Earlier quoted context omitted.
The WordPress hacking/plugin security issue has been a solved problem for well over 10 years now if you're even basically competent. Especially if you're using something like WP Engine or Pantheon for hosting.
WP Engine etc. cost a fortune - tens of thousands per year when you get a lot of traffic - for something that could be served statically for pennies.
So $30/mo for a secure, globally accessible backend for all of your content editors and pennies to serve it.