Home About
Services GEO / AI Visibility SEO + GEO Audit SEO Services Google Ads Web Design Email Marketing All Services Marketing for RCIC Best RCIC Marketing Agency
Pricing
Resources Free Visibility Audit Growth Calculator Trust Score RCIC Compliance Checklist SEO Tools Blog
Contact
Get the Book

When a rebuild is the wrong spend

A
Alioune Faye
Director, AFDV Marketing
Oct 6, 2026 6 min read

We build custom websites for a living, and our own service page says a rebuild may be the wrong spend. This is the evidence behind that sentence: what the WordPress security numbers actually say, the one measurement that does favour moving, and the three conditions that make a rebuild worth paying for. If none of them apply to you, keep your money.

The sentence on our own service page

Our website page carries this line, and it has been there longer than this article:

"I already have a WordPress site. Do I need this? Maybe not. If your current site is compliant, fast, and converting, a rebuild may be the wrong spend, and we will say so on the fit call."

That is easy to write and expensive to mean. So here is the evidence behind it, including the parts that argue against the thing we sell.

The number everyone quotes is worthless

You have seen some version of "WordPress accounts for ninety per cent of hacked websites". It gets repeated in pitch decks, usually by somebody selling a rebuild.

The original figure comes from a security vendor's report on infections it cleaned, and the same sentence that gives the number also says the sites were "the predominant CMS among our users". That is the sampling frame admitting itself.

The statistic answers: of the sites that got hacked, how many were WordPress. What a practice owner actually needs to know is the reverse: of WordPress sites, how many get hacked. Converting one into the other needs a denominator nobody publishes.

It gets worse for the pitch. Closed platforms run no comparable public disclosure pipeline, so a hosted builder with zero published vulnerabilities is telling you about its source code licence, not its safety.

One more thing worth knowing, because it explains why this myth will not die. The article most often linked for that ninety per cent figure carries a modified date of April 2026, a publication date of March 2019, and reports data from 2018. Search engines serve it as current. The article is seven years old. The data in it is eight.

What the real numbers say

Two security firms publish annual counts. They disagree on the total, which is why the agreement underneath matters.

Of the 11,334 WordPress vulnerabilities disclosed in 2025, 91 per cent were in plugins, 9 per cent in themes, and six were in WordPress core. Six. All rated low priority. The prior year: 96 per cent plugins, seven in core on one count, five on another.

Core is around one twentieth of one per cent of the total.

That reframes the whole argument. This is not a defect in the thing your site is built on. It is a consequence of what gets installed on top of it, which is a purchasing decision, which is manageable.

The firms publishing those totals sell WordPress security and pay researchers to find the bugs. One of them coordinated over half of a year's disclosures. Another pays up to 31,200 dollars per finding. Their totals rise partly because the bounty budget rises. One of them says so in its own report: "the rising number doesn't necessarily translate to increased risk."

The honest counterweight, since we are being honest. Median time from disclosure to first exploitation is measured in hours, not weeks. Nearly half of disclosed issues had no vendor fix available on the day they were published. And core is not spotless: a July 2026 release fixed one critical and one high-severity core issue. An unmaintained WordPress site is a genuinely bad idea. That is an argument for maintenance, not for a rebuild.

The real incidents of the last eighteen months make the same point. The largest compromised around 1.2 million sites through tampered scripts on a plugin vendor's content delivery network. Another was a backdoor committed into a plugin portfolio sold to a new owner. Both third party supply chain. Neither involved core.

The one measurement that does favour moving

Google publishes Core Web Vitals pass rates by platform. Pulled 2 September 2026, mobile, all regions, from the CrUX release dated 1 July 2026:

  • Duda 85.7 per cent
  • Wix 80.4 per cent
  • Shopify 77.0 per cent
  • Squarespace 71.7 per cent
  • Webflow 69.8 per cent
  • Drupal 64.5 per cent
  • The web overall 53.2 per cent
  • WordPress 49.5 per cent, across 2.76 million origins

WordPress is last among the major platforms. That is real and it is worth saying plainly.

Two things stop it being a knockout. The gap is closing fast: WordPress went from 32.5 per cent in 2023 to 49.5 now, with the distance to the web average down from 9.19 points to 3.76. Anyone telling you WordPress performance is getting worse is wrong on the record.

And a platform average describes everyone who builds on it, not a ceiling. WordPress takes anybody with any plugin, so its distribution is wide. The Web Almanac's own conclusion is the fair one: more extensible systems allow both excellent and poor implementations.

So the number tells you about the population, not about your site. Your site has a measurement of its own, and it is free.

The risk that is real and is not about code

In September 2024 a hosting company was cut off from wordpress.org. Its access to the update and plugin channel was blocked, its customer list was published, and control of a widely used plugin listing was taken over.

A federal court ordered all of it reversed within seventy two hours, including restoring the company's access to its 2024-09-20 state. That order still runs, and the case is set for a ten day jury trial in October 2027. A settlement conference was held in July 2025 and the case did not settle.

The usual telling gets that wrong in both directions. Nobody took WordPress away and nobody can, since the code is open source. What happened is narrower. The update and plugin distribution channel has a single point of control, it was used against one company, and it took a court to reverse.

For a solo practice with a handful of plugins, know it and do not act on it. For a firm whose whole operation depends on that channel, it is a board-level question.

What this does not change

There is a claim going around that one platform or another gets you cited by AI answer engines. We looked and there is no evidence for it. No study we could find has tested content management system as a variable, and the one controlled test of structured data, on 1,885 pages against roughly four thousand matched controls, found AI Overview citations down 4.6 per cent with the other engines statistically indistinguishable from zero.

So if anybody tells you a rebuild gets you into AI answers, ask for the study. That includes us.

The three conditions that make a rebuild worth paying for

Not one of these is about WordPress being bad.

Measurably slow, and unfixable inside the current build. Measure yours before accepting anybody's opinion. If it passes, the platform average is not your problem.

You cannot make the change you need without a developer every time. If the structure of the site fights you monthly, you are paying for a rebuild already, in instalments.

The site cannot do a thing your practice now requires. Multilingual done properly, structured service pages, an intake flow that feeds your CRM. Bolting a fourth plugin onto a build that was never shaped for it is how sites become slow and fragile in the first place.

If none of those describe you, the better spend is maintenance, hosting, and the pages you have never written.

What maintenance actually means

Updates on a schedule rather than when something breaks. The plugin list audited yearly and anything unused removed, because 91 per cent of disclosed vulnerabilities sit there. Disclosure count is not risk, which is why removing what you do not use is the cheap move. Hosting that is not the cheapest tier available. Backups you have restored at least once, so you know they work.

That is an afternoon a quarter plus whatever your host charges. It is not exciting and it is not what an agency wants to sell you. It is what the numbers above actually support.

A
Written by

Alioune Faye

Director, AFDV Marketing

Alioune helps immigration consultants build predictable client acquisition systems. With a background in technical engineering and front-line sales, he brings a unique analytical approach to digital marketing for RCICs.

Frequently Asked Questions

Core is, on the published record: six disclosed core vulnerabilities out of 11,334 in 2025, all low
Almost certainly not, if you are a small practice. The court ordered access restored within seventy two
On average, yes, and it is last among the major platforms at 49.5 per cent passing Core Web Vitals
No evidence supports that. Nobody has tested platform as a variable, and the one controlled test of
When you have measured your site against the three conditions above and at least one is true. If none
Coming soon

We're not taking new clients right now

We're writing a book on growing an RCIC practice. Leave your email and get it when it's out.

Get the Book

Get RCIC Marketing Tips Delivered

Join immigration consultants who receive actionable marketing strategies, industry insights, and growth tips every week.

No spam. Unsubscribe anytime. We respect your privacy.

Back to All Articles

Before you go: the advertising rules on one page

What an advertisement carries under sections 44 to 46 of the Code, as applied to every page AFDV builds. One page, free for licensed RCICs.

Get the checklist

No spam. Unsubscribe anytime.