Or, perhaps the author was tired of random wordpress updates breaking stuff and declined to install updates to a working system. Further, the wordpress people can't be arsed to indicate which updates are for security and which updates are for more stupid features. so unless you go through the release notes line by line for the software and all your plugins, it's very difficult to tell.
More and more, the solution seems to be static files and disqus.
If you choose to use a product like Wordpress, then you should also accept the maintenance that goes with that choice, tedious and annoying though it may be.
Installing a product, running a business on it, but ignoring patches and updates is flat out unprofessional.
More and more, the solution seems to be static files and disqus.