Real talk. It's easy to bitch and moan about the number of WordPress security releases we've seen over the past few months.
I get it. Updating and checking sites takes time, especially when you're responsible for dozens (100s?) of them.
But those releases also mean people are finding vulnerabilities, reporting them, and doing the work to fix them. Researchers and maintainers are taking responsibility for software that millions of people depend on.
That's a sign of a healthy community. It doesn't make the vulnerabilities any less serious, or put WordPress above criticism. It does give us a response we can examine and fixes we can apply.
And “I'll just build it with AI” doesn't get you out of any of this. Neither does switching CMSs or writing everything yourself. Whatever you build still needs security review and ongoing maintenance.
A working website can still be a vulnerable website. Fewer public security reports don't automatically mean fewer security problems.
Personally, I want people looking for flaws in the software I use, and people committed to fixing what they find. I'm glad WordPress has that community.
If you're building your own alternative, who's doing that work six months after launch?