Ask most web design companies to build you a five-page site for your plumbing business, your salon, or your law office, and there's a good chance you'll get a WordPress site back, whether or not that's actually the right tool. Not because WordPress is secretly the best option for a small local business. Because it's the option the agency already knows, already has a workflow for, and can hand off to a junior developer without much training.

That's a real reason. It's just not your reason. It's easier for the agency, not necessarily better for the business paying for the site.

WordPress now powers 40.7% of all websites worldwide, and 58.9% of all sites built on a known content management system.

Source: W3Techs, Usage Statistics of WordPress

That scale is exactly why this is worth a closer look. WordPress isn't a bad piece of software. It's a genuinely impressive open-source project that's earned its dominance. But dominance and default aren't the same thing, and a platform built to be endlessly extensible for every possible use case carries real costs for the one use case most local businesses actually have: a handful of pages that need to load fast, stay secure, and rarely change.

What WordPress Actually Gets Right

Fair is fair, and a post arguing against defaulting to WordPress should say plainly where it earns its reputation:

None of that is in dispute. The problem isn't WordPress as a platform, it's WordPress as a default reflex for a job it wasn't the best fit for in the first place.

The Plugin Problem

A stock WordPress install does very little on its own. Almost everything a business actually needs, a contact form, an SEO toolkit, a page builder, image optimization, caching, security scanning, gets bolted on afterward as a plugin. A typical small business WordPress site ends up running anywhere from ten to thirty plugins just to reach basic feature parity with what a custom-coded site does natively.

Every one of those plugins is a separate piece of software, built by a separate developer or team, updated on its own schedule, and capable of breaking the site or opening a security hole independent of WordPress itself. That's not a hypothetical risk. It's the documented, primary source of WordPress security problems.

Plugin vulnerabilities accounted for 96% of all WordPress vulnerabilities disclosed in 2024. Disclosed vulnerabilities increased 68% from the year before, and 35% of them were still unpatched as of the report's publication.

Source: Wordfence, 2024 Annual WordPress Vulnerability and Threat Report

That last figure is the one worth sitting with. A plugin can have a known, published security hole for months with no fix available, while your site keeps running it because nobody's checking. Wordfence's own firewall blocked and logged over 54 billion malicious requests against WordPress sites in a single year, which gives some sense of just how constantly this attack surface is being probed.

Plugins are also the main reason WordPress sites tend to run slower than they need to, the same overhead problem covered in more detail in our post on why website speed is killing local business leads. Every active plugin adds its own scripts, stylesheets, and database calls, whether or not a given page actually needs that functionality. A site built to do everything ends up doing a lot of unnecessary work just to render a simple page.

Real Security Incidents, Not Hypotheticals

This isn't an abstract risk that only affects huge platforms or careless owners. It plays out constantly, at scale, in ways that get documented by security researchers and covered in tech press.

In July 2026, security researchers disclosed "WP2Shell," a pair of critical WordPress core vulnerabilities that, when chained together, allow full remote takeover of a vulnerable site. Over 400 million websites were running the affected versions.

Source: TechCrunch, "Hackers are exploiting recently patched WordPress bugs"

That one was a core vulnerability, not a plugin, which is rarer and worth noting on its own. Plugin-driven compromises tend to be quieter but more common, and they get used for more than just defacing a homepage.

Security researchers uncovered "StopAndProtect," a criminal operation using close to 2,000 compromised WordPress sites as infrastructure to distribute ransomware and steal data through a fake CAPTCHA prompt, affecting more than 6,000 unique IP addresses by mid-2026.

Source: Check Point Research, "Thousands of Hacked WordPress Sites, One Operation"

The owners of those nearly 2,000 sites almost certainly didn't know their business's website had been turned into a launchpad for attacking other people. That's the uncomfortable part of running a platform this widely targeted: a hacked local business site isn't always about that business at all, it's about the compute and reputation of a domain that isn't on anyone's blocklist yet.

Who Actually Maintains All of This?

WordPress core, your theme, and every plugin all need updates on an ongoing basis, and updates aren't automatically safe. A plugin update can conflict with your theme, break a page layout, or get delayed for months because nobody's specifically responsible for checking. For a business owner without a developer on retainer, "keep WordPress updated" quietly becomes "hope nothing breaks," which is a worse position than not having that maintenance burden at all.

This is the part that connects directly back to how to choose a website designer: if an agency's answer to "what happens after launch" is vague, a WordPress site with a dozen plugins is exactly the kind of asset that quietly degrades without anyone noticing until it's hacked, broken, or both.

Why "The Agency Already Knows It" Isn't a Reason for You

Here's the actual dynamic worth naming directly. Many web design companies build every client on WordPress regardless of what that client needs, because:

Every one of those is a real business reason for the agency. None of them is a reason for you. A five-page site for a local plumbing company or salon doesn't need a content management system built to run a magazine, an online store, and a membership community all at once. It needs to load fast, work on a phone, and not be one unpatched plugin away from getting hijacked. Using WordPress because it's what the builder already knows is optimizing for their convenience, not your outcome, and it's worth asking directly whether that's what you're actually getting when a "custom WordPress site" gets quoted for a simple business.

When WordPress Genuinely Is the Right Call

To be fair to the platform: if you're running a large blog with multiple writers, a content-heavy publication, an online store with real e-commerce complexity, or a site where the owner needs to independently publish new pages every week without any developer involvement, WordPress is a legitimate and often sensible choice. That's a real, common use case, and dismissing WordPress entirely would be as lazy as defaulting to it for everything.

Most local service businesses, plumbers, contractors, salons, dentists, law offices, aren't in that category. Their site's job is to state clearly what they do, where they do it, and how to get in touch, updated a handful of times a year at most. That's a different problem than the one WordPress was built to solve at scale.

How Endless Local Reach Fits

Every site I build is custom-coded from scratch, no WordPress core, no plugin stack, no page builder. That means no plugin vulnerabilities to patch, no update conflicts to monitor, and a site that only loads the code it actually needs, which is also why speed is built in rather than bolted on. It costs the same flat $999 either way, you're just not paying for a content management system your business doesn't use. See what's included on the pricing page, or view real examples on the examples page.

The Bottom Line

WordPress earned its dominance honestly, and it's the right tool for plenty of websites. But plugin vulnerabilities made up 96% of all WordPress security issues disclosed in 2024, real compromises at scale keep making the news, and most of that risk gets added to a site through plugins the business never needed in the first place. If a web design company's pitch is WordPress by default rather than WordPress because your project specifically calls for a content management system, that default is serving their workflow, not your website.

Get a site with nothing to patch

Custom-coded, no plugins, no WordPress maintenance burden. Flat $999, custom-designed for your business.

Let's Talk