Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?

Automattic CEO Matt Mullenweg has been abruptly put on a paid leave of absence from the company by its board of directors, despite his objections. But enterprise IT executives who rely on WordPress may find the shift doesn’t mean much as long as Mullenweg fully controls WordPress.org, which handles all of the product’s patches and updates.

“The part of WordPress that actually keeps enterprise IT up at night isn’t Automattic’s org chart. It’s WordPress.org, the plugin and theme directory every WordPress site pulls its security updates from, and the WordPress trademark,” said Frank Dickson, principal analyst at Dickson Research. “Mullenweg owns and controls both personally, outside of Automattic, and nothing about this week’s vote touches that. He also remains a director on Automattic’s board. The company changed who runs its hosting business without changing who controls the distribution pipeline millions of those hosted sites still depend on.”

For IT leaders who rely on WordPress, it’s important to differentiate what is currently known about the change and what is speculation. A statement emailed to Computerworld from Automattic merely said: “Matt Mullenweg is currently on leave from Automattic. Mark Davies, Automattic’s CFO, will lead the company as interim CEO. The Board has full confidence in Mark’s leadership and in the team’s ability to execute against the company’s priorities.” 

However, messages from Mullenweg to Automattic employees made it clear that the move was one that he strongly opposed. He posted on his X account, “the next step in this playbook is to restart the smear attacks, so get ready for some National Enquirer rumors or hit pieces.”

He added: “I appreciate the hundreds of colleagues who have already expressed public and private support, and are organizing in solidarity. It’s a big help to counter the ‘Matt is an idiot and shouldn’t run an ice cream stand’ allegations. Also, whatever you can say about me, I’m direct and probably overcommunicate, which I’m going to continue doing through this mess folks have made.”

He also posted separately that he is looking to hire, but that applicants cannot be current Automattic employees. “I really need some great sysadmin and security researchers to hire really quick, no one from @automattic. I’m on the board there and fully support Mark Davies in his interim CEO role. But I think it’s probably good if I move some of my stuff currently hosted there, elsewhere.”

Next steps unclear

What is unclear are likely next steps. Is the leave permanent or temporary? And if temporary, how temporary? Is the board negotiating with Mullenweg, and might those negotiations involve whether Mullenweg continues to control WordPress.org? Neither Automattic nor Mullenweg provided clarification.

Melody Brue, analyst-in-residence at Moor Insights & Strategy, who has closely tracked WordPress for years, said that the apparent speed of Mullenweg’s removal as Automattic CEO suggests that the board was trying to sidestep something serious.

“It has to be some exposure or risk that was severe enough that speed outweighed any optics or fairness. Boards don’t generally move that abruptly,” she said. The appointment of the CFO as interim CEO “definitely shows some stabilization and possibly some legal compliance cleanup. What it doesn’t say is renewed product investment.”

IT worried about instability

But the longstanding worries among CIOs about WordPress were not primarily about the perceived lack of continued investment. It was the concern that Mullenweg has a tendency to react strongly to a situation, apparently without many thoughts of the consequences

Nothing better illustrated this than Mullenweg’s personal war with WordPress hosting provider WP Engine that resulted in a series of legal rulings in WP Engine’s favor. 

WP Engine litigation is still ongoing, and that may have played a role in the board’s actions. 

Part of that lawsuit is at the heart of enterprise IT concerns: Mullenweg had denied WP Engine access to WordPress.org resources, including patches, plugins and security updates for the software. 

The IT fear is that Mullenweg could unilaterally take similar actions against any customer, even an enterprise. 

“I would still treat this as vendor risk, because WordPress.org is still controlled by Matt, separate from Automattic,” Brue said. “The question is, who actually controls the plugins that these IT leaders rely on? It’s still a structural risk. Look at whether the patches flow through one person. For now, they still do. Is that pipeline protected by independent governance, oversight? That is what matters for enterprise IT.”

Flavio Villanustre, CISO at the LexisNexis Risk Solutions Group, agreed. 

“Most of the concerns from enterprises about using WordPress come from the fragmented ecosystem and the inconsistent security controls and support of modules and extensions, which have led to significant vulnerabilities in the past,” Villanustre said. “The change of CEO in their parent company won’t directly affect this, especially because Matt Mullenweg will continue as the WordPress[.org] leader anyway.”

Dickson also agreed, noting that the question of who sits in the CEO seat at Automattic was not the issue.

“The enterprise IT concern was never really about Automattic’s management bench. It was about one person holding unilateral, unaccountable control over a piece of critical open-source infrastructure,” he said. “In 2024, Mullenweg used exactly that control to cut WP Engine’s customers off from plugin and theme updates overnight, with no board sign-off and no customer input, purely as leverage in a business dispute. This week’s vote proves a board can restrain him inside Automattic. It says nothing about what restrains him at WordPress.org, because the honest answer is still nothing.”

In fact, rather than reducing those IT worries, Dickson argued that this move could worsen them. 

“If anything, this should sharpen the concern rather than settle it. A board just decided it couldn’t function with him running a corporate entity with ordinary fiduciary obligations,” he pointed out. “That same person still holds sole authority over the update pipeline for software that runs over 40% of the web. Risk teams that were nervous about concentration risk in WordPress now have a fresh, concrete data point: the concentration is real, and untouched by whatever just happened at Automattic’s board table.”

This change could help

Mike Wilkes, enterprise CISO at Aikido Security, interpreted the events differently, and suggested that it might indeed make WordPress look more attractive to enterprise IT.

“This could ultimately make WordPress more attractive to enterprise buyers, but only if it becomes the beginning of stronger institutional governance rather than simply a change in personalities,” he said. “CIOs don’t particularly care about palace intrigue until that intrigue can affect software updates, supply-chain dependencies or business continuity. The WP Engine conflict demonstrated that governance risk can become operational risk surprisingly quickly. The ongoing litigation underscores that this is not merely historical baggage.”

Wilkes pointed out that the next few steps taken by the board and by Mullenweg will likely be far more informative than any analysis of the board’s CEO change.

“I wouldn’t tell a CIO that yesterday’s announcement makes WordPress either safer or riskier today. I would tell them to watch what happens next,” he said. “If Automattic uses this moment to create clearer separation between corporate interests, WordPress.org infrastructure, and community governance, it could reduce one of the ecosystem’s most persistent concentration risks. If the same authority simply migrates to different individuals without structural reform, enterprise concerns haven’t really changed. In cybersecurity terms, replacing the administrator isn’t the same thing as eliminating the single point of failure.”

Dylan Forde, owner of Harmonic Design in Oakville, Ontario, Canada, and a WordPress developer for more than ten years, applauded the CEO change. 

“It is my opinion that the removal of Mr. Mullenweg is a good thing for both the WordPress community and open source,” he said. “He has been divisive for a long time, with many grievances that I overall understand, but I oppose his responses to. It sucks to build something used by millions of people and businesses around the world, all profiting off your work while giving nothing back. But cutting off and targeting individuals is not the answer. Open source is supposed to work for everyone, and my assumption is that anyone whose core business relies on WordPress will be sleeping easier now.”

Read more: Automattic CEO Matt Mullenweg is out: Does this mean long-term viability, or liability, for WordPress customers?

Story added 11. September 2026, content source with full text you can find at link above.