The WordPress question, answered straight
WordPress is a great tool. It is the wrong tool for most small business sites in 2026.
No meetings, no proposals - see how the build works or browse example sites
We have built with WordPress for years and we still like it - a lot. But let’s be precise about what it is: a database-driven content system, and a database sitting on the public internet is a job that never ends. Core updates, plugin updates, usernames, passwords, patches. For a local business with three pages and a contact form, it is machinery you do not need and risk you do not want. Here is the reasoning, the receipts, and the cases where WordPress genuinely is the right call.
What WordPress is, and where the problem starts
WordPress is a free, open-source content management system. It launched in 2003 as blogging software and became the default engine for small business sites - at its peak roughly forty percent of the web ran on it. You write pages in a dashboard, and it files them in a database on your hosting server. Themes control the look, plugins add features: contact forms, sliders, SEO tools, booking systems.
Read that again and you have the whole argument. Every WordPress site runs a database, and that database lives on a server connected to the public internet. Not in a locked office. On the internet, where outsiders can knock on every door.
A database online is an attack surface
If something is reachable from the web, someone is probing it. WordPress admin pages sit at predictable URLs, and automated botnets scan the same few million sites around the clock - the login page, the plugin directory, the database name, the version file. They are not singling you out. A landscaper in Ohio with a WordPress site two years out of date is simply one of millions of machines being rattled, every night, for whatever falls out.
Almost no WordPress compromises are human break-ins. They are automated scans that find an outdated plugin or a weak password and take it from there. Then the site serves spam, redirects visitors to scam pages, or joins a botnet - often for months before the owner notices.
In 2026, the database is a duty, not a feature
- 01
The work never stops. WordPress core keeps shipping versions, every plugin you installed keeps shipping versions, and every other month one of them is sealing a security hole. Passwords need rotating. Admin accounts need pruning. Backups need testing. And a site is only as current as its oldest plugin - the one you forgot you installed.
- 02
Walk away for six months or a year, the way most owners do once the site is "done", and each missed update is a door left open. The scans find it eventually. Auto-update exists precisely because the system cannot be left alone, and even it only patches what was known at the time the patch shipped.
- 03
So the fair 2026 question: does a three-page brochure site need a live database? A database exists to publish changing content. A local business site changes its phone number twice a year.
When WordPress is still the right answer
To be clear: we are not WordPress haters. It is one of the most important software projects of the internet era, we have built with it for years, and we recommend it in the right circumstances weekly.
That is: tens of thousands of pages or products; teams of authors with real editorial pipelines; e-commerce at serious scale; or a niche plugin ecosystem that would be impractical to rebuild. It is also: a business with a full-time person - developer, sysadmin, agency on retainer - whose job is to update it, monitor it, back it up, and notice when something is off. WordPress with a dedicated keeper is a superb platform. This is not up for debate.
What it is not, in 2026, is the right default for a local business with three pages and a contact form, bought once and then forgotten. For that job the database is mostly liability.
The receipts, from the last two years
This is not doom-mongering. WordPress 6.7 shipped in November 2024, and 6.7.1 followed within roughly two weeks as an emergency security release, patching a vulnerability that arrived inside the update itself. In 2024, the WP-Automatic plugin had a SQL injection vulnerability disclosed - researchers counted over a million exposed sites, exploited in the wild before many owners knew the plugin existed.
Through 2025, campaigns injected cryptocurrency-stealing redirects into thousands of neglected WordPress sites in a single sweep. Not sophisticated intrusions - known exploits replayed against installs nobody had patched, some three, four, eight versions behind. The sites sat there serving junk to visitors and to Google.
And AI is accelerating it. Attackers use AI to scan for weaknesses and draft working exploits faster than the patch cycle turns. Those scans run against every WordPress site on the internet - including the one you were told would be fine.
What a cheap WordPress build actually is
Here is what a few hundred dollars of WordPress actually buys. A developer buys or downloads a theme, restyles it with your logo and colors, and installs the usual free plugins - forms, SEO, security, caching, maybe a slider. Handled properly, it is a perfectly good website.
The catch is the maintenance ledger. One theme plus six or eight plugins is seven to nine separate update queues, and every one is a possible break or a possible entry point. The free open-source plugins are not the problem - professionals use them with monitoring tools every day. The monitoring is the job. If nobody is being paid to do it, and the developer has moved on to the next customer, you are holding a countdown.
What you get instead, and why we chose it
Our sites are hand-coded and static. No database on the internet means nothing to brute-force, no plugin queue to run, no login page for scanners to find, no update that can ship a new vulnerability. A static page is a file being fetched - it loads in roughly the time it takes to download it, typically ten times faster than the same page on WordPress, and it cannot break after an update that does not exist.
Want to edit your own copy? The optional CMS add-on is a simple Pages CMS over the same hand-coded files. Your changes publish straight into the site - they are not saved in a database on a server, because there is no database. That is the whole safety story in one sentence.
For 99 percent of small businesses in 2026, the right tool is a fast static site nobody has to maintain - precisely what the flat $500 USD buys, with the files and the domain in your name. And if you are set on WordPress, understand the upkeep, and want one anyway: we can build and maintain that too, properly scoped through our agency Underdog Digital rather than squeezed into a flat fee.
Straight answers.
No hedging, no fine print. If it is not here, email us - a human replies.
[email protected]Is WordPress unsafe?
Does auto-update fix all this?
I have run WordPress for years and nothing ever happened.
Can I still get a WordPress site from you?
Set on WordPress anyway? That is a legitimate choice for some businesses, and we will not argue you out of it. We build and maintain WordPress sites too - properly scoped, through Underdog Digital.
The website your business actually needs has no database in it.
Flat $500 USD. Three hand-coded pages, live, secure, yours to keep. No constant updating required.