COMPARE

WordPress, Drupal, Steldris.

The same website, four very different answers to one question: who is accountable for the code that runs on it?

Feature-by-feature comparison of self-managed WordPress, Fruition-hosted WordPress, Drupal, and Steldris
 WordPress self-hostedWordPress Fruition-hostedDrupalSteldris™
Who can push code to your sitePlugin authors you have never met — often anonymous, rarely accountable.The same third-party plugin supply chain, with Fruition scanning every dependency for provenance.Contrib maintainers, vetted through the community queue.One named team. Every line of code on your site is ours.
Third-party plugin / module supply chainTens of thousands of plugins of wildly varying provenance.The same plugins, scored by our provenance scanner the day they ship.A curated queue with a dedicated security team.None. Authoring, forms, documents, and accessibility are built in.
Core updatesYou schedule, test, and deploy them.Handled by our team for managed-care clients.You schedule, test, and deploy them.Handled for you, continuously.
Security patchingYour team, against a moving advisory feed.We patch the infrastructure and the stack; your plugin updates stay on your calendar.Your team, with strong upstream advisories.Continuous. Patching is part of the service, not part of your job.
Web application firewallBring your own, configure it yourself.Shield WAF in front of every site, tuned by us.Bring your own, configure it yourself.Shield WAF in front of every site, tuned by us.
AccessibilityTheme- and plugin-dependent. Retrofits are common and expensive.Theme- and plugin-dependent. The plugins are still third-party.Strong core accessibility; themes still vary.WCAG 2.2 AA at the platform level, plus PDF Accessibility for documents.
Compliance postureWhatever your hosting and configuration make of it.Audited infrastructure underneath; the CMS configuration is still yours.Whatever your hosting and configuration make of it.SOC 2 Type II, ISO 27001, HIPAA-compliant hosting available.
Maintenance windowsOn your calendar, on your weekends.Ours for the platform; yours for plugin updates.On your calendar, on your weekends.Zero. We own the infrastructure.
AI content toolingThird-party plugins of varying quality and provenance.Third-party plugins we can help you choose, but do not control.Modules and integrations you evaluate yourself.Built in. Claude-powered authoring and alt text.
Who answers when something breaksWhoever built it — if they are still around.Our team, around a codebase we did not write.Your internal team or your agency.The team that runs the platform. That is the whole model.

Self-managed WordPress and Drupal, as most organizations run them. A well-staffed platform team can close some of this gap on any CMS; moving an existing WordPress site onto Fruition infrastructure closes a different part of it, without changing CMSs.

THE FOOTPRINT

Less code. Less surface.

Every line an attacker can reach is a line that has to be patched forever. The numbers below are measured, not estimated — methodology in the footnote.

~550,000

lines of PHP in WordPress core alone (421,720 in wp-includes + 128,204 in wp-admin) — the surface an attacker studies before a single plugin is installed

~70,000

lines in the entire Steldris platform — public site, publishing application, and API combined

0

lines of PHP reachable from the internet on a Steldris site — public pages are static files

60,000+

plugins in the WordPress ecosystem, largely anonymous authorship — each one a supply-chain decision you now own

WordPress core measured on a 6.9.x install, 2026-08-10; Steldris from the platform repository. Full methodology, including source line counts, is published in our research notes.

01 — THE SHIFTING SURFACE

The target moves. Constantly.

Every WordPress release is a public diff and a change to the code your visitors execute. Twelve months, measured — with our own release cadence next to it.

WordPress core106 releases · 15 days
Six common plugins201 releases
Steldris platform187 deploys
Server code a WordPress visit executeschanged on 106 of 365 days
Server code a Steldris visit executesnone · 0 changes
Sep 16, 2025 to Sep 16, 2026. WordPress core: 106 releases across every supported branch, 4.7 through 7.0 — the tall marks are security days when every branch shipped at once. Plugins: 201 stable releases of WooCommerce, Elementor, Yoast SEO, Wordfence, Contact Form 7 and Akismet. Steldris: 187 production deploys since the current pipeline started on Jul 6, 2026. A WordPress visitor's request executes the code above on the server. A Steldris visitor's request fetches a static file; nothing runs on our side of the wire.

There is no one WordPress.

Sites update on their own schedule, so every release above stays in circulation. A site is one core version plus one version of each plugin, chosen independently and never tested together. Count only the last twelve months, only these six plugins, and only one version per core branch, and the possible combinations are still:

  1. 24core branches kept patched
  2. 106WooCommerce
  3. 48Elementor
  4. 28Yoast SEO
  5. 9Wordfence
  6. 6Contact Form 7
  7. 4Akismet

738,533,376possible WordPress version combinations

1build serves every Steldris site. 187 deploys replaced it in place — every site, at once.

How a moving target gets hit

  1. A release ships. Core, or any of 60,000+ plugins. The diff is public the moment it lands. Attackers read it for free.
  2. The diff is the map. Mass-compromise campaigns are automated diff-watchers. They read the change, find the exploitable delta, and weaponize it.
  3. Spray. Every site running that code gets the same payload. Drupalgeddon2 ran this play at platform scale: one deserialization flaw, roughly a million sites, automated scanners within hours of the first public exploit.

Why it matters more every year

WordPress core is 549,924 lines of PHP before a single plugin is installed. Each release above rewrites a slice of it, and each one hands attackers a fresh diff to read. What a defender audited last quarter is different code today.

The attacker has to win once. The defender has to win every time — against code that changes every release.

Release dates from wordpress.org and plugins.svn.wordpress.org (tag creation dates, stable versions only); Steldris deploys from the platform's CI history; all counted 2026-09-16. The combination count is exact for its assumptions and deliberately conservative: one version per supported core branch (counting all 106 core versions gives 3,261,855,744), all six plugins installed, one version of each. It ignores plugins' minimum-WordPress-version rules, which rule some pairs out, and the other 60,000 plugins, which multiply the rest. Core line counts measured on a WordPress 6.9.x install, 2026-08-10.

02 — THE NATURAL STATE

Hardened by default, not by effort.

The first requests an attacker sends, against two live sites we operate. WordPress ships with a login page, an admin panel, a REST API and a PHP runtime facing the internet: it has to be hardened against its own natural state, then re-hardened after every release above. A Steldris site's natural state is the hardened one. Nothing runs.

Public attack surface: Steldris versus a hardened, Fruition-hosted WordPress site
 WordPress Fruition-hosted & hardenedSteldris™ as shipped
Server-side runtime exposed to the internetLive PHP + MySQL behind a cache layer.None. Public pages are static files served from the edge.
Login endpoint on the public site/wp-login.php — a 1,650-line PHP file dispatching eleven auth flows, with 76 superglobal reads and 46 plugin-mutable hooks.None (403). Authentication lives on a separate app behind Auth0.
Admin panel reachableYes, /wp-admin/ on the public site.No. The admin is a separate application behind enterprise SSO.
REST API / user enumerationYes — the REST API leaks real usernames.None (403). There is no public API surface.
XML-RPC pingbackPresent by default (blockable, but it exists).Does not exist.
Version fingerprintingCore and plugin versions leak into the HTML.None.
Security headers by defaultHSTS only; the rest is per-site plugin/nginx work.Full A-grade set, applied uniformly at the platform level.
Code an attacker can reach~550,000 core lines + every installed plugin.Zero lines. Nothing executes for anonymous visitors.

Measured 2026-08-10 against live production sites Fruition operates: a hardened, Fruition-hosted WordPress site (the WordPress column is the architecture, not a misconfiguration) and a Steldris site. Full methodology is in our research notes.

03 — WHO HOLDS THE PEN

Every update hands a stranger the keys.

On a typical WordPress site, a plugin update puts code from an anonymous author onto your server with full access to your database, your visitors, and your content. No profile, no history, no one accountable. In 2026, websites are real-time, AI-integrated surfaces that adversaries actively target. The model that was fine in 2003 is not built for that.

WordPress, self-hosted

The plugin model: anyone can publish, updates flow straight to your site, and the person who wrote the code is usually a username. Accountability ends at the download button.

WordPress, Fruition-hosted

The same plugins, on infrastructure we run. Every dependency gets a provenance score and we watch the updates for you — but the code still comes from outside.

Drupal

Better governance, same model. Drupal's security team and vetted contribution queue raise the floor, but the modules still come from outside your organization, and the updates are still yours to chase.

Steldris

No third-party plugin layer at all. One accountable team writes, reviews, and deploys every change, and you can ask any of us by name what changed and why. That is what provenance means when it is actually enforced.

7,612

third-party WordPress plugins provenance-scanned across our managed fleet

234

installed by our clients but maintained by an anonymous author — no one to hold accountable

48 / 100

median provenance score of a random WordPress.org plugin (1,964-plugin random sample) — and none of the 1,964 earned an A or B

0

third-party plugin-layer dependencies on a Steldris site

From the dependency provenance scanner we run across our managed fleet, September 2026: every WordPress plugin and Drupal module is scored 0-100 on source origin, maintainer identity and verifiability, security coverage, and maintenance activity. An anonymous maintainer caps the grade at D automatically — no amount of popularity offsets an accountability failure. The WordPress.org baseline is a uniform random sample of the public plugin directory (random offsets over the popularity ranking), scored with the same rules — note that commercially-sold plugins (the anonymous-maintainer ones) do not even appear in the public directory, so the ecosystem's real floor is lower than the median suggests.

Ask your current vendor the question that matters: who typed the code that runs on your site, and can you call them? On Steldris the answer is a name.

Measured, not marketed

The scorecard.

A sample set of the sites we manage, scored by the same scanners and averaged by platform — including the column where Steldris is behind.

Average scores by platform for a sample set of sites Fruition manages, 2026-09-16
PlatformPerformanceAccessibilitySEOSecurity headers

WordPress

64D87B86B27F

Drupal

54F77C80B49F

Steldris

97A92A84B94A

Fruition Control Plane, CMS comparison, pulled 2026-09-16: a sample set of the sites we manage — the latest desktop Lighthouse score and the latest security-headers scan (0–100) for each site, averaged by platform. Letter grades are the scanner's own bands (A 90+, B 80+, C 70+, D 60+). Steldris trails on SEO because steldris.com serves a noindex header until its public launch, and that one check pulls the small Steldris sample down. Raw vulnerability-scanner finding counts are not shown: the feed does not split them by severity, so a static site's "technology detected" matches would read like exploitable findings. We score ourselves with the same scanners, weekly.

The trade-off.

WordPress and Drupal are mature platforms with enormous ecosystems, and neither is inherently insecure. Hosting them on Fruition's infrastructure closes a real part of the gap: the Shield WAF, managed patching of the platform, monitoring, and backups all become ours. What stays yours is the plugin ecosystem and the accessibility retrofit. Steldris removes that layer entirely. If your team has the people and loves the work, keep what you have. If you would rather spend that time on your mission, that is what we do.

BOOK A MIGRATION

Tell us where your site lives today.

We handle the move and run the platform for you. No re-platforming project, no plugins to babysit.

  • We migrate your content off WordPress or Drupal.
  • We run hosting, security, and accessibility from day one.
  • You get a calm dashboard and a team that owns the infrastructure.