Ask David! Question
Is WordPress clunky and prone to security issues because it is built on PHP?
There is a popular argument in web development: “PHP is a terrible language. Just look at how insecure WordPress is.”
That argument doesn’t make much sense.
WordPress is built with PHP, but that doesn’t mean PHP is responsible for WordPress’s security problems. Modern PHP is a mature programming language with strong typing features, improved error handling, modern syntax, and significant performance improvements over the years.
PHP isn’t the problem. The way software is built around it is a much bigger part of the story.
That distinction is important because you can build secure, fast, sophisticated websites with PHP. You can also build a complicated website with a large collection of separately maintained software and create a much larger security and maintenance burden.
That’s where WordPress comes in.
PHP Isn’t What Makes WordPress Complicated
Consider what actually happens on a typical WordPress website.
The WordPress installation provides the basic platform. Then the site owner adds a theme. Then a plugin for forms. Another for SEO. Another for e-commerce. Another for memberships. Another for backups. Another for caching. Another for security. And so on.
Those pieces can come from different developers, different companies, and different development philosophies.
Each one is another piece of software that has to be maintained.
That isn’t a PHP problem.
It is a software architecture and maintenance problem.
What About WordPress Performance and Bloat?
The same issue can affect performance.
PHP itself isn’t what makes a website slow. A PHP website can be extremely fast when the code is well designed and the server is properly configured.
The problem is what happens when you keep adding layers of software to a website.
Every plugin can add code, database queries, scripts, styles, or other processing. Some plugins are lightweight. Others can add considerably more overhead. When a website has a large collection of plugins, themes, page-builder components, and other additions, there is simply more code for the server and browser to process.
That can contribute to bloat and slower page loads.
And then another plugin gets added to try to fix the performance problem.
You can end up with caching plugins, image optimization plugins, database optimization plugins, script optimization plugins, and other tools layered on top of the software that created the need for them in the first place.
Again, that’s not a PHP problem.
It’s what happens when a website grows by continually adding more software to the stack.
For more on website-builder bloat and performance, see What are the Most Bloated and Sluggish Website Builders of Today?.
Why WordPress Has Such a Large Security Target
WordPress is enormous. W3Techs currently reports that WordPress is used by about 40.1% of all websites and has a 58.6% share among websites where the CMS can be identified.
That makes WordPress an extremely attractive target.
A vulnerability in a widely used WordPress plugin doesn’t have to be exploited one website at a time. Attackers can look for websites running the vulnerable software and automate much of the process.
And WordPress itself acknowledges that security issues can occur not only in WordPress core, but also in plugins, themes, and the wider WordPress ecosystem.
This is one reason the plugin model creates a security and maintenance problem.
If your website depends on 20 separately developed plugins, you don’t just have one piece of software to keep updated and secure. You have 20.
And those plugins can interact with one another.
An update to one can change how it works with another. A developer can stop maintaining a plugin. A plugin can introduce a vulnerability. A new version can create a conflict with your theme or another plugin.
None of that happens because PHP is an insecure language.
It happens because the website has become a collection of independently developed components.
We go into more detail, with examples, in: Why Relying on WordPress Plugins Can Backfire (And How to Avoid It)
The WordPress Plugin Trap
Plugins are one of the reasons WordPress can be used to build almost anything.
They are also one of the reasons maintaining a WordPress website can become such a chore.
Need a particular feature?
Find a plugin.
Need another feature?
Find another plugin.
Need to fix something the first plugin doesn’t do?
Find another plugin.
Eventually, the website can become dependent on a collection of software that wasn’t designed as one complete system.
That’s the part that gets missed when people blame PHP.
The programming language isn’t forcing you to build a website this way.
The WordPress model is.
Tired of high-maintenance website builders? Read: How to Find a Website Builder with Low Maintenance Requirements
Why We Built UltimateWB Differently
UltimateWB is also built with PHP.
We chose PHP because it is an excellent language for building dynamic websites, and it gives developers the flexibility to build everything from simple websites to complex applications.
But we didn’t want users to have to assemble their websites from a collection of unrelated third-party plugins.
That’s why UltimateWB includes the major website-building tools directly in the platform.
E-commerce.
Memberships.
Forms and surveys.
Forums.
Classifieds and listings.
Articles.
Mailing lists.
Rewards and points.
SEO tools.
Navigation and CMS tools.
Styles Manager.
And many other built-in features.
The point isn’t simply that UltimateWB has a long feature list.
The point is that these features are part of the same website builder.
You don’t have to build your website by finding a separate plugin for every basic capability.
UltimateWB Was Built for Performance
There is a reason we put so much emphasis on clean code and clean architecture. A CMS affects much more than how easy it is to manage content. Its architecture affects how much code is generated, what scripts and styles are loaded, how database queries are handled, and how much unnecessary processing happens behind the scenes.
UltimateWB was built with those things in mind. Features are integrated into the platform, code output is kept clean, and functionality can be loaded where it is needed rather than adding unnecessary overhead everywhere. The result is a powerful dynamic CMS designed to stay clean and efficient as a website grows, rather than requiring a constant battle against accumulated bloat.
The UltimateWB website itself is built with UltimateWB and has no errors or warnings in the W3C Validator. We take clean, valid code seriously because it isn’t just about making the code look nice. It affects performance, compatibility, accessibility, SEO, and how maintainable the website is.
For more on the technical factors behind fast-loading websites, see What Is the Best Content Management System (CMS) for Fast Loading Websites?. For more on clean, valid code, see Valid HTML Isn’t OCD. It’s Smart SEO, Accessibility, and Professionalism..
Built In Doesn’t Mean Locked Down
UltimateWB gives you built-in tools without locking you into a fixed website design or limiting what you can customize.
You can customize your website without coding, but developers can also work directly with the HTML, CSS, JavaScript, PHP, and MySQL.
That gives you both sides of the equation:
Easy when you want it to be easy. Flexible when you need more control.
You’re not limited to whatever options happen to be provided in a particular visual website builder. And you don’t have to install a plugin just because you want to add or customize a feature.
So, Is PHP the Problem?
No.
If you’re looking at WordPress security problems and concluding that PHP must be the problem, you’re looking in the wrong place.
PHP can be used to build secure and powerful web applications.
The bigger question is how the software is designed and how many separate pieces you have to depend on to keep your website working and secure.
WordPress’s enormous plugin and theme ecosystem gives it tremendous flexibility, but it also creates a large maintenance and security surface.
UltimateWB takes a different approach.
Instead of starting with a basic CMS and assembling the rest of your website from third-party plugins, UltimateWB gives you a complete website builder with its major features built in.
Don’t blame PHP for WordPress’s problems. Look at the architecture.
And if you want the power and flexibility of PHP without building your website around a pile of plugins, go straight to UltimateWB.
Related Ask David! Posts:
Thinking About Switching From WordPress? What Should You Consider Before You Move?
“My Partner Wants to Use WordPress Because 50% of the Web Uses It. Help!”
Ready to design and build your website? Learn more about UltimateWB! We also offer web design packages if you would like your website designed and built for you.
Got a techy/website question? Whether it’s about UltimateWB or another website builder, web hosting, or other aspects of websites, just send in your question in the “Ask David!” form. We will email you when the answer is posted on the UltimateWB “Ask David!” section.
