Magic vs WordPress: An Honest Feature Matrix

Magic vs WordPress: An Honest Feature Matrix

WordPress shipped in 2003. Elementor, the most-installed page builder on top of it, ships a <section> wrapped in a <div class="elementor-container"> wrapped in a <div class="elementor-column"> wrapped in a <div class="elementor-widget-wrap"> wrapped in a <div class="elementor-widget"> — five layers of generated div before your actual heading shows up, each with its own auto-numbered id, for a block of text a hand-written page would wrap in one <div>. That is not a bug anyone is going to fix. It is the compounding cost of an editor and a database schema designed in 2003, glued to a visual builder that has to express every layout as config because none of it is a file you could just open and edit.

The last matrix in this series was against a product built in 2023 that still beats Magic on several rows. This one is against the most dominant CMS in the history of the web, and it still loses most of the table — not because WordPress is badly built, but because every row where it loses is load-bearing weight from a 23-year-old architecture that Magic simply never had to carry.

The matrix

FeatureWordPressMagic Cloud
Age / architecture2003, PHP + hooks/filters + global state, MySQL-only core2026, generated code on a whitelisted AST runtime, four database engines
LicenceGPLv2-or-later; plugins/themes on wordpress.org must be 100% GPL tooMIT, all of it, no exceptions
Free tierSelf-hosted core is free; you supply hostingSelf-host everything, uncapped, forever
Hosted plansWordPress.com: Free (1GB, ads, no plugins) → Personal $9 → Premium $18 → Business $40 (plugins unlock here) → Commerce $70/mo$100/mo per cloudlet, $300 for double the machine — plugins, custom code and SSO included at every tier
Managed self-hostedWP Engine from $25–30/mo, Kinsta from $35/mo — both capped at ~25k visits/mo with per-1,000-visit overage feesFlat $100/mo, no visit metering, no overage
The backendA database of rows interpreted at request time through ~23 years of hooksHyperlambda files you can open, read, diff and commit
Extending itA plugin: PHP with full, unsandboxed access to the process — no permission boundaryA Hyperlambda file executing as an AST where every node binds to a whitelisted slot
Database enginesMySQL/MariaDB only, officially; Postgres via unsupported third-party shimsSQLite, MySQL, PostgreSQL, SQL Server — native
2025 disclosed vulnerabilities11,334 (+42% YoY) — 91% in plugins, 9% in themes, 6 in coreN/A — no plugin marketplace of that shape exists to measure
Visual editing outputElementor-class builders: 5 nested generated divs per widget, auto-ids, inline styles, content in shortcodesWeb Designer edits the real file in place — a retyped heading is a 1-line diff, no wrapper divs, zero inline styles
SSONot in core; a plugin, and usually a paid one, per providerEight OIDC providers built in — Google, Microsoft, GitHub, LinkedIn, Slack, Okta, Auth0, Keycloak
Agent / MCP storyAbilities API landed in core at WP 6.9 (Nov 2025); the official MCP Adapter is 7 months old, v0.6.x, and only exposes what each plugin opts to registerNative MCP with OAuth, RBAC-filtered tools, live since early 2026; agents generate new tools for themselves at runtime
What the agent can do once connectedCall whatever abilities plugins have registered — a fixed, opt-in surfaceRead the generated code, then write more of it
REST API/wp-json/, since 2016, with zero-config Application Passwords — genuinely programmatic, credit where dueEvery generated endpoint is an MCP tool the moment it's saved
Content heritageRevisions, drafts, scheduling, multisite, comments — 23 years of CMS featuresNone of it; not a CMS
E-commerceWooCommerce — the largest e-commerce platform by site countA purchase/webhook pipeline, not a storefront
Non-developersGutenberg + a 90,000-plugin marketplace; a huge population can run one aloneA developer tool, and honest about it
Frontend hostingNeeds a host; the host is the whole product categoryFirst-class static and SPA hosting per cloudlet, same machine as the API
Market share41–43% of all websites, 59% of CMS-using sitesRounding error, and we say so every time

Where WordPress wins, stated plainly

No rebuttals in this section, per the rules of this series.

The plugin and theme marketplace. Over 71,000 free plugins on wordpress.org, past 90,000 counting premium marketplaces. Whatever you need — forms, SEO, membership gating, multilingual, caching — someone already built it and ten thousand sites are running it in production. Magic has a small Bazar; it is not in the same universe.

WooCommerce. The largest e-commerce platform on earth by site count. Magic has a purchase pipeline you build; WooCommerce is a finished storefront with a payment-gateway ecosystem of its own.

Gutenberg and the non-developer path. A person with no development background can install WordPress, pick a theme, and run a real site alone. Nothing about Magic is aimed at that person, and nothing in this article pretends otherwise.

Market share as a hiring and support argument. 41% of the web means every agency, every freelancer, every Stack Overflow answer, every WordCamp. That depth of bench is real and it is worth money.

The REST API, specifically. Unlike a page-only builder, WordPress has shipped a genuine, credential-free, application-password-authenticated REST API since 2016. An integration does not need a human clicking through wp-admin to exist. That is a real, mature piece of infrastructure and it predates most of what Magic is being compared to in this series.

Where the gap is architectural, not a feature checkbox

A plugin is not sandboxed. A Hyperlambda file is. This is the row that matters most and the table above understates it. A WordPress plugin is PHP with full access to the running process — no permission model stands between "installed" and "can do anything the webserver user can do." That is exactly why 91% of the 11,334 vulnerabilities disclosed against the WordPress ecosystem in 2025 landed in plugins, while core logged six. The platform itself is secure; the extension model has no ceiling on what an extension is allowed to do. Magic's generated Hyperlambda executes as an AST where every node must resolve to a whitelisted slot, so generated code cannot exceed its permissions no matter what wrote it or what it was asked to do — there's a standing $100 bounty on proving that boundary wrong, and nobody has.

Visual editing either keeps your markup or it doesn't. Drop Elementor on a page and the output is elementor-section → elementor-container → elementor-column → elementor-widget-wrap → elementor-widget, each with a generated id, for every single block on the page, with the content itself living as shortcodes in a database row rather than as a document anywhere you could read it. Web Designer edits the file a developer would have written: retyping a heading through the panel produces a one-line diff, and the document's element count, div count, and inline-style count are measurably identical before and after. One of these produces a page. The other produces a page and a markup liability that compounds with every section you add.

The agent story is a 7-month-old graft versus a load-bearing design decision. Credit where it's due — WordPress's Abilities API, landed in core at version 6.9 this past November, is a structurally sound idea: a core registry any plugin can register a capability into, with the official MCP Adapter bridging that registry to MCP tools. But it is seven months old at the time of writing, sits at adapter version 0.6.x, and an agent's tool surface on any given WordPress site is only as complete as whichever of its plugins have bothered to adopt the new API — which, seven months in, across 90,000 plugins, is close to none of them. Magic's generator has been writing endpoints that are immediately live MCP tools since before the Abilities API existed, and the tool surface grows exactly as fast as you can describe the next endpoint in a sentence, not as fast as a plugin ecosystem adopts a new standard.

One database engine versus four. WordPress core speaks MySQL/MariaDB and nothing else; PostgreSQL support exists only as unsupported third-party compatibility layers that the core team does not maintain. If your organization already runs SQL Server or Postgres, WordPress is not meeting you there — you are migrating to meet it. Magic connects to SQLite, MySQL, PostgreSQL and SQL Server natively, including turning an existing SQL Server or MySQL database into a full backend without migrating a single row.

Pricing meters the two things that grow when a WordPress site succeeds: traffic and features. WordPress.com gates plugins entirely until the $40/mo Business plan. Managed self-hosted options meter visits with overage fees — WP Engine's entry tier caps at 25,000 monthly visits and charges $2 per thousand over; Kinsta's equivalent charges $1 per thousand over the same cap. Run an example: a content site at 150,000 monthly visits needing a page builder, an SEO plugin and a caching plugin is already past WP Engine's Growth tier ($59/mo, 100k cap) into Scale ($115/mo, 400k cap), before a cent of premium plugin licensing is added. Magic's cloudlet is $100/mo flat, with no visit counter anywhere in the invoice — though it is one machine, so a genuine traffic spike is your CDN's job to absorb, not the platform's.

The decision rule

Choose WordPress if: a non-developer owns the site day to day; you need WooCommerce or a mature plugin for a specific job right now; your content needs revisions, drafts, multisite, or editorial workflow; or you're hiring for it and want the largest possible talent pool.

Choose Magic if: the backend needs to be code — reviewable, diffable, git-tracked — rather than rows in wp_options interpreted through two decades of hooks; you don't want an ever-growing third-party plugin surface to patch; your data already lives outside MySQL; or you expect an AI agent to extend the backend by writing to it, not just by calling whatever a plugin author chose to expose.

The one-line test: if a human with no development background is going to run the site alone for years, pick the platform built for exactly that for 23 years. If the backend is going to be read, reviewed and rewritten by developers or by an agent, pick the one that was never anything else.

The fine print

Every WordPress number above was checked the week of publication: 2025's 11,334 disclosed vulnerabilities (91% plugins / 9% themes / 6 core) from industry vulnerability-tracking reporting; the 71,000+ free-plugin count from wordpress.org's own directory; WordPress.com's Free/$9/$18/$40/$70 tiers; WP Engine's and Kinsta's entry pricing and visit caps; the Abilities API landing at WordPress 6.9 and the MCP Adapter's current version; and W3Techs' 41–43% share of all websites. Pricing pages and vulnerability counts move continuously — re-verify before quoting any of it back.

The Elementor markup description is from its published, well-documented output structure, not a page I built and diffed myself today — unlike the Web Designer numbers in the table above, which are measured on this site's own template.

And the standing disclosure: I wrote Hyperlambda and sell Magic hosting. Every row above is checkable precisely because of that. The repository is MIT at github.com/polterguy/magic; self-hosting it costs one copy-paste on a $12 droplet, or a managed cloudlet if you'd rather not run it yourself.

Frequently asked questions

Is Magic Cloud a WordPress alternative?

For a content-and-plugins site run by non-developers, no — WordPress's 23-year CMS heritage and plugin marketplace do things Magic was never built to do. For a backend that needs to be reviewable code rather than database rows interpreted by hooks, yes, and that gap grows every year WordPress's plugin architecture stays unsandboxed.

Is WordPress secure?

WordPress core is: only 6 vulnerabilities were disclosed against it in 2025. The ecosystem around it is not: 91% of the 11,334 vulnerabilities disclosed that year were in plugins, which run with no permission boundary once installed. The risk is almost entirely in what you add, not in what WordPress ships.

Can AI agents use WordPress?

Increasingly, yes. WordPress 6.9 added a core Abilities API, and an official MCP Adapter bridges registered abilities to MCP tools. It's seven months old, and an agent's usable surface on any given site is limited to whichever installed plugins have adopted the new API so far — which is still a small fraction of the 90,000-plugin ecosystem.

Is WordPress cheaper than Magic Cloud?

At the very bottom, yes — generic shared hosting for self-hosted WordPress can run a few dollars a month. Once you need managed hosting at real traffic, premium plugins and a page builder, WordPress.com and managed hosts like WP Engine or Kinsta meter plan tier, feature unlocks and visit volume, with overage fees past the cap. Magic charges one flat per-cloudlet rate with no visit counter.

What's wrong with Elementor and page builders?

Nothing is wrong with what they let a non-developer build. The cost is in what they generate to get there: five nested, auto-id'd divs per widget, and content stored as shortcodes in the database rather than as a document you can read or diff. It works, and it is not markup you would ever choose to hand-write.