ever entering the layout layer — so nobody breaks the design by writing a paragraph. That took years to become true. In 2026 it is true.
4. It does not force a delivery method on you. The same WordPress install can serve pages dynamically or be published out as finished static files. That is a decision you get to make on the merits, and change later.
Where we would not reach for it
- A product with real application logic. A web app is a web app; a CMS is the wrong foundation for one.
- A single landing page with no ongoing content. Admin nobody logs into is admin nobody patches.
- Any project where the only reason given is “because there’s a plugin for it”. That is the sentence that builds the sites we get called in to rescue.
What’s coming next
The Gutenberg project runs in four phases: easier editing, customisation, collaboration, then multilingual. WordPress is in phase three. Block-level notes shipped in 7.0; full real-time co-editing was pulled from that release and is still being worked on — a decision we think reflects well on the project, because shipping half of that feature would have been worse than shipping none of it. Native multilingual support is phase four, and still some way out.
If you run a site in several languages, that is genuinely worth planning around rather than waiting for.
FAQs
Is WordPress still secure enough for a business site?
Yes, if it is built with restraint. Core recorded six low-priority vulnerabilities in 2025. The risk is in what gets added, so a curated stack with no abandoned plugins is the whole discipline.
Should we wait for the next version before rebuilding?
No. WordPress ships two or three times a year and always will. A well-built site takes those updates in its stride; that is what “well-built” means here.
Do we need the AI features in 7.0?
Not unless they solve something. The generation tools are an optional plugin, not part of the default install, and we are happy to leave them switched off.
Does the Automattic and WP Engine dispute put our site at risk?
No. It is a commercial and trademark dispute between companies. The software remains open source, and a site on hosting in your own name is not a party to any of it.
Next steps
- Planning a build: Custom Website Design & Build.
- Want the speed and security without the public attack surface? Static Site Builds.
- Inherited a site and unsure what is on it? Request an audit.
- Ready to talk? Start a project — we read every brief personally and reply within one working day.