The WordPress question, answered straight

WordPress is a great tool. It is the wrong tool for most small business sites in 2026.

No meetings, no proposals - see how the build works or browse example sites

No database to hack
Nothing to patch, ever
Roughly 10x faster loads
Yours to keep

We have built with WordPress for years and we still like it - a lot. But let’s be precise about what it is: a database-driven content system, and a database sitting on the public internet is a job that never ends. Core updates, plugin updates, usernames, passwords, patches. For a local business with three pages and a contact form, it is machinery you do not need and risk you do not want. Here is the reasoning, the receipts, and the cases where WordPress genuinely is the right call.

The system

What WordPress is, and where the problem starts

WordPress is a free, open-source content management system. It launched in 2003 as blogging software and became the default engine for small business sites - at its peak roughly forty percent of the web ran on it. You write pages in a dashboard, and it files them in a database on your hosting server. Themes control the look, plugins add features: contact forms, sliders, SEO tools, booking systems.

Read that again and you have the whole argument. Every WordPress site runs a database, and that database lives on a server connected to the public internet. Not in a locked office. On the internet, where outsiders can knock on every door.

The risk

A database online is an attack surface

If something is reachable from the web, someone is probing it. WordPress admin pages sit at predictable URLs, and automated botnets scan the same few million sites around the clock - the login page, the plugin directory, the database name, the version file. They are not singling you out. A landscaper in Ohio with a WordPress site two years out of date is simply one of millions of machines being rattled, every night, for whatever falls out.

Almost no WordPress compromises are human break-ins. They are automated scans that find an outdated plugin or a weak password and take it from there. Then the site serves spam, redirects visitors to scam pages, or joins a botnet - often for months before the owner notices.

The upkeep

In 2026, the database is a duty, not a feature

  1. 01

    The work never stops. WordPress core keeps shipping versions, every plugin you installed keeps shipping versions, and every other month one of them is sealing a security hole. Passwords need rotating. Admin accounts need pruning. Backups need testing. And a site is only as current as its oldest plugin - the one you forgot you installed.

  2. 02

    Walk away for six months or a year, the way most owners do once the site is "done", and each missed update is a door left open. The scans find it eventually. Auto-update exists precisely because the system cannot be left alone, and even it only patches what was known at the time the patch shipped.

  3. 03

    So the fair 2026 question: does a three-page brochure site need a live database? A database exists to publish changing content. A local business site changes its phone number twice a year.

The honest bit

When WordPress is still the right answer

To be clear: we are not WordPress haters. It is one of the most important software projects of the internet era, we have built with it for years, and we recommend it in the right circumstances weekly.

That is: tens of thousands of pages or products; teams of authors with real editorial pipelines; e-commerce at serious scale; or a niche plugin ecosystem that would be impractical to rebuild. It is also: a business with a full-time person - developer, sysadmin, agency on retainer - whose job is to update it, monitor it, back it up, and notice when something is off. WordPress with a dedicated keeper is a superb platform. This is not up for debate.

What it is not, in 2026, is the right default for a local business with three pages and a contact form, bought once and then forgotten. For that job the database is mostly liability.

The receipts

The receipts, from the last two years

This is not doom-mongering. WordPress 6.7 shipped in November 2024, and 6.7.1 followed within roughly two weeks as an emergency security release, patching a vulnerability that arrived inside the update itself. In 2024, the WP-Automatic plugin had a SQL injection vulnerability disclosed - researchers counted over a million exposed sites, exploited in the wild before many owners knew the plugin existed.

Through 2025, campaigns injected cryptocurrency-stealing redirects into thousands of neglected WordPress sites in a single sweep. Not sophisticated intrusions - known exploits replayed against installs nobody had patched, some three, four, eight versions behind. The sites sat there serving junk to visitors and to Google.

And AI is accelerating it. Attackers use AI to scan for weaknesses and draft working exploits faster than the patch cycle turns. Those scans run against every WordPress site on the internet - including the one you were told would be fine.

The cheap build

What a cheap WordPress build actually is

Here is what a few hundred dollars of WordPress actually buys. A developer buys or downloads a theme, restyles it with your logo and colors, and installs the usual free plugins - forms, SEO, security, caching, maybe a slider. Handled properly, it is a perfectly good website.

The catch is the maintenance ledger. One theme plus six or eight plugins is seven to nine separate update queues, and every one is a possible break or a possible entry point. The free open-source plugins are not the problem - professionals use them with monitoring tools every day. The monitoring is the job. If nobody is being paid to do it, and the developer has moved on to the next customer, you are holding a countdown.

The alternative

What you get instead, and why we chose it

Our sites are hand-coded and static. No database on the internet means nothing to brute-force, no plugin queue to run, no login page for scanners to find, no update that can ship a new vulnerability. A static page is a file being fetched - it loads in roughly the time it takes to download it, typically ten times faster than the same page on WordPress, and it cannot break after an update that does not exist.

Want to edit your own copy? The optional CMS add-on is a simple Pages CMS over the same hand-coded files. Your changes publish straight into the site - they are not saved in a database on a server, because there is no database. That is the whole safety story in one sentence.

For 99 percent of small businesses in 2026, the right tool is a fast static site nobody has to maintain - precisely what the flat $500 USD buys, with the files and the domain in your name. And if you are set on WordPress, understand the upkeep, and want one anyway: we can build and maintain that too, properly scoped through our agency Underdog Digital rather than squeezed into a flat fee.

WordPress, asked plainly

Straight answers.

No hedging, no fine print. If it is not here, email us - a human replies.

[email protected]
Is WordPress unsafe?
Not inherently - it is safe when actively maintained. Actively maintained means core updates, plugin updates, password hygiene and monitoring, forever, by someone responsible for it. A static site removes the entire category of risk by removing the database and the plugin stack.
Does auto-update fix all this?
It covers what developers already knew about. It cannot cover a vulnerability shipped inside a new update (6.7's emergency 6.7.1 patch was exactly that), an abandoned plugin still sitting installed, or a password already leaked. Auto-update reduces the work; it does not remove it.
I have run WordPress for years and nothing ever happened.
It may be luck, or it may be that nobody looked. A large share of compromised sites serve junk for months before the owner notices - falling traffic, not a dashboard alert, is usually the first sign. When did you last check the version, the plugins and the logs?
Can I still get a WordPress site from you?
Yes. If WordPress is a firm requirement for your business, or you have an existing site you must keep, we can build and maintain it through Underdog Digital. This page exists to make the choice honest - not to turn down the work.

Set on WordPress anyway? That is a legitimate choice for some businesses, and we will not argue you out of it. We build and maintain WordPress sites too - properly scoped, through Underdog Digital.

The alternative

The website your business actually needs has no database in it.

Flat $500 USD. Three hand-coded pages, live, secure, yours to keep. No constant updating required.

No database
Nothing to hack, ever
Nothing to update
No plugins, no patch Tuesdays
Full ownership
Code and files are yours
Worldwide delivery
Built remotely, delivered cleanly
Before checkout

Quick answers

Is it flat rate? Yes. The website is one payment. CMS is optional +$100.

$500 covers a custom, hand-coded website of up to three pages, responsive design, a working contact form, technical SEO foundations, launch hosting, SSL, baseline security, and 30 days of post-launch support. There are no mandatory platform subscriptions or agency retainers. Add the CMS only if you want to edit page content yourself.

See exactly what the price includes
Do I own the site? Yes. All files, all code. No lock-in.

You receive the source code and website files outright. Your domain stays registered in your name, and the site is not tied to WordPress, Wix, Squarespace, Webflow, or a proprietary page builder. Move hosts or hire another developer whenever you like.

See what is included and excluded
Revisions? Two rounds of reasonable tweaks after launch.

Both rounds cover reasonable copy changes, presentation tweaks, and layout adjustments inside the agreed design. Extra pages, new functionality, major integrations, or a completely different design direction are quoted separately.

See the full build process
Buy Now - $500