It still continues to be the easiest to hack, but they are fairly constant with updates. If you pick the right hosting provider and install WP with their tool, the updates are automatically done. I use SiteGround for my photography website and they do that. As mentioned earlier, make sure you have a good backup solution whether from your hosting company or on your own.
For my day job, I built our two websites straight HTML with scripts to avoid the extra security risks, but we also don’t use any special functions on our sites. You can buy HTML templates just as easy if you want to avoid a CMS platform.
WP can be kept secure at a commercial use level but it takes both a time and a cash investment.

