PROTECT MY WP

WordPress vs Squarespace: Security Compared

By 12 min read

In July 2024, a dozen or so companies woke up to find their domains no longer belonged to them. They were Squarespace customers. Nobody had guessed a password, and no server had been broken into. The accounts had simply been migrated from Google Domains in a way that let someone else claim the admin email address first.

I start there because it is the most useful thing in this comparison, and because it is the part the marketing pages on both sides skip. The usual WordPress versus Squarespace argument is about plugins and patching. The incident that actually cost Squarespace customers their businesses was about account recovery, which is the layer nobody puts in a comparison table.

So this post is organised around where each platform's security actually fails in practice rather than where the feature lists differ. It's current for July 2026, and I have nothing to sell you either way.

Short version, if you want it up front: Squarespace's platform security is genuinely good and its account security has a documented weak spot. WordPress inverts that. Which one is safer depends less on the platform than on which of those two failure modes you are equipped to handle.


Draw the line around what you own

Every hosted platform draws a line. On one side is what they secure, on the other is what remains yours. The comparison only makes sense once you know where Squarespace's line sits, because everything they own is a problem you will never have, and everything you own is a problem they will never solve for you.

On Squarespace, what remains yours is smaller than most people assume, and specific: your account credentials, your Extensions installs, your DNS and domain settings, and anything you paste into Code Injection or Code Blocks. Everything else, the servers, the CMS, the database, the network, the CDN, the TLS certificates, patching, DDoS mitigation, 24/7 SOC monitoring, is behind the line and not your problem.

Note what is on your side of that line, though. DNS and domain settings, and the account that controls them. That is precisely where July 2024 happened. The line is drawn in a sensible place, but the sliver left to you contains the keys to everything else.

On WordPress the line barely exists. You pick the host, install the CMS, choose the theme, add the plugins, and own the upkeep of all of it. That is a far larger surface, and it is the honest reason WordPress sites get compromised more often. It is also why no Squarespace-style incident can happen to you without your involvement: there is no migration process between you and your registrar that you did not set up yourself.


What Squarespace does better than WordPress

A lot of pro-WordPress writing pretends the advantages only run one way. They don't, and two of the items below are things WordPress cannot match at any price.

Put those together and a pattern emerges: Squarespace is strongest exactly where inattentive owners are weakest. An unmanaged WordPress site run by someone who will not log in again for a year is genuinely riskier than the Squarespace equivalent. That is not magic, and it is not marketing. They have removed the surfaces where non-experts reliably fail, and then, in the passkey and re-authentication work, gone further than most of the sector on the surface that is left.


Back to July 2024, in detail

Which brings us to the exception, and the reason it belongs at the centre of this comparison rather than in a footnote.

Between the 9th and 12th of July 2024, a coordinated wave of domain hijackings hit Squarespace customers. Compound Finance, Celer Network, Pendle Finance, Unstoppable Domains and around a dozen other companies (mostly in crypto and web3) had their domains taken over. The attackers had exploited a weakness in Squarespace's migration of Google Domains customers over to its own registrar. They pre-registered admin email addresses they'd guessed from public data, then used those addresses to take over the migrated Squarespace accounts. Researchers reported that 2FA was effectively disabled on migrated accounts. Squarespace's own post-mortem, published on 23 July 2024, blamed "a weakness related to OAuth logins" and said it was fixed within hours.

Two things are worth taking from this. One, no CVE-tracked platform vulnerabilities or major breaches surfaced in the year since, in the reputable coverage I could find. So the response held. Two, the design choice underlying the incident (email addresses not validated at account creation) is still there. If you're running a site of any real value on Squarespace, that's a good reason to make sure the email address on the account is one only you control, on a domain you control, and that 2FA is on with a hardware key or a passkey.

I'd hold this against Squarespace less than the internet did at the time. It was a migration edge case, not rotten engineering, and the fix was fast. But it demonstrates the thing worth understanding about hosted platforms generally. When the failure is on their side of the line, you do not get to patch it, you do not get advance warning, and you find out when your domain stops resolving. That is the trade you are making, and it is a reasonable trade. It is just not the trade the comparison articles describe.


What WordPress does better than Squarespace

The other direction, which also has to be said honestly.

Notice these are not really security features. They are control, ownership and the ability to respond. On a good day that distinction does not matter at all. It matters entirely on the day something goes wrong, which is the only day security is ever measured.


Three things the comparison usually gets wrong

A few areas where the standard version of this argument misleads people in both directions.


So which one

If security is the deciding factor, the choice comes down to which failure mode you are actually equipped to handle: neglected maintenance, or no control when the platform slips.


Where this fits

Everything above assumes the WordPress option comes with a maintenance habit attached. That habit is what the Protect My WP handbook is. Fourteen chapters covering the server, the core, the users, the files, the database, HTTPS, the firewall, plugins, performance, monitoring, backups, AI agents, and the maintenance workflow that keeps a site on the right side of this comparison rather than becoming the neglected install everyone warns you about.

Chapter 3 is the one most relevant to the story this post opened with. Account security, enforced two-factor, and controlling the email address and domain that everything else recovers through. The July 2024 lesson applies to WordPress too, and the people who came through it fine were the ones who had already done that work.

Get the book for £19.

More on this topic

Want to go deeper?

The first chapter of Protect My WP is free. Start with the foreword, then read Chapter 1 on hosting and server security. There is also a shorter guide that walks the same ground faster if you want the shape of the book first.