I do understand it from an user perspective (it's easier to tell the average user to drag and drop rather than committing to a GitHub repo and letting hugo build the website), but from a security standpoint WordPress is really just waiting for a vulnerability (either in the core or on the thousands of plugins) in order to unlock its RCE-as-a-service functionality.
And people like to be able to extend from Blogs to various other non static features which WordPress allows for.
- Less training; org probably has someone who’s used Wordpress before. (Yes, training. You must deal with the reality of the typical user.)
- In the developing group or agency, anyone can work on the theme if you install a theme builder. An agency can put a cheaper content marketer or designer on it, rather than a developer.
Surely someone once offered a vulnerability for 500k somewhere, but that doesn't mean someone bought it.
WordPress is one of the most hardened targets of all time
that obsolete code did not change for decades. all the bugs have been discovered and patchedWill be publishing a report on www.theweb.report soon - if you're interested.
That's a seed of about 13 million domains - pretty sure WordPress would be dominating the even longer tail.
( Also worth noting it's sooo easy to detect a site is WordPress, it screams it across every signal we gather, where-as some sites are just well made and have limited information leaks ).