Also: “The reason WordPress sites don’t get hacked as much anymore is we work with hosts to block vulnerabilities at the network layer, […]” — as opposed to not putting the vulnerabilities in⁰ in the first place!
----
[0] Though I've not worked with WP for a long time. I'm told the quality control of the core product has improved a lot over the years and people still running old versions, and/or with unverified extensions, is a large part of the current level of issues.