Security

Security: Builders vs Static Delivery

A static file cannot be SQL-injected. That is not the whole security story, and it is still a better default.

What the public internet can touch

A WordPress site exposes PHP, a database, an admin login, and every plugin’s attack surface. Hosted builders expose the vendor’s multi-tenant application. A static site exposes files and the few endpoints you intentionally created, such as a form handler.

Fewer public inputs means fewer emergency updates.

Admin logins are a target

The WordPress login and many builder accounts are scanned constantly. A static site does not have a public content login unless you add one. Editing happens in Git or in a separate CMS that is not required to render the page.

That separation is a security design, not an inconvenience.

Static is not magic

A leaked API key, a bad form handler, or a compromised deploy account can still hurt. Dependencies still need review.

The claim is narrower and stronger: the public site should not include a CMS runtime it does not need.