WordPress is Bloatware and Bloated Software Guarantees Security Incidents

3 years ago (in September) we dumped WordPress - something we had planned since a decade earlier. It made sense, but it was a huge task (we had about 40,000 blog posts in WordPress).
Earlier today Russell Coker (Debian) said that he had been cracked and he's not even sure how exactly it happened or the scope of the breach. He says he chooses to "believe that they did not compromise the OS," but that is based on something that's partly speculative. He said the attacker likely "ran hostile SQL code to change fields in the MySQL database so had to consider the possibility that the account creation time could have been set to a deliberately misleading value" (in WordPress; it allows people to create accounts and add stuff to the database, even modify it in some ways).
He then said: "I checked backups of the MySQL database stored off-site and found that the account in question was not in the 2026-07-21 backup (which was done before 16:43) but in the 2026-07-22 backup."
So it was very likely done via WordPress.
This site turns 20 in about 11 or 12 weeks from now and it was never cracked, not even when it ran WordPress.
Moving from Content Management Systems (CMSs) to any kind of Static Site Generator (SSG) greatly enhances security. Coker now worries about the integrity of his entire system; that's the price of using WordPress. █
