They’re explaining how seriously they take security using Wordpress.
I know that WordPress doesn't have the greatest security record, but it seems unfair to judge an organization for using WP. Many, many respectable businesses use WordPress for their brochureware or corporate blogs. In my experience, it's not a security nightmare if it's well maintained.
> I have had the same issue with the plugin. This was on a simple WooCommerce site with a few thousand products. Notice it incurred over $6,000 in fees.
> Amazon CloudFront Invalidations $6,485.76 > $0.000 per URL – first 1,000 URLs / month.1,000 URL$0.00 > $0.005 per URL – over 1,000 URLs / month.1,297,151 URL$6,485.76
After a user reporting a plugin costing his business over 6000 USD, months go by without proper attention to this issue. If there was good quality control, the plugin should have been pulled. It just shows how the ecosystem is not designed with robustness and security in mind.
But I agree, WP cannot be a proxy to judge how companies treat security. This just illustrates how bad WP itself is.