WordPress suits publishers who want a free GPL licence, a large plugin directory and a familiar editor, from a solo blog to a small newsroom. The trade-off is that core gives you roles, scheduling and revisions but leaves multilingual content, structured data and advanced workflow to plugins you must vet and keep updated.
Word & Press is an independent publication. It is not affiliated with, endorsed by or connected to WordPress, the WordPress Foundation or Automattic. This profile describes the open-source WordPress software as a third party.
What is WordPress?
WordPress is open-source publishing software written in PHP. Its own about page says it started in 2003 when Mike Little and Matt Mullenweg created a fork of b2/cafelog, and describes it as built on PHP and MariaDB and licensed under the GPLv2. That page also says it is the platform of choice for over 43% of all sites across the web. That is the project’s own claim, so treat it as a marketing figure rather than an independent measurement.
For publishers the practical meaning is a large installed base. Developers, hosts and freelancers who know the software are easy to find, and the choice is rarely a surprise to an agency.
| Fact | Detail |
|---|---|
| Licence | GPL version 2 or later |
| Latest version | 7.1.3 (6 October 2026), according to the release archive |
| Written in | PHP |
| Database | MariaDB 10.11+ or MySQL 8.0+ recommended |
| Hosting | Self-hosted on Apache or Nginx with PHP 8.3+ recommended |
| Price | Software free; hosting, themes, plugins and development are extra |
| Made by | Open-source contributors; originally forked in 2003 by Mike Little and Matt Mullenweg |
Our licence guide explains what the GPL does and does not require of you.
Who is WordPress best for?
It suits a small or mid-sized publisher that wants to launch quickly, hire from a deep talent pool and add features by installing extensions. A single editor, a magazine with a handful of writers and a local news site with a part-time developer all fit.
It is a weaker choice where editorial process is the product: strict multi-stage approvals, content modelled as structured data rather than pages and posts, or many languages managed as linked translations. You can build those on WordPress, but the documentation we opened for core does not describe them, so you would be relying on extensions and custom work. Compare it against Drupal and TYPO3 if those needs lead your list.
Editorial workflow
The documentation lists six default roles: Super Admin, Administrator, Editor, Author, Contributor and Subscriber. An Editor can publish and manage posts including other users’ posts, an Author can publish their own, and a Contributor can write their own posts but cannot publish them.
That maps to a simple newsroom. Freelancers and junior writers get the Contributor role and press Submit for Review. The post gets the pending status, which waits for someone with the publish capability, typically an Editor. Posts can also be scheduled: the future status means published at a later date. WordPress ships eight built-in statuses in all, including private and trash.
Revisions are kept for each saved draft or published update, with a slider that shows what changed and a Restore button. Since 7.0 there is a new revisions screen, and the classic side-by-side screen remains. By default WordPress stores every revision, and the limit is set in wp-config.php or a filter. The documentation says a function exists to delete revisions but there is no interface for it, so a busy site may want a plugin or a policy. Autosaves are limited to one per user per post and do not overwrite published content.
What the pages above do not describe is custom approval stages, inline editorial comments or a built-in editorial calendar. Treat those as extension territory and check each against your process.
SEO, structured data and feeds
Core handles the plumbing. Pretty permalinks are chosen on the Permalinks screen: plain, day and name, month and name, numeric, post name or a custom structure, with custom category and tag bases. Note the default uses day and name in the URL, so many publishers change it before launch and avoid changing it later.
Since WordPress 5.5 a sitemap index is exposed at /wp-sitemap.xml, covering public post types, taxonomies, author archives and the homepage. The source we opened does not list a news sitemap, and we have not verified how core handles Google News requirements, so check Google’s own documentation and your plugin before assuming.
Feeds are built in: RSS 2.0, Atom and RDF, plus a comments feed. Title tags, meta descriptions, canonical handling and JSON-LD structured data are not covered by the pages we opened as core features. On most WordPress sites an SEO plugin supplies them, which means that layer of your search presence depends on a plugin’s quality and updates. See the features checklist when you compare options.
Media, multilingual and performance
The documentation we opened does not detail image handling, so we do not make claims about it here. On languages, the Multisite documentation describes one installation running several sites, and we did not find core content translation described in the pages we read. A multilingual news site should plan on a translation plugin or a separate site per language, and test how it handles URLs and hreflang.
For speed, the performance documentation says caching plugins serve posts and pages as static files to cut server load, and that a CDN can greatly reduce load on the site. Both are standard for a news site that sees traffic spikes. Page-builder themes and plugin-heavy pages are the usual cause of slow templates, though that is a general observation, not something we measured.
Hosting and requirements
The requirements page recommends PHP 8.3 or greater, MariaDB 10.11 or greater or MySQL 8.0 or greater, Apache or Nginx, and HTTPS. It says older stacks such as PHP 7.4 and MySQL 5.5.5 still technically work but are end-of-life and may expose a site to security vulnerabilities. Check your host’s PHP version before you migrate.
Because you self-host the software, you decide where it runs, who updates it and who monitors it. The release archive states that only the most recent release in the 7.1 series is safe to use and actively maintained, so budget for routine updates.
Extending WordPress
Extensions are plugins and themes. The project describes its plugin directory as the largest directory of free and open source WordPress plugins, though it gives no count we could verify. Under the project’s licence statement, plugins and themes are derivative work and inherit the GPL.
For developers, the REST API exposes posts, pages, taxonomies and other data types as endpoints that send and receive JSON. That allows a decoupled front end, a mobile app or an import script. The same openness cuts the other way: any plugin runs with the permissions of the site, so vet what you install and remove what you do not use.
What WordPress costs
The licence is free. A realistic publisher budget has four lines: hosting, a theme or custom design, paid plugins where free ones do not fit, and developer time for updates and incident response. We have not verified public prices for any host or plugin, so we give no figures. Our cost guide lists the categories.
Where WordPress falls short
- Core does not describe structured editorial stages, so complex approval flows need plugins or custom code.
- Multilingual content, structured data, meta fields and news sitemaps are not covered as core features in the pages we read.
- Every plugin adds update work and potential security exposure.
- By default every revision is kept, and there is no interface to delete them.
- Self-hosting means you run the stack, backups and security.
The verdict for publishers
WordPress is the pragmatic default for a small to mid-sized publication: free licence, a standard editor and role model, scheduling, revisions, sitemaps and feeds in core, and the biggest pool of people who know it. It rewards teams that keep the plugin list short and maintain it.
It is not the obvious pick when your needs are structured content, many languages or formal approval chains, where Drupal or TYPO3 are built around those problems. Read how we assess products on how we test. This profile is based on vendor documentation, not an install of our own.
Questions people ask
Is WordPress free to use for a news site?
The software is released under the GPLv2 or later, so there is no licence fee. You still pay for hosting, any paid plugins or themes, development and maintenance. Plugins and themes inherit the GPL under the project's own licence statement, but individual vendors may still charge for them.
What PHP and database versions does WordPress need?
The requirements page recommends PHP 8.3 or greater and either MariaDB 10.11 or greater or MySQL 8.0 or greater, running on Apache or Nginx with HTTPS. It notes older versions technically work but are end-of-life and may expose a site to security vulnerabilities.
Does WordPress have an editorial approval workflow?
Partly. Core has a Contributor role that cannot publish, a pending status and a Submit for Review button, so an editor can approve work. Custom stages, comments on drafts and approval checklists are not described in the documentation we opened, so expect to add a plugin.
Does WordPress generate an XML sitemap?
Yes. Since version 5.5 it exposes a sitemap index at /wp-sitemap.xml covering public post types, taxonomies, author archives and the homepage. It does not include a Google News sitemap according to the source we opened, which lists no such type.
Can WordPress run as a headless CMS?
Yes, in the sense that its REST API returns JSON for posts, pages and taxonomies, so a separate front end can consume the content. You then take on building and hosting that front end, and features that depend on the WordPress theme layer need replacing.
Are Word & Press and WordPress related?
No. Word & Press is an independent publication with no connection to WordPress, the WordPress Foundation or Automattic. This profile describes the open-source software as a third party.
Sources
- The WordPress release archive lists WordPress 7.1.3, released on 6 October 2026, as the newest release, and states that only the most recent release in the 7.1 series is safe to use and actively maintained. — source, checked 10 October 2026.
- The WordPress software is released under the GPLv2 (or later) from the Free Software Foundation, and plugins and themes are derivative work and inherit the GPL licence. — source, checked 10 October 2026.
- WordPress started in 2003 when Mike Little and Matt Mullenweg created a fork of b2/cafelog. — source, checked 10 October 2026.
- The WordPress requirements page recommends PHP 8.3 or greater, and MariaDB 10.11 or greater or MySQL 8.0 or greater, with HTTPS support. — source, checked 10 October 2026.
- The WordPress requirements page recommends Apache or Nginx as the most robust and featureful server for running WordPress, and says older versions such as PHP 7.4 and MySQL 5.5.5 are end-of-life and may expose a site to security vulnerabilities. — source, checked 10 October 2026.
- WordPress documents six default roles: Super Admin, Administrator, Editor, Author, Contributor and Subscriber. An Editor can publish and manage posts including those of other users; an Author can publish and manage their own posts; a Contributor can write and manage their own posts but cannot publish them. — source, checked 10 October 2026.
- WordPress provides 8 built-in post statuses, including draft, pending (awaiting a user with the publish_posts capability), future (scheduled to be published at a future date), private and publish. Users without the publish_posts capability see a Submit for Review button instead of Publish. — source, checked 10 October 2026.
- The WordPress revisions system stores a record of each saved draft or published update, lets you drag a slider to see what changed, and has a Restore button. Since WordPress 7.0, clicking a revision opens a new revisions screen, with the classic screen still available. — source, checked 10 October 2026.
- By default WordPress stores every revision (WP_POST_REVISIONS true or -1); the number can be limited in wp-config.php or with the wp_revisions_to_keep filter, and there is an API function to delete revisions but no UI. Revisions are stored in the posts table. — source, checked 10 October 2026.
- There is only ever a maximum of one autosave per user for any given post, and autosaves do not overwrite published content. — source, checked 10 October 2026.
- Since WordPress 5.5, WordPress exposes a sitemap index at /wp-sitemap.xml, with sitemaps created by default for all public post types and taxonomies, author archives and the homepage. — source, checked 10 October 2026.
- WordPress documentation lists built-in feed formats of RSS 2.0, Atom and RDF/RSS 1.0, plus a comments feed in RSS 2.0. — source, checked 10 October 2026.
- The WordPress Permalinks screen offers Plain, Day and name, Month and name, Numeric, Post name and Custom structure options, plus custom category and tag bases; by default WordPress uses URLs that have day and name in them. — source, checked 10 October 2026.
- The WordPress REST API supplies endpoints representing posts, pages, taxonomies and other built-in data types, and applications can send and receive JSON to query, modify and create content. — source, checked 10 October 2026.
- WordPress documentation says caching plugins cache posts and pages as static files to reduce server load, and that using a CDN can greatly reduce the load on a website. — source, checked 10 October 2026.
- WordPress Multisite enables you to create several instances of WordPress managed within one installation. — source, checked 10 October 2026.
- The WordPress.org plugin directory describes itself as the largest directory of free and open source WordPress plugins. — source, checked 10 October 2026.