CloudLinux Survey Shows WordPress Agencies Are Becoming Infrastructure Operators
A CloudLinux and WebPros survey of 210 WordPress agencies shows small teams carrying hosting, update, security, performance, and AI automation work at infrastructure scale.
A new CloudLinux and WebPros survey makes the WordPress agency market look less like a loose collection of site builders and more like a distributed infrastructure operations layer. The headline is not that agencies are busy. It is that many small teams are now responsible for hosting choices, update discipline, performance work, security monitoring, and the first wave of AI automation across dozens or hundreds of client sites.
Table Of Content
- The agency stack is now operational infrastructure
- Hosting decisions put agencies on the hook
- Updates are the real security bottleneck
- Auto-updates are a control, not a program
- A useful update gate has four records
- Performance work refuses to standardize
- Performance needs portfolio rules
- AI is adopted where it is easy, not where operations hurt
- Agents create a second operations problem
- What agencies should change in 2026
- Bottom line
- Sources
CloudLinux says it and WebPros surveyed 210 WordPress agencies and freelancers for its 2026 agency report. Because CloudLinux sells hosting and security products into this market, the survey should be read as vendor-sponsored research, not a neutral census of all WordPress work. Even with that caveat, the numbers are useful because they describe the operational pressure points agencies already feel: updates, hosting standardization, performance regressions, and AI tools that help with content and code before they help with maintenance.
The agency stack is now operational infrastructure
The survey’s most important pattern is the mismatch between team size and operational surface area. CloudLinux reports that 78% of surveyed agencies are solo operators or teams of up to 10 people, while 18% manage more than 100 client WordPress sites. It also says 47% of solo and small-agency operators manage more than 20 sites. In other words, a small headcount no longer implies a small technical estate.
The same post says hosting, ongoing maintenance, security monitoring, and performance optimization are each offered by 44% to 55% of agencies, and that the average agency offers about four services. That turns a website relationship into a continuing operations commitment. Every plugin decision, PHP version, CDN rule, backup policy, and client-added script becomes part of the agency’s delivery risk.
Hosting decisions put agencies on the hook
CloudLinux also reports that 83% of agencies either choose hosting outright or recommend it and stay involved in the final decision, while only 7% say the client picks hosting independently. CMS and framework choices follow the same pattern: 74% of agencies choose or recommend the technology based on project requirements.
That matters because scale pulls agencies deeper into server operations. The survey says about 42% of agencies run exclusively on self-managed VPS or dedicated servers, 38% run exclusively on managed hosting, and 90% of agencies managing more than 100 sites operate at least some sites on self-managed VPS or dedicated servers. Once an agency is making those decisions, it is not only designing pages. It is setting the reliability and security baseline for a client portfolio.
Updates are the real security bottleneck
The sharpest operational warning is about updates. CloudLinux says the top security challenge is keeping plugins and themes updated across all client sites, named by 65% of agencies and by 75% of agencies managing more than 100 sites. More concerning, the same post says 45% of agencies with more than 100 sites still update WordPress manually, one site at a time.
That finding lines up with WordPress’s own security guidance. The WordPress Advanced Administration Handbook says the most important thing for WordPress security is to keep WordPress itself and all installed plugins and themes up to date. The WordPress documentation for plugin and theme auto-updates adds that administrators can opt in to automatic updates plugin by plugin and theme by theme, and that WordPress runs enabled plugin and theme auto-updates twice per day by default.
Auto-updates are a control, not a program
Auto-updates reduce waiting time, but they do not remove the need for change management. WordPress’s documentation also advises regular automatic backups before enabling plugin and theme auto-updates, and it notes that update scheduling depends on WordPress Cron tasks. For agencies, that means the operational target is not simply “turn on updates everywhere.” The target is a repeatable release process that can prove what changed, where it changed, whether the site still works, and how it can be rolled back.
A useful update gate has four records
- Inventory: which sites, plugins, themes, PHP versions, and hosting profiles are in scope.
- Recovery: whether a recent backup exists and whether the rollback path has been tested for that hosting tier.
- Compatibility evidence: a small smoke test for checkout, forms, login, cache behavior, and critical pages after updates.
- Ownership: who approved the change, who receives failure notifications, and which client contract covers emergency work.
Performance work refuses to standardize
Security is not the only backlog. CloudLinux says 37% of agencies describe performance work as significant, heavy, or overwhelming, compared with 28% who say the same about security. The report’s explanation is practical: security controls can often be standardized, while performance problems are more site-specific. A cache rule, image policy, or plugin replacement that helps one client may break another client’s theme, analytics setup, or conversion funnel.
The survey names plugin and theme bloat as the top performance challenge at 59%. Third-party scripts come next at 30%, and CloudLinux says that figure rises from 16% among agencies managing 20 or fewer sites to 50% among agencies managing more than 100. That is the hidden cost of portfolio scale: the more clients an agency supports, the more after-launch changes it must absorb from marketing tags, chat widgets, tracking pixels, page builders, and one-off business requests.
Performance needs portfolio rules
A single-site optimization project can be bespoke. A 50-site or 100-site agency portfolio needs policy. Agencies should define plugin approval rules, performance budgets for key templates, a third-party-script review path, and a standard way to measure before and after changes. Without that baseline, every slow site becomes a custom investigation and every client request becomes a potential reliability regression.
AI is adopted where it is easy, not where operations hurt
The survey’s AI findings show a familiar gap. CloudLinux says nine in ten agencies already use AI somewhere in their workflow, especially for content writing (59%), code generation and debugging (53%), and SEO research (39%). But the work most tied to operational debt is barely automated: only 16% of agencies use AI for site monitoring and maintenance automation.
Demand points in the other direction. CloudLinux says agencies most want automated WordPress updates with intelligent pre-update testing (38%) and automated security across client sites (35%). It also reports that 63% use basic AI autocomplete such as GitHub Copilot or ChatGPT in coding workflows, 39% already use AI agents such as Cursor, Claude Code, or Windsurf for complex development tasks, and 26% use design-to-code workflows.
Agents create a second operations problem
That adoption is not automatically good or bad. It is a sign that AI has entered production workflows before many agencies have mature controls for it. An agent that can edit code, read files, call package managers, or connect to a hosting panel needs access boundaries, logging, dependency review, and secret-handling rules. Otherwise, AI becomes another privileged operator in the agency stack, but without the same onboarding, least-privilege, and incident-response habits expected from a human developer.
What agencies should change in 2026
The practical lesson is to treat WordPress operations as a productized service, not as a set of heroic maintenance tasks. Agencies that want to scale safely should make a few changes before their portfolios force the issue.
- Segment the portfolio: group sites by revenue criticality, plugin risk, hosting model, and update tolerance.
- Standardize hosting baselines: define supported PHP versions, backup retention, cache layers, WAF expectations, and monitoring for each tier.
- Automate evidence, not just clicks: update tools should produce logs, screenshots, test results, rollback markers, and client-facing change notes.
- Measure performance drift: track key templates, not only the homepage, and flag third-party script additions as change events.
- Fence AI agents: restrict which repositories, credentials, production shells, and client data an agent can reach, and review agent-generated changes like any other code change.
Bottom line
The CloudLinux survey is useful because it reframes WordPress agency work around operations rather than aesthetics. Small teams are choosing hosting, maintaining plugins, tuning performance, and experimenting with AI agents across portfolios that can exceed 100 sites. That is infrastructure work, whether the client contract calls it that or not.
The agencies that win from here will not be the ones that merely add more AI content tools or more page-builder expertise. They will be the ones that turn updates, performance, security, and AI-assisted development into measurable release systems. WordPress is still a publishing platform. At agency scale, it is also an operations platform.
Sources
- CloudLinux Blog: How WordPress Agencies Really Operate in 2026, and Where the Work Is Piling Up
- CloudLinux: State of WordPress Agencies 2026 report landing page
- WordPress Advanced Administration Handbook: Security
- WordPress.org documentation: Plugin and themes auto-updates
- Featured image source: helloquence on Wikimedia Commons
Featured image: Helloquence-61189 by helloquence, released under the CC0 1.0 Universal Public Domain Dedication via Wikimedia Commons; cropped and converted to WebP for sxz.io.








No Comment! Be the first one.