Websites in the AI Era, Part 3: AI Is Reshaping WordPress Development Faster Than You Think

Custom Code, Plugin Risk, and the Security Arms Race

Part 3 of 4 — Iceberg’s “Websites in the AI Era” Series

This is Part 3 of Iceberg’s four-part “Websites in the AI Era” series. Parts 1 and 2 covered how AI is changing website discovery and why human brand personality matters more than ever. This one gets into something closer to the engine room: how AI is changing the way WordPress websites are actually built, maintained, and secured.

For business owners, these predictions matter because they affect what your website is running on, how vulnerable it is, and what your agency relationship might look like. Two contributors shape this article: Iceberg Web Design’s founder, Jessi Gurr, who has been using AI coding tools directly for Iceberg, and Iceberg’s Web Developer, Ega, whose predictions focus on the security implications of increasingly capable AI models.

Penguin interacting with a futuristic computer, projecting its screen

Jessi: AI Is Making Custom Plugins More Practical Than Paid Ones

With tools like Claude Code and Codex becoming more popular, we’re already seeing how easy it is to write a quick plugin that replaces, or expands on, popular paid plugins in the WordPress space. A real example: At Iceberg, we recently replaced an internal function that used to depend on Zapier with a very small Claude-coded plugin.

Demand will push agencies in the direction of providing these vibe-coded solutions for customers… and agencies that don’t rapidly embrace new AI technology will quickly fall behind.

A quick note on terminology: a plugin is a piece of add-on software you install on a WordPress website to give it new capabilities. These are things like a contact form, an online store, or an appointment booking system. Traditionally, most website owners relied on off-the-shelf plugins built by third-party companies, often with a monthly subscription fee.

What Jessi is describing is a shift away from that model. Tools like Claude Code and Codex are AI systems that help developers write code quickly and accurately. They’ve made it practical for agencies to build small, custom-made plugins tailored to exactly what a client needs. This removes subscription costs, unnecessary features, and third-party dependency.

The Zapier example from Iceberg’s own work is a useful illustration. Zapier is a popular automation tool that connects different software systems together. It works well, but it comes with ongoing subscription costs and sends your data through their servers. A small AI-coded plugin that handles the same specific task costs development time once, saves money monthly, and keeps everything on your own website.

What this means for your business: Ask your website developer or agency whether AI-assisted custom development is part of their toolkit. Agencies using these tools are delivering more precise, more secure, and often more cost-effective solutions than those still defaulting to plugin stacks — and the gap is growing.

Penguins working on computers with security icons floating around them

Ega: AI-Generated Exploits Are Already Here

Anthropic new model, Mythos can find and exploit zero-day vulnerabilities for under $50 each run. Most of WordPress vulnerabilities live in plugins.

Engineers at Anthropic with no formal security training have asked Mythos Preview to find remote code execution vulnerabilities overnight, and woken up the following morning to a complete, working exploit.

Shocking facts takeaway: people without security training, an overnight prompt, and a complete exploit delivered by morning.

Mythos Preview is being released first to ‘critical industry partners and open‑source developers’ as part of Anthropic’s Project Glasswing program. That’s good to know, but it doesn’t guarantee others will show the same restraint. It simply means Mythos Preview isn’t the model that will reach your site first.

Before we unpack this, a few terms worth knowing. A “zero-day vulnerability” is a security flaw in software that hasn’t been publicly discovered or fixed yet, meaning there’s no patch available because the software maker doesn’t even know the problem exists. “Remote code execution” means an attacker can run their own harmful code on your website’s server, giving them effectively full control.

What Ega is describing is a genuine shift in the threat landscape. The barrier to finding and exploiting these vulnerabilities has historically required significant technical skill, time, and resources. The Claude Mythos Preview model changes that equation: under $50 per run, no security background required, a working exploit delivered by morning.

The responsible disclosure program gives some comfort, but Ega’s point is sharp. This capability being controlled by one company is not the same as this capability being controlled. Other models, less responsibly deployed, are in development or already in the hands of bad actors.

What this means for your business: The risk calculus for WordPress security just changed. If the tools to find and exploit vulnerabilities are this accessible, the old timeline for fixing things, “we’ll get to it next week,” is no longer a safe assumption.

Ega: Shorter Patch Cycles Are the New Normal

Anthropic’s own advice to partners was: “shorten patch cycles” and “expedite vulnerability mitigation”. For wordpress, it means auto updates on for every plugin you trust and can safely roll back. Staging site for the plugins where auto-update is too risky, usually ecommerce, membership and lms. Active monitoring of patchstack, wpscan and wordpress.org advisories. 24 hours is the new target, the new normal.

More terminology worth knowing: a “patch” is a software update that fixes a security flaw. A “staging site” is a private, hidden duplicate of your website used for testing updates safely before they go live on your real site, like a rehearsal before the performance.

Ega’s practical advice is specific and actionable. The 24-hour patch window is ambitious for most WordPress sites operating without active management, but it’s the right target in an environment where AI tools can find and weaponize vulnerabilities faster than a weekly site check catches them. Services like Patchstack, WPScan, and wordpress.org advisories publish security warnings the moment a vulnerability is discovered. Knowing about a problem the same day it’s disclosed and not two weeks later is the difference between patching and getting hit.

What this means for your business: If your WordPress site doesn’t have a managed maintenance plan that includes active monitoring and fast patching, this is the year to put one in place. Unmanaged sites with outdated plugins are the easiest targets in this new environment.

Ega: The Great Plugin Purge

Expect plugin footprints to shrink dramatically. Not by preference, but by necessity. If 96% of WordPress vulnerabilities live in plugins, then deleting even one is a real reduction in exposure.

That 96% figure comes directly from the State of WordPress Security 2025, and it reframes how agencies and site owners should think about plugins entirely. Every plugin installed on your WordPress site is a potential entry point for an attacker. The fewer you have, the smaller your risk. It’s that simple.

This connects directly to Jessi’s prediction at the top of this article: as AI-assisted custom development makes it cheaper and faster to build purpose-specific functionality, the case for large plugin stacks gets weaker. Why maintain 40 plugins when 15 custom-built functions do the same job with a fraction of the exposure?

What this means for your business: Ask your developer to audit your current plugin list. Anything inactive should be deleted — not just turned off. Anything that hasn’t been updated in over a year is a liability. And anything that can be replaced with a lighter custom solution is worth a conversation.

The Throughline in Part 3

These four predictions reinforce each other. AI is making custom WordPress website development more accessible, which reduces the need for large plugin stacks. At the same time, AI is making those plugin stacks more dangerous than ever to maintain. The agencies and site owners who see both sides of this will be running leaner, safer, more resilient WordPress websites as this shift continues.

Coming Up in Part 4: The Final Post in the Websites in the AI Era Series

Part 3 introduced the threat. Part 4 gets into the defense. Ega walks through four specific security practices that are shifting from “good idea” to non-negotiable, including why the password-only login is effectively dead, and what monitoring actually needs to look like now.

Is Your WordPress Site Ready for What’s Coming?

The Iceberg team handles Hosting & Maintenance, security reviews, and WordPress website development. If you’re not sure what’s running under the hood of your site or how many plugins you actually need, we can help you find out! Give us a call at 763-350-8762 – we are Website Developers Who Answer the Phone!®

Related Posts

Are you ready for Business Growth?

Our responsive team will help your website convert more leads.
Contact us today!

This field is for validation purposes and should be left unchanged.
Name(Required)
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form