Static websites: a smaller attack surface, not immunity
A brochure site does not always need a public CMS, a database and a collection of plugins. Pre-built pages can remove unnecessary moving parts. That is a useful security choice, not a promise that a site cannot be compromised.
What static means
The pages are built in advance and served as files. Visitors do not need a database query or a server-side CMS to read each page. Depending on the architecture, the editor or content source can live separately from the public site.
What risk it reduces
Removing a publicly reachable CMS, admin login and runtime plugins removes those particular attack paths. Static files can also be cached close to visitors, making routine traffic easier to serve.
It does not remove the domain registrar, DNS, hosting account, source repository, build pipeline or dependencies used to publish the site. An attacker who controls deployment or DNS can still change what visitors see. Third-party scripts can be compromised. A contact form may call a dynamic backend with its own vulnerabilities and data-handling obligations.
What still needs looking after
- Strong sign-in, least-privilege access and usable recovery for the domain, hosting and deployment accounts.
- Dependency review and updates to the build system, with secrets kept out of public files.
- DNS, TLS, domain renewals and relevant security headers.
- Forms, external scripts and integrations, including rate limits and data handling.
- Recoverable source and configuration, plus a tested way to redeploy a trusted version.
When a CMS is the better choice
Frequent publishing, editorial workflows, memberships and shops often justify a maintained CMS or application. A static front end with external services is another option, but the services still need security review. Choose around the actual workflow, not a claim that one architecture is invulnerable.
How OpsHelp helps
We still build and maintain websites. Our Web & Infrastructure Security Assurance looks beyond the page renderer at the systems and access that support it, including non-WordPress applications. If a site is already compromised, use the urgent help path within security assurance.