WordPress is not as decentralised as many people assume
WordPress has powered a huge share of the web for years. It is familiar, widely supported and, for many small businesses, it still does the job well.
But the events of the past year exposed something many website owners had probably never thought about before. WordPress is open source in licensing terms, but some of the infrastructure millions of websites depend on is controlled by a much smaller group of people than many assume.
That matters because most businesses do not think about where plugin updates come from. They install WordPress, add plugins, enable updates and trust that the ecosystem will keep quietly working in the background. The recent dispute showed that things are not quite that simple.
What actually happened
In late 2024, WP Engine, one of the largest managed WordPress hosting providers, became involved in a public dispute with Matt Mullenweg, co-founder of WordPress and CEO of Automattic.
That might sound like internal industry drama, but it had practical consequences. WordPress sites rely on central update systems to install and update plugins, including security patches. During the dispute, WP Engine was blocked from parts of that system, which meant it could not reliably deliver plugin updates to the sites it hosted.
That is where the story becomes relevant to ordinary website owners. Plugin updates are not just feature improvements. They often include security fixes. If those updates are disrupted, websites can become more vulnerable.
The issue escalated into legal action, and a US court later ordered that certain access be restored while the case continued. But the wider concern had already been exposed: a disagreement at the top of the ecosystem could affect the update process that real websites rely on.
The Advanced Custom Fields issue made it worse
One of the most controversial moments involved Advanced Custom Fields, a hugely popular plugin used on millions of WordPress sites. Its listing in the official plugin directory was changed, and users were served a modified replacement version under a near-identical name.
That replacement inherited the original plugin’s reviews, reputation and search visibility, which meant many everyday users would not have immediately realised anything had changed.
Developers reacted strongly because the concern was bigger than one plugin. If a widely used plugin can be replaced inside the official directory without broad consensus, then the directory is not just a neutral distribution channel. It is a point of control.
For a platform built heavily on trust and community contribution, that was a damaging moment.
Why website owners should care
Most businesses do not want to think about WordPress governance. They want their website to work, their plugins to update and their security patches to arrive without drama.
The past year showed how much of that reliability depends on decisions made by a small number of people. If access to update systems can be restricted during a dispute, that creates risk. If plugin listings can be changed in ways ordinary users may not notice, that affects trust. If public conflict slows contribution or creates uncertainty, the platform’s momentum can suffer.
None of this means WordPress is suddenly unusable. Millions of websites continue to run on it every day. The point is more practical than that. If your business depends on WordPress, you should understand that it is not just a piece of software sitting independently on your server. It is part of a wider ecosystem with governance, infrastructure, commercial interests and human decision-making behind it.
The architecture is also showing its age
WordPress began as a blogging platform and grew into a full CMS through themes, plugins and years of backwards compatibility. That history is part of its strength, but it is also part of the problem.
A traditional WordPress site is usually one tightly connected system. The CMS, templates, plugins and front-end rendering all sit together inside the same application. That can be convenient, especially when a plugin solves a problem quickly, but it also means complexity tends to build up in one place.
Over time, this is how many WordPress sites become difficult to manage. More plugins are added, templates get adapted around short-term requirements, performance becomes harder to protect and every change starts feeling heavier than it should.
Modern web development has been moving in a different direction. Front-end frameworks, APIs, structured content and headless CMS platforms are built around clearer separation between systems. Content can live in one place, the front-end can be built separately, and integrations can be handled more deliberately.
Headless WordPress can be one route, but it is not always a clean escape. Once WordPress is separated from the front-end, many of the plugins that made it attractive become less useful because they assume WordPress is still controlling the full page. At that point, businesses can end up carrying WordPress complexity while also taking on the responsibility of a custom front-end.
WordPress is under pressure from a different kind of web
The timing of all this matters because the wider web is changing quickly. AI is influencing how content is created, how people search and how businesses expect digital systems to connect with each other. Content platforms are being asked to support more structured data, more automation and more flexible delivery across different interfaces.
WordPress has started responding to AI largely through plugins. Some of those tools are useful, but they still sit on top of the existing system, with the same architectural assumptions underneath.
That is the bigger issue. WordPress can keep adding features through plugins, but deeper change is harder because the platform has to preserve compatibility with a vast ecosystem. That cautious approach has helped WordPress remain dominant, but it also makes it harder to move quickly when the web changes.
Meanwhile, newer platforms are starting from a different place. They are not trying to modernise WordPress. They are rethinking what a CMS should be when AI, structured content, edge infrastructure and automated workflows are part of the foundation from the beginning.
Cloudflare’s work on EmDash is a good example of that direction. The aim is not simply to recreate WordPress with a newer interface, but to explore what a modern content platform could look like if hosting, content management, AI tooling and security were designed together rather than assembled through a plugin-heavy model.
That should make WordPress uncomfortable. Not because it is about to disappear, but because the next generation of CMS platforms is no longer just competing on editing screens. They are competing on architecture, security, automation and how well they fit into a more AI-driven web.
The bigger question is predictability
None of this means WordPress is collapsing. It still powers a huge number of websites, and many of those sites will continue running perfectly well for years. If you already have a well-maintained WordPress site that supports your business effectively, there is no reason to panic.
The better question is whether WordPress is still the strongest default choice for a new business website. That used to feel obvious. For many organisations, it no longer does.
The past year showed that some of the systems WordPress sites depend on are more centralised than many people realised. It showed that leadership decisions can affect operational infrastructure. It also landed at a moment when the rest of the CMS market is moving quickly toward more flexible, API-driven and AI-ready architecture.
WordPress still works. For some businesses, it will still be the right choice. But it is no longer the obvious go-to it once was, and website owners should feel comfortable asking whether a platform built around old assumptions is the right foundation for what comes next.
Founder and Technical Director
I’m Amy Evans, a front-end engineer with 20 years’ experience building websites for agencies, startups and global brands. I write about coding, tech, AI and the messy bits of delivery that rarely make it into case studies. Away from my screen, I’m usually behind a camera, collaborating with other creatives, or planning my next trip.





What is a headless website? A practical guide for teams who’ve outgrown their CMS.