From a reimagined Contributor Day to candid conversations with CloudLinux, Hosting.com, Porkbun, and BigScoots, WordCamp US showed us an industry working through major changes in AI, security, infrastructure, and community investment.
WebHosting.Today attended WordCamp US 2026 looking for answers to a few important questions.
What does the WordPress community look like in 2026? Why should hosting companies continue investing in physical events? How are providers responding to AI, faster security threats, and changing customer expectations? Most importantly, does WordCamp still deliver meaningful value for the hosting industry?
After four days in Phoenix, our main takeaway was clear. Community remains one of this industry’s strongest assets.
WordCamp US took place August 16 through 19 at the Phoenix Convention Center. The event combined a reimagined Contributor Day, a dedicated Showcase Day, two days of sessions and workshops, a Sponsor Hall, Career Corner, Happiness Bar, and closing community social.
More than 50 talks and workshops covered AI, technical WordPress, professional development, and the fundamentals of building with the platform.
Despite early concerns about registration, and the challenge of bringing attendees to Phoenix in August, final attendance approached 1,200 people. Roughly 35% were first-time attendees.
That influx matters to hosting companies. It represents new agencies, freelancers, developers, creators, and businesses entering or becoming more involved in the WordPress economy. Many could become future customers, partners, employees, or collaborators.
The event’s value, however, could not be measured only by attendance or the number of leads collected at a booth.
Throughout the week, we saw some of the most valuable conversations happening in hallways, coffee lines, community spaces, evening gatherings, and the Sponsor Hall. These were opportunities for companies to listen to customers, meet partners, and develop relationships that would be difficult to reproduce during a scheduled video call.
For hosting providers, attending WordCamp is less about generating an immediate pipeline and more about long-term positioning. It means remaining visible, building trust, and participating in the conversations shaping the next phase of WordPress.
Contributor Day tried something different

This year’s Contributor Day reflected how quickly the open-source project is evolving.
Traditional WordPress Contributor Days generally organize participants around established contributor teams. At WordCamp US 2026, organizers tried a different model. Participants formed teams around specific goals and attempted to ship something before the end of the day.
Experienced contributors helped newcomers turn ideas into achievable projects. Goal owners pitched their ideas to the room, participants selected the work that interested them, and each team demonstrated its progress at the end of the day.
According to the official WordCamp US recap, 425 people participated, including 29 new contributors. Twenty-six teams opened 22 pull requests and shipped 21 contributions across WordPress.
The range of projects demonstrated that WordPress is not standing still. Contributors worked on long-standing needs such as documentation, testing, accessibility, email reliability, and developer tooling. Other teams focused on AI agents, vectorized search, AI literacy, and the way WordPress will communicate with emerging software systems.
What Contributor Day teams worked on
- WP Hosting Test Runner Multi-Environment Reporting: Expanded reporting so hosts can submit WordPress test results from multiple combinations of PHP, databases, and web servers.
- AI Literacy Survey and Dashboard: Created an assessment that gives participants an individual AI-literacy profile while contributing anonymous results to a community dashboard.
- Learn.WordPress.org Contribution Tracks: Developed educational paths introducing contributors to development, design, localization, communications, community work, and event management.
- PHPStan Fixes: Addressed static-analysis errors in WordPress core, creating practical starting points for first-time code contributors.
- WP Photo Directory Importer: Built and documented a plugin for importing images from the WordPress Photo Directory directly into the Media Library.
- Theme Developer Accessibility Feedback: Tested themes submitted for accessibility review and provided developers with practical feedback.
- Notes Activity Widget: Added unresolved editor notes and recent replies to the WordPress dashboard’s Activity widget.
- Script and Style Concatenation: Tested replacing WordPress’s older concatenation system with prefetching and modern browser-loading techniques.
- WebMCP for the Editor: Added support for browser-based AI assistants to perform approved actions within the WordPress administration interface.
- WordPress Email-Delivery Checks: Developed native SMTP settings, a test-email tool, and checks for account, password-reset, and recovery messages.
- Multisite Documentation: Improved the Advanced Administration Handbook using practical feedback from people who operate WordPress Multisite.
- PHPUnit Test Improvements: Investigated slow tests, parallelization issues, and ways to avoid unnecessary test runs.
- Client-Side Media Testing: Built testing tools, assembled sample media, and identified bugs and edge cases in the client-side media system.
- “It’s Not SAD, It’s SAB”: Produced an AI-search and SEO readiness guide for service-area businesses.
- Description List Blocks: Advanced a block-editor implementation of the HTML description-list elements
<dl>,<dt>, and<dd>. - HIPAA and Accessibility Plugin: Explored a WordPress solution intended to help healthcare providers address accessibility and HIPAA-related requirements.
- Vectorized Search: Used the PHP AI Client’s vectorization support to bring semantic search capabilities to the canonical WordPress AI plugin.
- Extensible Visual Revisions: Worked on extension points that would allow developers to add functionality to the visual revisions interface.
- WP-CLI Autoload Improvements: Isolated a long-standing conflict involving Composer,
wp-env, and WP-CLI, then developed potential fixes. - Making Sites for Others: Helped participants turn their ideas into functioning WordPress websites while collecting feedback that could improve WordPress core.
- WordPress AI Guidelines: Created an outline for formal community guidelines covering the responsible use of AI within the WordPress project.
- MCP Adapter’s Path to WordPress.org: Updated installation and migration documentation while preparing the MCP Adapter for the WordPress.org Plugin Directory.
- New Contributor Tool Testing: Tested an emerging contribution tool from the perspective of people making their first WordPress contributions.
- Skills and Benchmarks: Improved WP Bench performance and evaluated the skills AI agents need to work effectively with WordPress.
- WordPress AI Block Map: Built an interactive guide explaining the building blocks in the WordPress Core AI initiative.
- WordPress for Dummies: Examined the terminology and process barriers that make WordPress contribution difficult for newcomers.
- Surgical Edits for WordPress AI: Developed a safer editing ability that lets AI agents replace a precise passage without rewriting an entire post.
The new Contributor Day format felt fast, experimental, and inclusive. It also gave participants a visible finish line. Instead of spending the day discussing what might eventually happen, teams were encouraged to produce something they could demonstrate.
For hosting companies, the work on multi-environment testing was particularly relevant. So were the projects involving AI agents, email delivery, performance, accessibility, and safer content editing. These are not abstract community exercises. They address issues that affect hosting platforms and their customers directly.
Showcase Day connected ideas with practical use
The event continued with a dedicated Showcase Day built around working implementations of WordPress.
Sessions examined real projects and operating websites instead of presenting the platform only in theory. Recurring themes included AI supervision, ownership of the technology stack, structured content, editorial usability, accessibility, security, and the work required after a website launches.
The beginner program gave first-time builders a practical path into the ecosystem. WP 101 participants arrived with a laptop and browser and left with a functioning WordPress site, including pages, a post, navigation, and visual branding. Participants received a copy of their site, hosting, and a domain so they could continue building after the event.
That program gave the first-timer statistic more weight. New attendees were not simply sitting in session rooms. They were building websites, meeting contributors, and becoming potential long-term participants in the WordPress ecosystem.
AI was never far from the conversation. Showcase Day’s opening keynote argued that AI does not eliminate a developer’s responsibilities. Instead, it moves more of the work into defining requirements, supplying context, supervising automated systems, and verifying what ultimately ships.
That same question, how to use AI without surrendering judgment or control, surfaced repeatedly in our conversations with hosting and infrastructure companies.
Porkbun: WordCamp is not a conversion campaign
Our conversation with Eddie from domain registrar and hosting provider Porkbun produced one of the clearest explanations of how companies should evaluate WordCamp participation.
“This is a brand-awareness expense. It’s not a conversion expense,” Eddie said. “If you’re coming here for conversions, I think you’re looking for the wrong thing.”
Porkbun has been making a more deliberate move into the WordPress community. After experiencing the value of direct customer conversations, the company expects to continue participating in WordCamp US and may expand its presence at WordCamp Europe and WordCamp Asia.
Existing Porkbun customers approached the team to ask questions, request help, and share their experiences. That direct access helped distinguish Porkbun from domain registrars that are not physically present in the communities where their customers work.
“This is about meeting your customers where they’re at,” Eddie said. “This is about showing up for the community.”
That presence is particularly useful in the domain industry. Ownership, transfers, renewals, expiration policies, and account responsibilities remain confusing for many website owners.
“Domains are hard,” Eddie said. “There’s a lot of myths and just bad information out there about how domains work.”
Porkbun’s objective is not necessarily to convert every conversation into a transfer. Eddie said the priority is helping people understand and regain control of their domains, even if those domains ultimately remain with another registrar.
“I’m not even necessarily worried about it being at Porkbun so much as they’re taken care of one way or another,” he said.
For WebHosting.Today, Porkbun’s perspective captured an important part of the event’s value. A helpful conversation may not generate revenue during WordCamp, but it can build trust that lasts much longer.
Hosting.com: Hosting companies should support the open web
Corey from Hosting.com framed community involvement as more than a marketing decision. In his view, hosting providers have a responsibility to support the open ecosystems on which their businesses depend.
“Hosting companies should be the best citizens of the web,” Corey said. “We have a vested interest in the open web.”
That responsibility extends beyond WordPress to Joomla, Drupal, and other open technologies. Hosting companies benefit when people can freely create, publish, and operate websites. Supporting the people and projects that sustain that environment is both community participation and long-term business stewardship.
The return is not always immediate or easy to attribute.
“Being there and being part of it is brand awareness and presence,” Corey said. “The ROI might not show up next week. It might be a couple of years. It might be a couple of months.”
Consistent participation sends a message that matters in an industry built around continuity and trust.
“We’re here today, and we’re going to be here tomorrow,” Corey said.
Corey also challenged the idea that softer enthusiasm in parts of the United States means the broader WordPress community is disappearing. He pointed to active communities across Europe, India, Asia, Kenya, Bangladesh, and other regions.
“The embers might have softened in this part of the world, but they’re burning pretty bright in other parts of the world,” Corey said. “I think the fire has maybe shifted, and that’s good.”
Hosting.com sees agencies as part of the customer journey
Hosting.com’s transformation illustrates how relationships formed in the community can become part of a broader partnership strategy.
The company began consolidating more than 40 brands under the Hosting.com name in April 2025. With that process underway, its focus is shifting from the rebrand itself to building an ecosystem around customers and partners.
One initiative is the Agency Success Partner Network, which is intended to connect agencies with Hosting.com customers who need design, development, consulting, strategy, and other services the hosting provider does not necessarily offer directly.
“Instead of asking agencies, ‘What can you do for us?’ we’re asking, ‘Who are you, and what do you do best?’” Corey said.
With more than 700,000 customers, Hosting.com sees agencies as an extension of the customer journey. Hosting.com can provide domains and infrastructure, while partner agencies deliver the specialized services customers need to build and grow.
That model makes the relationship between a hosting provider and the WordPress community more tangible. Community connections can become part of the service a hosting company provides.
AI has arrived, but companies disagree on how far it should go
If community was the event’s most consistent theme, AI was its most unavoidable one.
The official program included an AI track alongside sessions about technical WordPress, professional development, and beginning WordPress. Topics ranged from AI-assisted development and AI search to block-based workflows and preparation for an agentic web.
The discussion is no longer simply about whether AI competes with WordPress. It is about how publishing, marketing, hosting infrastructure, support, and security evolve alongside increasingly capable tools.
Corey from Hosting.com believes WordPress has reached another transition point.
“I think we’re at the stage where we need to reinvent ourselves again,” Corey said.
WordPress helped pioneer democratized publishing on the open web. Its next challenge is preserving that philosophy while making the platform accessible to software agents and AI-driven workflows.
“Whatever it means, from security to the dashboard, get AI in there and make it native,” Corey said.
Hosting.com already uses AI throughout its marketing operations. Corey described it as a tool that can do more than accelerate content production. Used well, it can help marketers understand why a message resonates, how customers perceive a product, and where communication is failing.
Eddie from Porkbun described a more restrained implementation. Porkbun uses AI for productivity, coding assistance, editing, and refinement, but not as a substitute for original human work.
“AI is a tool helping us get things out faster,” Eddie said. “It’s not necessarily replacing the real work that we do.”
Porkbun’s blog posts begin as complete human-written articles. AI may assist during editing, but it does not replace the original author.
BigScoots: AI assists, but humans remain responsible
Zach from managed WordPress hosting provider BigScoots described a similar division between AI assistance and human responsibility.
BigScoots uses AI behind the scenes for infrastructure monitoring and incident diagnosis. Its tools can sometimes identify the likely source of a website problem in about 15 seconds, giving an engineer more context before troubleshooting begins.
The final action remains human.
“It’s still a human logging in and figuring it out,” Zach said. “It’s not a bot or an agent doing it.”
That distinction supports BigScoots’ positioning around 100% human support. AI serves as an intelligence layer for engineers, not an autonomous replacement for them.
Zach remains skeptical of adding complexity simply because AI makes it possible.
“AI will sometimes over-engineer things for no benefit,” he said, pointing to the KISS principle, “Keep it simple, stupid.”
BigScoots’ cautious approach is especially relevant in infrastructure operations. A poorly written marketing draft can be corrected. An autonomous change made across production servers can have much more serious consequences.
CloudLinux: AI agents raise the stakes for security
Eric from Linux operating system and hosting security company CloudLinux offered the sharpest warning about AI operating inside hosting environments.
CloudLinux now considers frequent, severe Linux vulnerabilities part of a “new normal.”
“We pretty quickly assessed that this was a new normal,” Eric said. “I predict a major exploit coming out once a week for the rest of the year.”
Rather than responding only by expanding its security team, CloudLinux has improved its internal processes and automation. After early incidents such as CopyFail exposed weaknesses in the response cycle, the company created repeatable remediation pipelines and customer-notification protocols.
“Once we got kicked over once, we automated that, and then never got surprised by it again,” Eric said.
Communication is part of the security response. CloudLinux uses email, connected Slack channels, status notifications, and Zendesk alerts to tell customers that a vulnerability is known and being addressed, ideally before support requests begin arriving.
That preparation is becoming more important as AI lowers the technical barrier for attackers. AI can assist with vulnerability discovery, automate scanning, generate malicious tools, and accelerate exploitation.
CloudLinux is responding through faster patching, proactive examination of protected software, application hardening, and web application firewall technology designed to filter suspicious traffic.
AI agents operating inside hosting infrastructure introduce another category of risk. An agent with broad credentials could change hundreds of websites or servers almost instantly. Once an organization gives an automated system powerful access, there is only so much an outside security vendor can do.
“If they give away the keys to the access, the worst possible scenario is possible,” Eric said.
His recommendation is to introduce agents slowly, limit their permissions, evaluate each use case individually, and require backups before automated changes occur.
“Go slow and integrate these things on a case-by-case basis, and think about the risk,” Eric said.
His strongest operational recommendation was equally direct.
“Before anything changes, we’re going to make backups, and just make that a requirement moving forward.”
Backups become the final safety mechanism. If an agent makes a catastrophic change, the organization can restore the affected system before investigating what went wrong.
“If they do make one of these showstopper changes, we can go back and then worry about why it happened,” Eric said.
Despite those risks, Eric remains optimistic about AI. The question is not whether hosting companies will use it, but whether they will introduce it with controls appropriate to its speed and reach.
Security is becoming more proactive and layered
Recent vulnerability-response cycles demonstrate how quickly hosting security now operates.
Eddie from Porkbun said the company relies on specialized infrastructure partners, including WP Cloud for WordPress hosting and companies such as WebPros and CloudLinux on the cPanel and Linux side.
In some cases, Porkbun receives a vulnerability notification and almost immediately receives confirmation that the issue has already been patched. Its strategy is to work with organizations that specialize deeply in those technologies instead of reproducing every security capability internally.
BigScoots described a similarly proactive response during recent cPanel vulnerabilities.
“We knew right away about the CVE, and we put blocks in place before cPanel published the update,” Zach said.
BigScoots worked with security partners and internal engineering teams to block attack vectors across shared servers, VPS environments, and other infrastructure while waiting for an official patch.
“It was a coordinated effort,” Zach said. “No one really saw it, but behind the scenes there was a big effort.”
BigScoots also uses its Cloudflare Enterprise-powered Boost service, proprietary traffic rules, and intelligence gathered across its infrastructure to mitigate abusive bots.
Its goal is not to block every automated visitor. Some customers want legitimate AI crawlers to reach their sites so their content can be found through AI search products. The challenge is distinguishing useful automated traffic from malicious activity.
For vulnerable WordPress plugins and themes that cannot be updated immediately, BigScoots uses Patchstack-powered virtual mitigation. Combined with authentication controls, rate limiting, bot filtering, infrastructure monitoring, and human intervention, the result is a layered defense rather than reliance on a single product.
Infrastructure ownership remains a differentiator
Zach also pointed to BigScoots’ ownership of its physical infrastructure as an operational advantage.
“We have control,” he said. “We’re not worried about a cloud contract going up in price six months from now.”
Owning its infrastructure allows BigScoots to manage capacity, anticipate hardware requirements, and control costs without depending entirely on an outside cloud provider. The company ordered equipment in advance of potential hardware shortages and reorganized parts of its infrastructure to improve utilization without passing additional costs to customers.
BigScoots has also expanded beyond its Chicago footprint with infrastructure in Ashburn, Virginia.
The company continues to develop logged-in user edge caching for dynamic WordPress applications. Its support has expanded beyond WooCommerce to include subscription, membership, licensing, publishing, and e-commerce products.
The objective is to cache personalized content closer to visitors through Cloudflare while reducing requests that must return to the origin server.
That work reflects another theme we heard at WordCamp US. AI may be attracting attention, but hosting companies still compete on traditional fundamentals such as performance, capacity, reliability, security, and support.
CloudLinux and BigScoots agree on stronger authentication
When we asked what WordPress core should change next, Eric from CloudLinux and Zach from BigScoots arrived at the same answer, stronger native authentication.
“Two-factor authentication should be a feature of WordPress core,” Zach said. “It shouldn’t be a plugin.”
Eric likewise identified native two-factor authentication and support for security keys or passkey-style authentication as immediate opportunities.
Credential theft remains a major path into WordPress websites. Native support for stronger authentication would give site owners a basic layer of protection without requiring them to select, install, configure, and maintain another plugin.
The agreement was notable. The companies we interviewed differed in their enthusiasm for AI, infrastructure models, and methods of measuring community investment. On the need for stronger default WordPress security, there was little disagreement.
Eddie from Porkbun offered a lighter answer when we asked what he would change about WordPress, its blue color scheme. While unlikely to become a core security roadmap item, the answer reminded us that not every WordCamp conversation has to become an infrastructure debate.
Closing keynote: Simplicity, AI, and open source
The final keynote took the form of a fireside chat between Robert Jacobi, Chief Experience Officer at Blackwall, and WordPress co-founder Matt Mullenweg. Jacobi acted as a voice for the audience, interrupting the presentation with questions and helping move the conversation beyond its prepared slides.
Mullenweg’s central argument was that technology, including WordPress, needs to become simpler. He called for cleaner front-end HTML, introduced shorter WordPress.org profile addresses using w.org/username, and previewed “Piplets,” experimental self-contained applications that store their code and data in a single file.
AI remained a major theme. Mullenweg suggested the industry may be emphasizing the term too heavily when users might better understand many applications as automation. He remained optimistic about AI creating opportunities for independent professionals and small teams, while arguing that open source will remain essential even as code becomes faster and less expensive to generate.
WordPress 7.1 was also released live from the stage. That moment led into a discussion about contribution and whether WordPress should focus less on pledged Five for the Future hours and more on measurable impact, including code committed, tickets resolved, documentation published, and events organized.
Mullenweg also raised the possibility of rewarding broader community participation within the WordPress.org Plugin Directory. He presented the concept as an idea for discussion, not a policy announcement.
One of the keynote’s odder moments came when an audience member asked about the environmental impact of AI data centers. Mullenweg characterized some concerns as misinformation and questioned whether water consumption was as significant as critics claim because some facilities recirculate water.
He then imagined data centers becoming more welcoming civic spaces, potentially incorporating libraries, public areas, or free access to technology. The answer shifted unexpectedly from environmental accountability to architectural possibilities and left the original question only partially addressed.
The keynote ended with a call for WordPress, Drupal, Joomla, and other open-source communities to work together more closely. Mullenweg argued that these projects should learn from one another, share compatible work, and focus less on tribal competition.
It was a fitting conclusion for an event centered on the continuing value of community.
The event closed with signs of continuity and change
WordCamp US concluded with Michael Hammett, Chief Innovation Officer for the City of Phoenix, presenting a proclamation on behalf of Mayor Kate Gallego declaring August 19 “Phoenix WordCamp Day.”
Around the formal program, attendees visited a Merchant Corner featuring Phoenix-area businesses using WordPress, assembled a collaborative LEGO WordPress logo, searched for 48 hidden Arizona-themed Wapuus, and gathered for a closing social.
Those details may appear secondary to product announcements and technical sessions, but they help explain why companies continue to invest in physical events.
Recordings can distribute presentations. Documentation can preserve technical knowledge. Video calls can support scheduled partner meetings. None fully reproduces the density of interactions that occurs when users, contributors, agencies, hosts, security vendors, and platform companies occupy the same space for several days.
What WebHosting.Today took away from WordCamp US
WordCamp US 2026 did not present an ecosystem without challenges.
Attendance patterns are changing. Economic pressure is affecting travel and sponsorship decisions. AI is altering customer expectations while creating new operational and security risks. WordPress must determine how it fits into a web increasingly navigated by software agents as well as people.
But the event also demonstrated that the ecosystem is still moving.
New attendees built their first WordPress sites. Contributors shipped code, documentation, accessibility improvements, testing tools, and AI experiments. Agencies met potential partners. Customers spoke directly with their providers. Hosting companies shared operational lessons. Security vendors prepared for a faster threat environment.
Our interviews reinforced that story.
For Porkbun’s Eddie, the value of WordCamp was meeting customers where they are.
For Hosting.com’s Corey, it was fulfilling the responsibility hosting companies have to the open web.
For BigScoots’ Zach, it was demonstrating how AI can support engineers without removing human control.
For CloudLinux’s Eric, it was an opportunity to discuss the security controls hosting companies will need as AI agents gain access to production infrastructure.
WebHosting.Today’s overall takeaway is straightforward. As the ecosystem changes, the value of community remains stable. It is where partnerships begin, where strategies take shape, and where the open web continues to find its footing.
My personal takeaway is just as direct. Community can’t be on a spreadsheet and AI Security is layered, but at the end of the day, your final line of defense is the latest reliable backup you have.