01Three stacked reasons

Share

Around forty percent of the web runs WordPress, so every attack script is written for it first.

Plugins

Tens of thousands of third-party components of varying discipline. One abandoned plugin is a door, and the average site runs dozens.

The serving model

PHP executes per request, a database sits behind it, and an admin login faces the internet. Landed attacks persist.

02Three stacked reasons

03Three stacked reasons

New here? Start at the pillar page for the full picture.

Share. WordPress runs roughly forty percent of the web, so every attack script is written for it first. That explains the volume of attempts.

Plugins. Tens of thousands of third-party components with wildly different security discipline. One abandoned plugin is a door, and the average site runs dozens. An application firewall lowers the odds per month. It cannot make them zero while the door count keeps changing.

The serving model. PHP executes on the server for every request, the database sits behind it, and an admin login faces the internet. When an attack lands, code persists where it landed. That is why a cleaned site keeps getting reinfected.

04Why hardening only gets you so far

Fewer plugins, strong logins, a firewall, prompt updates: all real, all worth doing, and all of it lowers probability rather than removing the category. The model keeps executable third-party code, a public login and a database in the serving path. As long as those stay, staying safe is a permanent job with a failure rate. Some owners run that job happily for years. Others get hit twice in a year and start reading comparison pages.

05What removing the model does

A static site serves files. No code executes per visitor, the database is gone, and there is no site login to attack. A compromise would mean your repository or your host account was taken, which is a different, rarer and auditable class of problem. The side-by-side shows the surfaces next to each other. The trade is editing flexibility, and the maintenance angle is where most people feel it first.

06Frequently Asked Questions

Are static sites unhackable?

No, and anyone selling that is lying. The attack path shrinks from "any installed plugin, reachable by any visitor" to "your GitHub account or host account". Smaller, rarer, and defended by providers whose job it is, rather than by your monthly vigilance.

Do security plugins fix the problem?

They scan, block and alert, and on a site you are keeping they earn their keep. They also run inside the PHP environment they are protecting, and they add to the update surface.

Is the database the main risk?

It is where injected spam lives and what attackers dump, and it exists because WordPress stores content dynamically. Static sites serve the same content as files, so there is nothing to dump.

Does HTTPS help here?

It protects the connection, not the application. Nearly every hacked WordPress site has a valid certificate. Necessary, and unrelated to break-ins.

Build it with your AI. Host it here.

Deploys on every push, from Australia, with nothing to maintain.

Start free