WordPress Will Take a More Proactive Approach to Addressing Security Vulnerabilities
Lately, it’s been all over the news and our blog: security updates for both the WordPress core itself and for popular themes and plugins.
We’re seeing this among our customers as well: The number of WordPress (and Joomla) websites that are being compromised by attackers because they weren’t updated in time is on the rise.
To tackle this problem at its root, the WordPress security team has announced the “Core Security Initiative.” One reason for the rise in reports is that, thanks to advanced AI models, it has become easier than ever for security researchers (and, unfortunately, hackers as well) to scan code for potential security vulnerabilities. Let’s take a look at how WordPress plans to proactively address this issue to fix security holes and vulnerabilities more quickly.
An Improved Release Process
To respond more quickly and predictably to discovered security issues, the WordPress developers are overhauling the entire release process. They are currently working on a more streamlined and highly automated process for security updates.
Thanks to improved end-to-end testing, the team can deploy security patches more reliably and at regular, scheduled intervals. This gives you, as a website owner, a better idea of when to expect an update, and the automatic update process runs much more smoothly.
Above all, be sure to enable automatic updates for all possible components within WordPress so that you don’t have to take any manual action. In practice, this is often put off when it has to be done manually.
With automatic updates, there is a small risk that, for example, an error message might appear on your website. However, in our experience, this risk is lower than the risk of security vulnerabilities.
Clearing the Backlog
Due to the enormous increase in reports of potential security vulnerabilities, the core developers have accumulated a significant backlog. WordPress is now allocating additional resources to address this.
Together with sponsored contributors from the WordPress community and new volunteers, all open reports and known security vulnerabilities are being systematically reviewed and validated. The goal is clear: to reduce the list of open security issues to zero as quickly as possible. After all, it’s only a matter of time before an attacker, working with AI, discovers them as well.
Using AI Itself to Detect Potential Vulnerabilities
Artificial intelligence is a powerful tool for hackers to uncover vulnerabilities in code, but WordPress is turning the tables. Instead of simply waiting for external researchers (or attackers) to report a vulnerability through responsible disclosure, the security team now employs AI-driven scans and tools itself.
By continuously scanning the WordPress source code with AI, potential vulnerabilities can be identified and fixed before they can be exploited in the real world.
Steps for Your Own WordPress Website
It’s a positive development that the WordPress ecosystem is arming itself even more effectively against modern threats. However, the most important security rule still lies with the website administrator: Update regularly!
The Core Security Initiative ensures that patches for the WordPress core are developed faster and more securely, but you are personally responsible for applying updates to your themes, plugins, and the core.
Our tips for keeping your website secure:
Enable automatic updates: Make sure that security updates (minor releases) for WordPress and your plugins are installed automatically.
Clean up: Remove inactive themes and plugins. These can still serve as a gateway for hackers. Also, check to make sure all files have actually been deleted.
Create regular backups: This way, you can quickly restore a secure version of your website at any time if problems arise.
Do you need help backing up or updating your WordPress website on our hosting platform? Feel free to contact our help desk via chat or by submitting a ticket!
Source: https://make.wordpress.org/security/2026/08/28/the-core-security-initiative/
