Do you still need WordPress?
Many sites run WordPress to serve the same content to every visitor. What does that cost in speed, security and upkeep, and what can you use instead?
A 5 minute read by Damien Guard, Engineering & Ops
For several years my sites ran on WordPress: my personal blog, customer sites, side projects. In those early, less busy and less malicious days it worked well. Occasionally my blog would get featured on Slashdot or Boing Boing and struggle under the load, which sent me off tuning it with HHVM, MariaDB and WP Super Cache so it would survive next time.
Eventually it did. But with a dedicated $90-a-month server and carefully tuned settings, I was spending more time running the site than writing for it. Keeping up with versions, security patches and plugin vulnerabilities was a game of whack-a-mole.
It was time for a change, and I was sure it didn't involve WordPress. If your content is the same for every visitor, you probably don't need it either.
What does WordPress do on every visit?
WordPress is a powerful, flexible engine. But if you serve the same content to everyone, you have to ask why you're using a dynamic engine for what is essentially a static site. Static here doesn't mean the content never changes, only that it doesn't vary by visitor.
Every request starts PHP and runs the WordPress code. The plugins run, MySQL answers a batch of queries, the templates load and the HTML is assembled and sent. The next visitor triggers all of it again, to produce the same HTML. You pay that overhead, and the premium for running PHP, on every single page request.
A static site generator does that work once per content update. During your build it generates every page as HTML, and you upload the files to the simplest of web servers. You can still use JavaScript for dynamic touches, but no server-side code runs when someone visits.
Is a static site faster?
Yes, and of this there is no debate.
With no server-side code to run the server is just pulling HTML files from disk (or in-memory cache) and streaming them to the browsers (or bots) requesting them.
Is a static site more secure?
Yes. You can't hack something that isn't there.
WordPress is a large codebase (almost a million lines at last count), and every plugin adds thousands of lines more. Every module, file or modification is another chance for a vulnerability to sneak in: a tired plugin author making a genuine mistake, or a maliciously compromised dependency upstream. This isn't theoretical - there were 1,275 common vulnerabilities and exposures (CVEs) for the ecosystem in September 2026 alone, according to Wordfence's vulnerability database, including 12 in the core WordPress product.
You might think you can stay up to date with patches. Unfortunately, sometimes zero-day vulnerabilities hit where hackers find out before the people maintaining the code do. At other times, staying up to date means you loaded up a malicious version of a plugin before anyone noticed. It's a trade-off with no good option.
For me the security crunch was finding out my personal blog had been hit by an automated hack while I slept. The vulnerability wasn't public when I had gone to bed.
Is a static site cheaper?
The simple nature of these files means it can be. As long as you have a cheap or free host you can run the build process on (you can even do it locally if you want) then the only real costs are serving up static files and it doesn't get any cheaper than that.
You can also use very cheap, or free, highly scalable hosting. Cloudflare is my current choice and I've never paid to host any of our static sites. Before that I used Amazon S3, where it was hard to exceed the free tier. Both offer content delivery networks (CDNs) that sit in front of your files and serve them from a location near each visitor.
When is WordPress still the right choice?
If you want a lightweight personalised experience for signed-in users or members, WordPress and other dynamic tools will give you that and WordPress might be worth the cost. Especially if it's bringing in revenue and you're prepared to spend some of that on tools, monitoring, backups and hosting to keep it all in check.
WordPress certainly has other things going for it too. Editing content, uploading and publishing is pretty good and easy-to-use and there's probably a plugin for every feature you could want. WordPress gives you the power to do almost anything, including breaking your site. That flexibility can become a problem when staff change, because someone arriving with "WordPress experience" may not understand how your templates, plugins and customisations fit together. But there's no denying the power.
Some popular static site generators
I'm not alone in being lured by static sites, or there wouldn't be such a plethora of static site generators available.
My first after WordPress was Jekyll, which integrates well with GitHub Pages. I got along with it for a while, but its template-focused approach trades simplicity for power. You learn Jekyll's templating and can do whatever that language allows. Want custom paging? You have your work cut out. Reading-time calculations? Better hope there's a plugin.
Thankfully there's a wide range to choose from, with different abilities, trade-offs and languages to suit.
Hugo
Go
Good for
Large content sites, speed
Astro
JavaScript / TypeScript
Good for
Content sites with some interactivity
Jekyll
Ruby
Good for
Simple blogs, GitHub Pages
Nuxt Content
Vue / TypeScript
Good for
Vue teams; sites built from Markdown and data files
Next.js (static export)
JavaScript / React
Good for
React teams; sites with a lot of app logic
Eleventy
JavaScript
Good for
Flexible, minimal sites without a framework
Nuxt Content is personally where I landed, and it's what this site and most of my customer sites are built with. It uses Vue's binding system, so you write HTML with a few annotations on how it binds to data, like Jekyll's templates, but you also have the full power of JavaScript to add the little flourishes that make a site stand out.
How to get started
If you're interested in migrating, these steps will get you started:
- Audit your existing content, see what's worth keeping
- Export that content and convert it to Markdown
- Choose a static site generator that aligns with your abilities
- Set up a new site in that stack with your content and play!
Claude Code and other AI agentic tools are great at working with these generators from setting up new pages and design to fixing up your markdown, so it may take less time than you expect.
Once you've done that you need to decide on a build host (GitHub Actions perhaps) and a web host (almost any provider will do) to put it up on a preview URL.
Where next
Now, of course, the one thing you are going to find is that editing markdown files is not as smooth an experience as WordPress and that's where we can help. Check out our Intracia product to see what the experience can look like.
About the author
Damien has spent three decades building the tools other developers depend on — Entity Framework at Microsoft, the Atom editor at GitHub and SDKs at Auth0 — and runs engineering and operations at Intracia.
Read his full profile


