shouldiuse.io

Categories

VERDICT

Should I use WordPress.org Brasil?

Um programa de código aberto que você pode usar para criar um lindo site, blog ou aplicativo sem dificuldade. - br.wordpress.org

Depends. Great fit if you (or a developer) can handle hosting, updates, backups, and security yourself — the core software is free and endlessly flexible. Avoid it if you want a hands-off hosted site; WordPress.com, Squarespace, or Wix will spare you the maintenance and security headaches.

Confidence

Medium. Based on ~25 distinct public sources: reviews, official pages, security advisories, and news.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

WordPress.org software

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Third-party hosting$2.95–$13.95/mo

Best for

  • Bloggers and content publishers
  • Developers comfortable self-hosting
  • Stores built on WooCommerce
  • Portuguese-speaking self-hosters

Not for

  • Non-technical owners who won't manage updates and security
  • Anyone wanting a zero-maintenance hosted site
  • Simple portfolios or one-pagers — pure overkill
  • Teams with no budget for developer or admin time

Gotchas - check before you buy

high

You own updates, backups, and hardening; skip them and you're the low-hanging fruit.

high

Old WordPress versions stopped receiving security updates in July 2025 — lag and you're exposed.

medium

Free core, paid everything else: hosting from ~$2.95/mo plus plugins and dev time.

medium

Plugin quality varies wildly — some official plugins rate as low as 2.7/5.

Pros and cons

Pros

  • Free, open-source core with no license fees
  • G2: praised for flexibility and ease by beginners and experts
  • Huge plugin ecosystem: stores, analytics, newsletters, more
  • Powers millions of sites, from blogs to stores

Cons

  • Self-hosted: heavy maintenance burden falls entirely on you
  • Trustpilot score just 1.8/5 across 263 reviews
  • Critical flaws exploited in the wild as of July 2026
  • Plugin supply-chain hacks pushed malware to thousands of sites

Sources & method

Analyzed 9/21/2026 - 11 sources - Actively targeted in 2026: critical core flaws exploited in the wild and plugin supply-chain compromises.

official x3review x5security x1news x2
  • Critical core flaws exploited in the wild, Two critical vulnerabilities gave hackers remote access, putting millions of sites at risk (Jul 2026).
  • WP 7.0.3 patched 12 vulnerabilities, Included the wp2shell exploit chain (CVE-2026-60137, CVE-2026-63030), fixed Aug 2026.
  • Plugin supply-chain compromise, 30+ plugins in the EssentialPlugin package were hacked to push malware (Apr 2026).
  • Critical plugin vulnerability CVE-2026-28139, Disclosed as one of the newest critical WordPress plugin vulnerabilities (Aug 2026).

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 11

    Sources

  • Analyzed

  • Value for money: 5/5. Core is free; costs are hosting and time
  • Ease of use: 3/5. Easy start, but self-hosting adds real work
  • Feature depth: 5/5. Plugin ecosystem covers nearly any feature
  • Support quality: 2/5. Community forums only; no vendor support
  • Security posture: 2/5. Actively exploited flaws and plugin supply-chain attacks
  • 1.8/5 Trustpilot rating 263 reviews
  • Free Software price open-source, self-hosted
  • Yes Free tier you pay for hosting instead
  • 12 Vulns fixed in WP 7.0.3 Aug 2026 security release

Pricing

WordPress.org software

Free

  • Download and self-install
  • No license fees

Third-party hosting

$2.95–$13.95/mo

  • Typical shared hosting range
  • Billed separately from the software

Security

Actively targeted in 2026: critical core flaws exploited in the wild and plugin supply-chain compromises.

  • Critical core flaws exploited in the wildTwo critical vulnerabilities gave hackers remote access, putting millions of sites at risk (Jul 2026).⁷
  • WP 7.0.3 patched 12 vulnerabilitiesIncluded the wp2shell exploit chain (CVE-2026-60137, CVE-2026-63030), fixed Aug 2026.⁹
  • Plugin supply-chain compromise30+ plugins in the EssentialPlugin package were hacked to push malware (Apr 2026).⁸
  • Critical plugin vulnerability CVE-2026-28139Disclosed as one of the newest critical WordPress plugin vulnerabilities (Aug 2026).

What users say

Polarizing: G2 reviewers praise flexibility and ease of use, while Trustpilot reviewers (1.8/5) call it a maintenance headache.

“Wordpress is the worst headache you will ever have designing.”
Trustpilot
“The biggest drawback is the heavy maintenance burden. Because it is self-hosted, you are entirely responsible”
G2
“Users consistently praise the platform for its flexibility and ease of use”
G2

Companies that use it

  • Microsoft
  • HP
  • Postman
  • UNICEF
Full analysis

Based on ~25 distinct public sources: reviews, official pages, security advisories, and news.

Powerful free CMS, but you're the IT department: hosting, updates, and security are all on you.

Methodology

Based on ~25 distinct public sources: reviews, official pages, security advisories, and news.

Sources

  1. review
  2. review
  3. review
  4. review
  5. official
  6. official
  7. news
  8. news
  9. security
  10. official
  11. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.