The "surprisingly secure" WordPress just had a unauthenticated RCE earlier this year. Just simplifying isn't going to be enough.
https://nvd.nist.gov/vuln/detail/cve-2026-63030
If that's your benchmark for being unsecure, then React is unsecure too.
https://react.dev/blog/2025/12/03/critical-security-vulnerab...
"First step"
Nobody said it's enough, but it's a start.
Plus, how secure are the plugins?
If that's your benchmark for being unsecure, then React is unsecure too.
https://react.dev/blog/2025/12/03/critical-security-vulnerab...