For context for those outside the US, this is a play on a common saying "Guns don't kill people. People kill people."
It's commonly used in relation to the 2nd amendment which gives citizens the right to bear arms. It comes up when there are political debates relating to gun violence.
It's a statement of responsibility. Whether it's the government, gun makers', or citizens' responsibility to ensure responsible gun use.
I think a large % of Wordpress usage is for simple websites that are better served by tools simpler than Wordpress. I'm not sure if you've tried to use Wordpress for a simple site. I did recently and it was a horrendous experience.
Ironically, the antiquated model of a bunch of source code and a database sitting on a computer is something coding agents really like.
WordPress and a nice page builder with MCP is actually a joy to use, and the absolutely enormous catalog of plugins that are easily extensible and endlessly modifiable makes it so easy to work with when building via agent.
Having worked with WordPress for over a decade, I find it hilarious that WooCommerce (the bane of my existence that has inexplicably paid my rent for a gigantic chunk of my adult life) is easier to use and better positioned for building with AI than Shopify.
The future is actually pretty bright for WordPress I think.
The absolutely enormous catalogue is an absolute security (and often maintenance) disaster in 2026.
Those who have ever delivered actual WP sites know the pain of it. Typical WP setups grow very fast growing towards completely entangled mess of plugins and template hacks as the project matures.
I have worked professionally in the WordPress space for over a decade, running teams that make plugins used on probably close to a million sites, I’m a (former?) regional WordCamp organizer, and I’ve built and deployed sites on WordPress for clients, our products, and personal projects ranging in complexity from single page brochure sites to ecommerce/hybrid SaaS monstrosities.
The security issues with WordPress aren’t fake, but they are not nearly as bad as the reputation is. The main reason WordPress gets a bad rap is companies like Patchstack have a financial incentive to abuse CVEs and scare people into buying their products.
For example, we have had numerous CVEs from them stating that they found an RCE in our plugins (!). Oh no! CVE filed. Reproduction steps:
1. Log in as a site admin with full access to the database and file system of the site.
2. Scroll past an input field in our plugin where you can type in arbitrary PHP and have it executed.
3. Do some magical incantation to fire some useless hook.
——
Hello Toyota, I found a security problem- the center console inside the car can be opened by unauthorized users. As some vehicle owners may place valuables there, it exposes them to the possibility of theft.
Steps to reproduce:
1. Unlock the car door and enter the vehicle using your key.
2. Open the center console.
Proposed security fix: Require the vehicle’s key, an RSA fob, and iris scan to open the center console. You have 15 days to recall all vehicles in your fleet that have an unsecured center console. Here are several blog posts that will be going live after the deadline:
• All Toyota Cars Insecure And Anything You Put Inside Can Be Stolen By Anyone Unless You Give Us $50/mo
• Toyota Car Alternatives Because of Vulnerability
• How To Secure Toyota Cars
• Safe Toyota Cars Near Me
• Toyota Car Discount Code Security
——
Their whole business model is to file CVEs, get to them to rank on Google, and then blast out press releases scaring people into paying for their garbage plugin.
There have been real issues, like the Bricks thing, where actual sites did get hacked. But this is a fact of life, if you expose your server/data to the internet at some point it very well may get compromised. I’m sure a few people had a bad day, but if you have a WordPress site and care about security literally all you need to do is put it on a half decent host and they will use a WAF and won’t have to worry about anything.
There are plenty of household names running WordPress at scale like Rolling Stone, Time, the White House, Techcrunch, etc. They aren’t doing much different from what a $5/mo blog on GoDaddy gets in terms of security, and they certainly aren’t running Patchstack (I really hope someone doesn't sniff their sites or tell me they are providing a WAF for them etc and prove me wrong lol).
I’m the CEO of Patchstack. We don’t accept vulnerabilities in our program that require admin privileges (even though there have been real cases where such vulnerabilities cause serious damage to multisite networks). The plugin vulnerability issues in WordPress have become significantly worse, as low severity issues are now chained together that become a severe issue. On top of that, these vulnerabilities are being exploited faster than ever before. WordPress now also has an issue with supply chain attacks - which has started to happen quite a lot more compared to past years.
“Their whole business model is to sign CVEs” - please don’t make up random stuff. We were invited to the CVE program and therefore have an obligation to assign CVEs.
“Get to rank them on Google” - what?
Also, we don’t send press releases about vulnerabilities. There are cases where publications reach out to us and ask for comments when there are severe issues disclosed - but that’s very much different from the picture you’re trying to paint here.
Also, your “get a half decent host with a WAF” argument shows how disconnected you’re from the reality. There are web hosts that say they offer secure hosting when promoting free SSL. We’ve tested the web hosts with independent reviewers and what you’re claiming is a widespread myth that has been debunked: https://patchstack.com/articles/myth-of-secure-hosting-only-...
> I'm not sure if you've tried to use Wordpress for a simple site. I did recently and it was a horrendous experience.
As someone who made a number of bespoke backends, WordPress wins on turnkey host-support, ease of content-authorship, familiarity (when handing over or taking over a backend), and breadth and depth of plugins. A lot of people would be well-served by static-site generators, and those were on the rise for a bit. WordPress stays winning because of the user-friendliness of its publishing workflows (vs SSGs), and self-reinforcing ecosystem.
I hear the words you're saying. But this was not the case for myself setting up Wordpress and trying to help a non-technical user navigate the admin dashboard to manage their content.
I haven't used Astra or Fable much. It's because Opus 4.8 is doing everything I need and I feel confident in using it. Why fix what's not broken? The model isn't the limiting factor for me right now.
I just wrote about my process [1] and I fully agree that the more tied you are to existing approaches to software engineering the more trouble you will have.
I just came here to say that I tried setting Wordpress up for someone a couple weeks ago and the entire admin experience felt like someone designed it WHILE AT burning man.
There is a simple version of this idea that really resonates with me.
For about a decade, I've been using flat files on disk or object storage for most of my side projects. There's even a python library that handles some of the plumbing for you [1].
If you don't have strong record-level concurrency needs then it's a lot nicer, easier, cheaper than a relational or document database. And if you do need that, you can design your data model around what defines a record.
A lot more people have taste than have previously been able to materialize it.
With AI, I created printable artifacts for a booth of a nonprofit I advise. We don't have a "creative" on the team but I'm fluent with all of Claude's tools and I feel I have good taste. I am not what you'd typically call a "creative" though - because I lacked certain skills that are less important now.
In about 30 minutes, I had a PDF I could upload to FedEx Kinkos to print. It looked very professional. Partly because it was based off the website that Claude also helped me design.
In the same way that AI enables me to bypass creatives, it lets creatives by bypass someone like me.
If most people’s “latent” taste was as good as they thought it was, we wouldn’t have so much “AI slop” - AI generations that are so-labeled precisely because the act of publishing them demonstrates significantly below-average taste.
IME, most users of the term “AI slop” use it for all (identified) uses of AI because they believe that use of AI is itself inherently an indication of poor taste and low effort that invalidates the work independently of what quality the work would have viewed independently of the mode of creation.
There are definitely people who accept AI use generally who try to make “AI slop” a distinction within the universe of AI creation rather than a label for the entire universe of AI creation, but that seems to be a minority use of the term.
I'm not sure "most" people have taste (assuming taste isn't subjective).
I don't think AI slop is indicative of taste. A lot of work doesn't care about taste at all. And AI slop is problematic in that it churns out an awful lot of output that people don't really care to review.
I’d frame taste as a combination of both. People mindfully interacting with a domain will develop nuanced aesthetic preference within it, and while preference is subjective, there’s still plenty that can be agreed upon or respected. Much like morality and relativism.
Obliviousness and uncaring will have similar failure modes, all the more so if both lead to rubber-stamping AI outputs to vague prompts.
I trust Meta far more than, say, Anthropic. For one, the judgments against them from the government just mean that they have tons of oversight and auditing happening now. The other providers are just the wild west with privacy.
Really? There's so much information about how Meta targeted children with addictive design patterns. They paid the fine, and profited in the meantime. Do you really think they have any reason not to do the same in the future?
They will use it for nefarious but "legal" purposes - however - they have decades of experience handling such data and keeping it "safe" from "illegal" purposes.
Remember that time they were spying on all of their "free" VPN traffic through some elaborate scheme? Onavo, for anyone interested. This was only like 2 years ago.
Remember when their Android app would open a local TCP port, and they would have websites connect to localhost:PORT so they could deanonymize you? That was only like 1 year ago.
Do you mean in terms of competence at resisting breaches? I trust Meta’s security team a lot more than anyone else’s in that respect.
They are big enough and pay well to have a competent team. Compared with momandpop.com (willing but too small) or equifax (big but unwilling) and given the kind of data they are guarding, they’re probably the best in the business.
It's commonly used in relation to the 2nd amendment which gives citizens the right to bear arms. It comes up when there are political debates relating to gun violence.
It's a statement of responsibility. Whether it's the government, gun makers', or citizens' responsibility to ensure responsible gun use.
reply