Get a quote

Traditional versus static websites

Two ways to deliver the same website. One builds every page while the visitor waits. The other has already built it.

WordPress vs Static Website An animated explainer in seven scenes. 1: WordPress generates pages on demand with PHP and a database, while a static site serves pre-built files from a CDN. 2: A WordPress request passes six stops - visitor, DNS, web server, PHP runtime, database, response - and time to first byte builds up at each, about 700 milliseconds for an uncached page. 3: A static request has one stop - visitor, global CDN, response - around 50 milliseconds. 4: Security: WordPress exposes plugins, themes, PHP, SQL, logins, XML-RPC and uploads; a static site removes them, leaving only DNS and the CDN account to protect. 5: Performance: static pages skip PHP execution and database queries entirely and are served from the nearest edge. 6: Cost: hosting, backups, maintenance and security all cost less without servers to rent, back up and patch. 7: Summary: faster, more secure, lower cost, easier to maintain, better scalability. WordPress vs Static WebsiteWhy converting a traditional WordPress site to a static site pays off01 / 07WordPressdynamicStatic websitepre-builtvsPages are generated on demandPHP and a database run for every requestPages are pre-built filesServed from a global CDN, close to the visitorSix quick comparisons: request flow, security, performance, cost and upkeep. Traditional WordPress request flowWhat happens every time someone opens a page02 / 07Visitoropens a pageDNSdomain lookupWeb ServerTLS + routingPHP Runtimetheme & plugins runDatabaseSQL queriesResponseHTML assembledTime to first byte builds up at every stopDNSServerPHP executionDatabase queriesResponse≈ 700 ms6 stops per visit. PHP runs and the database is queried every single time.Timings are typical for an uncached page and illustrative Static website request flowThe page already exists as a file. Nothing is computed on the way.03 / 07Visitoropens a pageGlobal CDNedge location nearest to the visitorResponsepre-built HTML fileTime to first byte, same scale as the previous sceneWordPress≈ 700 msStatic≈ 50 ms1 stop. No code runs and no database is touched. The page is already built. Security: attack surfaceEvery moving part is something an attacker can probe04 / 07WordPress siteStatic siteYour siteYour sitePlugin flawsTheme exploitsOutdated PHPSQL injectionLogin brute-forceXML-RPC abuseMalicious uploadsUnpatched coreNo PHP to exploitNo database to injectNo admin login to guessNo plugins to patchStill worth protecting: DNS and the CDN account (use MFA)Attack surfaceWordPressLargeStaticMinimalFewer moving parts means fewer ways in. Performance: response time and request complexityLess work per request means faster pages, everywhere, under any load05 / 07WordPressStaticTime to first byte, typical uncached pageWordPress≈ 700 msStatic≈ 50 msDatabase queries per page viewWordPress20 to 100Static0Work per page viewWordPressStaticDNS lookupyesyesTLS handshakeat originat the edgeApplication codePHP runsnoneDatabase queries20 to 1000HTML generatedevery requestonce, at buildServed fromorigin servernearest edgeStatic pages skip the work entirely, so they stay fast under any load.Figures are typical ranges and illustrative Cost: what you pay for, month after monthRelative monthly cost of ownership06 / 07WordPressStaticHostingManaged PHP and database serverCDN or object storage, often freeBackupsDatabase and file backups, on a scheduleVersion control is the backupMaintenanceCore, plugin and theme updatesRebuild only when content changesSecurityFirewall, malware scans, patchingNothing to patch on the serverLess to rent, back up, patch and monitor. The savings repeat every month.Bars are relative and illustrative Why convert to static?The same content, delivered a better way07 / 07Faster1 stop instead of 6 for every visitMore SecureNo PHP, database or admin login to attackLower CostCDN hosting instead of servers, backups and patchingEasier To MaintainNothing to update or patch on a serverBetter ScalabilityEdge caching absorbs traffic spikesFrom 6 stops to 1Every page view, for every visitorWordPress6 stopsStatic1 stopConvert once. Serve fast, safely and cheaply from then on.

The animation above runs for just over a minute. The seven scenes, for anyone who would rather read them, are below; the timings and figures in them are typical and illustrative, not measurements of any one site. The animation shows WordPress, the commonest traditional website, but Concrete5, Umbraco, Joomla, Drupal and the rest work the same way: they build the page while the visitor waits, and everything below applies to them too.

The seven scenes

1. A traditional website versus a static one

WordPress vs Static Website: 1. WordPress vs Static Website Title card comparing WordPress, where pages are generated on demand by PHP and a database, with a static website, where pages are pre-built files served from a global CDN. WordPress vs Static WebsiteWhy converting a traditional WordPress site to a static site pays off01 / 07WordPressdynamicStatic websitepre-builtvsPages are generated on demandPHP and a database run for every requestPages are pre-built filesServed from a global CDN, close to the visitorSix quick comparisons: request flow, security, performance, cost and upkeep.

A traditional website generates each page on demand: its code and a database run for every request. A static page is a pre-built file, served from a global network close to the visitor.

2. The traditional request

WordPress vs Static Website: 2. Traditional WordPress request flow A request travels through six stops: Visitor, DNS, Web Server, PHP Runtime, Database and Response. A stacked bar underneath shows time to first byte accumulating at every stop, roughly 700 milliseconds in total for an uncached page. Traditional WordPress request flowWhat happens every time someone opens a page02 / 07Visitoropens a pageDNSdomain lookupWeb ServerTLS + routingPHP Runtimetheme & plugins runDatabaseSQL queriesResponseHTML assembledTime to first byte builds up at every stopDNSServerPHP executionDatabase queriesResponse≈ 700 ms6 stops per visit. PHP runs and the database is queried every single time.Timings are typical for an uncached page and illustrative

Every page view passes through six stops: the visitor, the domain lookup, the web server, the code that builds the page (PHP, for WordPress), the database and the response. The code runs and the database is queried every single time.

3. The static request

WordPress vs Static Website: 3. Static website request flow A request travels through one stop: Visitor to Global CDN to Response. A comparison shows roughly 50 milliseconds for the static page against roughly 700 for WordPress, on the same scale. Static website request flowThe page already exists as a file. Nothing is computed on the way.03 / 07Visitoropens a pageGlobal CDNedge location nearest to the visitorResponsepre-built HTML fileTime to first byte, same scale as the previous sceneWordPress≈ 700 msStatic≈ 50 ms1 stop. No code runs and no database is touched. The page is already built.

One stop. The page already exists as a file, so no code runs and no database is touched on the way.

4. Security

WordPress vs Static Website: 4. Security comparison Left: a WordPress site surrounded by eight threat labels such as plugin flaws, SQL injection and login brute-force. Right: a static site with a shield and four labels for what no longer exists to attack, plus a note that DNS and the CDN account still need protecting. Bars at the bottom show a large attack surface for WordPress and a minimal one for static. Security: attack surfaceEvery moving part is something an attacker can probe04 / 07WordPress siteStatic siteYour siteYour sitePlugin flawsTheme exploitsOutdated PHPSQL injectionLogin brute-forceXML-RPC abuseMalicious uploadsUnpatched coreNo PHP to exploitNo database to injectNo admin login to guessNo plugins to patchStill worth protecting: DNS and the CDN account (use MFA)Attack surfaceWordPressLargeStaticMinimalFewer moving parts means fewer ways in.

Every moving part is something an attacker can probe: plugins, themes, out-of-date server code, the login page, the upload folder. A static site has no server code to exploit, no database to inject, no admin login to guess and no plugins to patch. What is left to protect is the domain and the hosting account, which is why they have two-factor sign-in.

5. Performance

WordPress vs Static Website: 5. Performance comparison Two bar charts compare time to first byte, about 700 milliseconds for WordPress against 50 for static, and database queries per page view, 20 to 100 against zero. A table lists the work per page view: application code, HTML generation, and where the page is served from. Performance: response time and request complexityLess work per request means faster pages, everywhere, under any load05 / 07WordPressStaticTime to first byte, typical uncached pageWordPress≈ 700 msStatic≈ 50 msDatabase queries per page viewWordPress20 to 100Static0Work per page viewWordPressStaticDNS lookupyesyesTLS handshakeat originat the edgeApplication codePHP runsnoneDatabase queries20 to 1000HTML generatedevery requestonce, at buildServed fromorigin servernearest edgeStatic pages skip the work entirely, so they stay fast under any load.Figures are typical ranges and illustrative

Less work per request means faster pages, everywhere, under any load. A static page skips the work entirely, so it stays fast when a busy day brings a crowd.

6. Cost

WordPress vs Static Website: 6. Cost comparison Grouped bars compare relative monthly cost for hosting, backups, maintenance and security. WordPress bars are long: managed PHP and database hosting, scheduled backups, plugin and theme updates, firewall and scanning. Static bars are short: CDN hosting, version control as backup, rebuild on change, nothing to patch. Cost: what you pay for, month after monthRelative monthly cost of ownership06 / 07WordPressStaticHostingManaged PHP and database serverCDN or object storage, often freeBackupsDatabase and file backups, on a scheduleVersion control is the backupMaintenanceCore, plugin and theme updatesRebuild only when content changesSecurityFirewall, malware scans, patchingNothing to patch on the serverLess to rent, back up, patch and monitor. The savings repeat every month.Bars are relative and illustrative

Less to rent, back up, patch and monitor. A static site needs no managed server running code and a database, its history is its backup, and it is rebuilt only when the content changes. The savings repeat every month.

7. The summary

WordPress vs Static Website: 7. Final summary Five checked benefits: Faster, More Secure, Lower Cost, Easier To Maintain, Better Scalability. A recap card shows the six-stop WordPress chain above the one-stop static chain. Why convert to static?The same content, delivered a better way07 / 07Faster1 stop instead of 6 for every visitMore SecureNo PHP, database or admin login to attackLower CostCDN hosting instead of servers, backups and patchingEasier To MaintainNothing to update or patch on a serverBetter ScalabilityEdge caching absorbs traffic spikesFrom 6 stops to 1Every page view, for every visitorWordPress6 stopsStatic1 stopConvert once. Serve fast, safely and cheaply from then on.

Convert once. Serve fast, safely and cheaply from then on.

What a static site does not do on its own

A static site is pages, news, documents and forms. Anything that needs something running behind the pages for each visitor, Stillsite provides as an add-on, built for you and looked after the same way; the form on a Stillsite site already has a small service behind it, and it is part of the plan. Nothing is ruled out: ask, and we will tell you what it involves. The pricing page lists the first packs, with lots more to follow.

What this means for your site

A Stillsite site is the static one: rebuilt once, served fast from then on, with nothing to patch and nothing to break into. How it works says what the rebuild involves.

Would your site suit?

Send us the address and we will tell you.

Get a quote