The numbers, the risks, and the tools shaping WordPress right now.
This issue of WP More is brought to you by our sub-reddit; join now and start a WordPress discussion today!
Hello WordPressers!
Welcome to this week’s WP More roundup. This is WP More newsletter issue 50, where you get curated news about WordPress and the WordPress community all in one place.
Issue 50. Half a century of WordPress roundups. This week we looked into market share projections, a damning PHP audit, a clever client training trick, and an AI security agent that caught a live backdoor before it reached a single site.
In this Issue:
- WordPress market share is declining: here’s what the next three years actually look like
- The WordPress.org active install count is easy to fake, and nobody outside WordPress.org can audit it
- Security researchers found 70% of WordPress sites running outdated PHP, and site owners can’t fix it
- WordPress Playground and Blueprints can replace your staging environment for client training
- Wordfence’s AI agent caught a plugin backdoor within two hours, before any site was hit
WordPress Market Share: A Realistic 3-Year Forecast
WordPress peaked at around 43.6% of all websites in 2025. By July 2026, W3Techs put it at 41.5%. Nikolai Graf-Rüssel projects a further 1.1 to 1.4 percentage-point annual decline through 2029, landing WordPress above 37% of all websites. AI-first builders like Wix and Squarespace are winning the simple, first-time site segment: restaurants, freelancers, landing pages.
WordPress holds firm for content-heavy sites, WooCommerce stores, agencies, publishers, and anyone who needs plugin depth and data ownership. The lost segment is low-value commodity installs; the defensible segment is managed WordPress with real performance, security, and AI-assisted onboarding.
Read the full blog on his LinkedIn →
That decline depends on a metric worth questioning, and the next story does exactly that.
The WordPress.org Active Install Count Nobody Can Audit
Marcin Dudek at MakeWPFast spent a day digging into how WordPress.org’s “active installs” figure actually works. The count comes from unauthenticated update-check requests that anyone can POST to, and anyone can inflate a competitor’s numbers by reporting their slug as active on thousands of invented URLs. The number is rounded to one significant digit (”10,000+” means anywhere from 10,000 to 19,999), has no public history, costs 0.34 KB to fake, and yet drives plugin directory ranking.
Dudek built tooling to record daily snapshots going forward, since WordPress.org publishes no historical data. Before picking a plugin based on install count, treat it as directional at best; nobody outside WordPress.org can verify it.
Read the full blog on his MakeWPFast →
Numbers you can’t audit are a trust problem. Numbers running on dead software are a security problem.
70% of WordPress Is Running on an End-of-Life PHP Version
Security researchers at Censys scanned the public internet and found over 70% of publicly visible WordPress sites running outdated PHP. PHP 7.4, which stopped receiving security patches in November 2022, is still the most common engine on the WordPress web. The core problem is an ownership gap: WordPress updates itself through the dashboard, but PHP is a server-level runtime that site owners can’t see or change.
Hosts control it, and most haven’t built fleet-wide lifecycle management for it. The researchers also documented an active defacement campaign targeting these same sites: outdated software, default misconfigurations, no sophisticated exploit needed. The advice to “update your PHP” isn’t wrong; it’s just aimed at people who can’t act on it.
Read the full blog on his WP Maintain →
Not all WordPress news this week is grim. Here’s a practical trick for developers who train clients on block themes.
Brought to you by
WP More Socials
I send this newsletter every week, but do you want to keep up with WordPress and the community?
Then follow WP More’s social profile.
X (formerly Twitter) – https://x.com/WPMoree
LinkedIn – https://www.linkedin.com/company/wordpress-more/
BlueSky – https://bsky.app/profile/wpmore.bsky.social
I post there every day. So, you are not going to miss anything.
Follow WP More, Stay Updated with WordPress!
Train Clients on Block Themes With WordPress Playground and Blueprints
Elliott Richmond came back from WordCamp Europe wanting to try one thing: WordPress Playground and Blueprints for client training. Playground runs a full WordPress instance in the browser via WebAssembly, no hosting needed. A Blueprint is a JSON file that configures the whole environment on load.
Richmond built a trimmed-down version of a client’s real site (50MB instead of 1GB+), with the custom block theme and plugin intact, so the client could explore, edit, and break things in a safe environment that resets every session. When the client forgets something next month, they just open the same link again.
Read the full blog on Elliott Richmond Site →
And speaking of things that work quietly in the background: the last story is about an AI agent that caught a live backdoor before it reached anyone.
Wordfence AI Agent Stops Plugin Backdoor in Under Three Hours
WordPress.org’s Protect the Shire initiative has its first confirmed real-world interception. A supply chain backdoor was planted in the Advanced Responsive Video Embedder (ARVE) plugin (around 20,000 active installs) on July 28. Less than two hours later, Wordfence’s autonomous AI agent PRISM flagged it.
Wordfence notified the WordPress.org Plugins Team at 15:43 UTC, and the plugin was closed for downloads by 16:09 UTC. The entire sequence took under three hours, and because Protect the Shire holds new releases in a cooldown window, the tampered version never reached a single site. The backdoor checked incoming requests for a hardcoded token and, if matched, silently authenticated the attacker as a random site administrator in one HTTP request. PRISM has now found 202 vulnerabilities total, including 88 in the past 30 days.
Read the full report on The Repository →
WordPress Must Read
→ The Future of the Website (joost.blog) – Joost de Valk on where websites are heading: agent-readable surfaces, MCP servers, and why authenticity is the only moat left.
→ How WooCommerce.com Speeds Up Requests by Loading Fewer Plugins (developer.woocommerce.com) – How selective plugin loading cut memory use by 50%+ and dropped key endpoint latency from 800ms to 475ms.
On Other WordPress News
→ Rethinking Our Monthly Team Meetings (make.wordpress.org)
→ WordCamp Creator Studio, Sponsored by WordPress.com: Available for Sign Ups Now! (us.wordcamp.org)
→ WordPress Credits Student Feedback: The Program Works, Now for Quality and Retention (make.wordpress.org)
→ Proposal: Bringing Back the Meetup Organizer Newsletter (make.wordpress.org)
→ WP Engine Accuses Automattic of Destroying Evidence, Asks Court to Dismiss Trademark Counterclaims (therepository.email)
→ Class Action Against Automattic to Proceed After Judge Finds Company Tracked WP Engine Customers (therepository.email)
→ Jamie Marsland Among Educators Leading WordCamp US 2026 Beginner Workshops (therepository.email)
→ First Student Survey Shows WordPress Credits Building Skills and Satisfaction, With Focus Now On Retention (therepository.email)
→ WordPress Credits Calls for Help Designing a Developer Track Ahead of a US College Pilot (therepository.email)
→ WordPress 7.1 Beta 4 Adds Opt-Out for Responsive Styling, Punts Inherited Styles Display (therepository.email)
From WordPress Community
→ WordCamps Are Great, But They’re Not Enough (youtube.com)
→ Why WordPress 7.1 Will Improve Your Workflow (thewpminute.com)
→ Jonathan Jernigan Finally Decided It’s Time to Leave WordPress (youtube.com)
→ Interview with Birgit Pauli-Haack, Anne McCarthy and Nathan Wrigley (wpbuilds.com) – Inside WordPress 7.1: responsive styling, new blocks, media modal, and behind-the-scenes changes.
→ Gogh Is Getting a Lot of Excitement. Should We Build It? (pootlepress.com)
→ Lana Miro: An Unexpected Conversation With a Woman Who Manages to Smile and Laugh in the Middle of a War (seriouslybud.com)
→ Join WP More Sub Reddit, start a WordPress discussion! (reddit.com)*
*brought to you by WP More.
Until Next Week
Issue 50, can you believe it? Thanks for being part of this community and for reading along. If any of this week’s stories sparked a thought, hit reply and share it. And if you know another WordPresser who’d enjoy this, pass it on.
Nishat, WP More
Follow → X.com | LinkedIn | BlueSky | Facebook
Join Our Community → Sub-Reddit | X Community

Leave a Reply