A couple months ago now, the internet was abuzz with news that Anthropic was holding back its latest model, Mythos, from public consumption. The newest AI from America's most cutting edge frontier lab was simply too powerful. Supposedly, Mythos exposed new cybersecurity vulnerabilities at such a scale that releasing it could be disastrous and companies needed forewarning to harden their systems prior to release.

To quote the NBC News story on the delayed release:

Experts and software engineers warn that Anthropic's new AI model could usher in a new era of hacking and cybersecurity as AI systems capable of advanced reasoning identify and exploit a growing number of software vulnerabilities.

I am skeptical that Mythos was predominantly delayed due to security threats. I don't doubt the power of the models, but it seemed more like a marketing ploy to me. However, even assuming we are in an AI bubble and much of the industry is getting high on its own supply, one of the clear use cases for AI agents now and in the future will be hardening and exploiting cybersecurity vulnerabilities.

This is why you saw influencers like Elizabeth Holmes (tweeting from her jail cell) and Derek Thompson of Abundance fame warning to scrub your inboxes and delete your passwords.

A cybersecurity reckoning is coming

Horse and buggy software, lazy code, and unsophisticated applications (think WordPress plugins) are all on the chopping block. There is a retail cybersecurity reckoning coming and it's going to smash a lot of law firm websites.

Why?

Because most law firm websites have unresolved gaping security holes.

Why law firms are on WordPress

Most of these sites are built on WordPress because "it's good for SEO." Yes, WordPress has long been a great CMS for publishers. You can install plugins from third party developers like Yoast which easily handle indexation settings, append pages in a paginated folder with the proper canonical tags, insert schemas, and even use AI to write meta descriptions and page titles.

Some WordPress plugins are legitimately useful.

But as the demand for these sites grew so too did the number of developers offering WordPress websites for clients. There are only a handful of good WordPress developers out there and they charge more than full stack engineers, which tells you that this market is begging to be disrupted. Industry leaders aside, most of the devs knew just enough to be dangerous and couldn't build on WordPress without hacking together a series of low quality plugins which are often incompatible with new versions of WordPress as they roll out.

For example, there are whole plugins that exist because an "engineer" couldn't write ten lines of code.

One site, 25 plugins

I have a client site that we are transitioning away from WordPress that has 25 plugins. All with their own code base that has to be maintained by someone, and updated by someone. Many are inactive. Some were added to perform a task one time, like WordPress Importer, and are left in the code base for no reason.

Examples: Widget CSS Classes adds a CSS class to a widget. WP-ShowHide makes a toggle. Page navi slider does pagination. Auto Post Thumbnail grabs the first image in a post. Every one of these is a small function in functions.php or a few lines of CSS.

A deactivated plugin is not a removed plugin. The code still lives in the /wp-content/plugins/ folder, only it no longer gets security updates.

The only reason legal marketing agencies keep building sites on WordPress is because they lack the engineering chops to build on something cleaner like Astro.

The ethics problem for lawyers

And the bill for lawyers is coming due soon. Vulnerability discovery is accelerating and with it many of these hacked together law firm WordPress sites will be compromised. This is an issue for lawyers in particular because of the ethics considerations.

ABA Model Rule 1.6(c) requires reasonable efforts to prevent unauthorized disclosure of client information, and Comment 8 to Rule 1.1 puts technology competence inside the duty of competence.

With many firms having harvested hundreds or thousands of client contacts, often with sensitive information, via built for WordPress contact forms, the issue is potentially enormous.

How Associate helps

WordPress security issues, even glaring ones, are often overlooked by agencies because they aren't a "KPI" driver. One of the things we built into Associate is the ability to scan a WordPress install and identify out-of-date plugins and plugins that are no longer supported. Patching these errors is encompassed within our Work order system. The user can assign the task to their IT professional or marketing agency, or hire us to make the fix. The hard conversation is often that the theme needs to be rebuilt to remove dependency on low-quality plugin libraries. When we go in that direction, I usually opt for Astro over WordPress.

The Law Firm WordPress security crisis is coming. Is your firm ready?

Try Our AI Agent Built for Law Firms

Want this running on your firm’s site? Request access →