Traditional versus static websites Two ways to deliver the same website. One builds every page while the visitor waits. The other has already built it.
WordPress vs Static Website
An animated explainer in seven scenes. 1: WordPress generates pages on demand with PHP and a database, while a static site serves pre-built files from a CDN. 2: A WordPress request passes six stops - visitor, DNS, web server, PHP runtime, database, response - and time to first byte builds up at each, about 700 milliseconds for an uncached page. 3: A static request has one stop - visitor, global CDN, response - around 50 milliseconds. 4: Security: WordPress exposes plugins, themes, PHP, SQL, logins, XML-RPC and uploads; a static site removes them, leaving only DNS and the CDN account to protect. 5: Performance: static pages skip PHP execution and database queries entirely and are served from the nearest edge. 6: Cost: hosting, backups, maintenance and security all cost less without servers to rent, back up and patch. 7: Summary: faster, more secure, lower cost, easier to maintain, better scalability.
WordPress vs Static Website Why converting a traditional WordPress site to a static site pays off 01 / 07 WordPress dynamic Static website pre-built vs Pages are generated on demand PHP and a database run for every request Pages are pre-built files Served from a global CDN, close to the visitor Six quick comparisons: request flow, security, performance, cost and upkeep.
Traditional WordPress request flow What happens every time someone opens a page 02 / 07 Visitor opens a page DNS domain lookup Web Server TLS + routing PHP Runtime theme & plugins run Database SQL queries Response HTML assembled Time to first byte builds up at every stop DNS Server PHP execution Database queries Response ≈ 700 ms 6 stops per visit. PHP runs and the database is queried every single time. Timings are typical for an uncached page and illustrative
Static website request flow The page already exists as a file. Nothing is computed on the way. 03 / 07 Visitor opens a page Global CDN edge location nearest to the visitor Response pre-built HTML file Time to first byte, same scale as the previous scene WordPress ≈ 700 ms Static ≈ 50 ms 1 stop. No code runs and no database is touched. The page is already built.
Security: attack surface Every moving part is something an attacker can probe 04 / 07 WordPress site Static site Your site Your site Plugin flaws Theme exploits Outdated PHP SQL injection Login brute-force XML-RPC abuse Malicious uploads Unpatched core No PHP to exploit No database to inject No admin login to guess No plugins to patch Still worth protecting: DNS and the CDN account (use MFA) Attack surface WordPress Large Static Minimal Fewer moving parts means fewer ways in.
Performance: response time and request complexity Less work per request means faster pages, everywhere, under any load 05 / 07 WordPress Static Time to first byte, typical uncached page WordPress ≈ 700 ms Static ≈ 50 ms Database queries per page view WordPress 20 to 100 Static 0 Work per page view WordPress Static DNS lookup yes yes TLS handshake at origin at the edge Application code PHP runs none Database queries 20 to 100 0 HTML generated every request once, at build Served from origin server nearest edge Static pages skip the work entirely, so they stay fast under any load. Figures are typical ranges and illustrative
Cost: what you pay for, month after month Relative monthly cost of ownership 06 / 07 WordPress Static Hosting Managed PHP and database server CDN or object storage, often free Backups Database and file backups, on a schedule Version control is the backup Maintenance Core, plugin and theme updates Rebuild only when content changes Security Firewall, malware scans, patching Nothing to patch on the server Less to rent, back up, patch and monitor. The savings repeat every month. Bars are relative and illustrative
Why convert to static? The same content, delivered a better way 07 / 07 Faster 1 stop instead of 6 for every visit More Secure No PHP, database or admin login to attack Lower Cost CDN hosting instead of servers, backups and patching Easier To Maintain Nothing to update or patch on a server Better Scalability Edge caching absorbs traffic spikes From 6 stops to 1 Every page view, for every visitor WordPress 6 stops Static 1 stop Convert once. Serve fast, safely and cheaply from then on.
WordPress vs Static Website
A phone version of the WordPress vs Static explainer, in seven tall scenes. 1: WordPress generates pages on demand with PHP and a database, while a static site serves pre-built files from a CDN. 2: A WordPress request passes six stops and time to first byte builds up to about 700 milliseconds for an uncached page. 3: A static request has one stop, around 50 milliseconds. 4: Security: a static site removes plugins, PHP, the database and the admin login, leaving only DNS and the CDN account to protect. 5: Performance: static pages skip PHP and database queries and are served from the nearest edge. 6: Cost: hosting, backups, maintenance and security all cost less without servers to rent, back up and patch. 7: Summary: faster, more secure, lower cost, easier to maintain, better scalability.
WordPress vs Static Website Why converting a WordPress site to static pays off 01 / 07 WordPress dynamic Pages are generated on demand PHP and a database run for every request vs Static website pre-built Pages are pre-built files Served from a global CDN, close to you Six quick comparisons follow.
WordPress request flow What happens on every single page view 02 / 07 Visitor opens a page DNS domain lookup Web server TLS and routing PHP runtime theme and plugins run Database SQL queries Response HTML assembled Time to first byte builds up at every stop ≈ 700 ms 6 stops. PHP runs and the database is queried every time.
Static request flow The page already exists. Nothing is computed. 03 / 07 Visitor opens a page Global CDN edge nearest to you Response pre-built HTML file Time to first byte, same scale WordPress ≈ 700 ms Static ≈ 50 ms 1 stop. No code runs, no database is touched.
Security Every moving part is a way in for an attacker 04 / 07 WordPress site Your site Plugin flaws Theme exploits SQL injection Login brute-force Malicious uploads Outdated PHP Static site Your site No PHP to exploit No database to inject No admin login to guess Only DNS and the CDN account to protect Fewer moving parts means fewer ways in.
Performance Less work per request means faster pages 05 / 07 WordPress Static Time to first byte WordPress ≈ 700 ms Static ≈ 50 ms Database queries per page WordPress 20 to 100 Static 0 Work per page view WP Static Application code PHP runs none Database queries 20 to 100 0 Served from origin the edge Static pages skip the work, so they stay fast.
Cost Relative monthly cost of ownership 06 / 07 WordPress Static Hosting WordPress Static Backups WordPress Static Maintenance WordPress Static Security WordPress Static Less to rent, back up, patch and monitor.
Why go static? The same content, delivered a better way 07 / 07 Faster 1 stop instead of 6 More secure No PHP, database or login to attack Lower cost CDN hosting, not servers and patching Easier to maintain Nothing to patch on a server Better scalability Edge caching absorbs spikes From 6 stops to 1 WordPress Static Convert once. Serve fast, safely and cheaply.
The animation above runs for just over a minute. The seven scenes, for anyone who would rather read
them, are below; the timings and figures in them are typical and illustrative, not measurements of
any one site. The animation shows WordPress, the commonest traditional website, but Concrete5,
Umbraco, Joomla, Drupal and the rest work the same way: they build the page while the visitor waits,
and everything below applies to them too.
The seven scenes
1. A traditional website versus a static one
WordPress vs Static Website: 1. WordPress vs Static Website
Title card comparing WordPress, where pages are generated on demand by PHP and a database, with a static website, where pages are pre-built files served from a global CDN.
WordPress vs Static Website Why converting a traditional WordPress site to a static site pays off 01 / 07 WordPress dynamic Static website pre-built vs Pages are generated on demand PHP and a database run for every request Pages are pre-built files Served from a global CDN, close to the visitor Six quick comparisons: request flow, security, performance, cost and upkeep.
A traditional website generates each page on demand: its code and a database run for every
request. A static page is a pre-built file, served from a global network close to the visitor.
2. The traditional request
WordPress vs Static Website: 2. Traditional WordPress request flow
A request travels through six stops: Visitor, DNS, Web Server, PHP Runtime, Database and Response. A stacked bar underneath shows time to first byte accumulating at every stop, roughly 700 milliseconds in total for an uncached page.
Traditional WordPress request flow What happens every time someone opens a page 02 / 07 Visitor opens a page DNS domain lookup Web Server TLS + routing PHP Runtime theme & plugins run Database SQL queries Response HTML assembled Time to first byte builds up at every stop DNS Server PHP execution Database queries Response ≈ 700 ms 6 stops per visit. PHP runs and the database is queried every single time. Timings are typical for an uncached page and illustrative
Every page view passes through six stops: the visitor, the domain lookup, the web server, the code
that builds the page (PHP, for WordPress), the database and the response. The code runs and the
database is queried every single time.
3. The static request
WordPress vs Static Website: 3. Static website request flow
A request travels through one stop: Visitor to Global CDN to Response. A comparison shows roughly 50 milliseconds for the static page against roughly 700 for WordPress, on the same scale.
Static website request flow The page already exists as a file. Nothing is computed on the way. 03 / 07 Visitor opens a page Global CDN edge location nearest to the visitor Response pre-built HTML file Time to first byte, same scale as the previous scene WordPress ≈ 700 ms Static ≈ 50 ms 1 stop. No code runs and no database is touched. The page is already built.
One stop. The page already exists as a file, so no code runs and no database is touched on the way.
4. Security
WordPress vs Static Website: 4. Security comparison
Left: a WordPress site surrounded by eight threat labels such as plugin flaws, SQL injection and login brute-force. Right: a static site with a shield and four labels for what no longer exists to attack, plus a note that DNS and the CDN account still need protecting. Bars at the bottom show a large attack surface for WordPress and a minimal one for static.
Security: attack surface Every moving part is something an attacker can probe 04 / 07 WordPress site Static site Your site Your site Plugin flaws Theme exploits Outdated PHP SQL injection Login brute-force XML-RPC abuse Malicious uploads Unpatched core No PHP to exploit No database to inject No admin login to guess No plugins to patch Still worth protecting: DNS and the CDN account (use MFA) Attack surface WordPress Large Static Minimal Fewer moving parts means fewer ways in.
Every moving part is something an attacker can probe: plugins, themes, out-of-date server code, the
login page, the upload folder. A static site has no server code to exploit, no database to inject, no
admin login to guess and no plugins to patch. What is left to protect is the domain and the hosting account, which is
why they have two-factor sign-in.
WordPress vs Static Website: 5. Performance comparison
Two bar charts compare time to first byte, about 700 milliseconds for WordPress against 50 for static, and database queries per page view, 20 to 100 against zero. A table lists the work per page view: application code, HTML generation, and where the page is served from.
Performance: response time and request complexity Less work per request means faster pages, everywhere, under any load 05 / 07 WordPress Static Time to first byte, typical uncached page WordPress ≈ 700 ms Static ≈ 50 ms Database queries per page view WordPress 20 to 100 Static 0 Work per page view WordPress Static DNS lookup yes yes TLS handshake at origin at the edge Application code PHP runs none Database queries 20 to 100 0 HTML generated every request once, at build Served from origin server nearest edge Static pages skip the work entirely, so they stay fast under any load. Figures are typical ranges and illustrative
Less work per request means faster pages, everywhere, under any load. A static page skips the work
entirely, so it stays fast when a busy day brings a crowd.
6. Cost
WordPress vs Static Website: 6. Cost comparison
Grouped bars compare relative monthly cost for hosting, backups, maintenance and security. WordPress bars are long: managed PHP and database hosting, scheduled backups, plugin and theme updates, firewall and scanning. Static bars are short: CDN hosting, version control as backup, rebuild on change, nothing to patch.
Cost: what you pay for, month after month Relative monthly cost of ownership 06 / 07 WordPress Static Hosting Managed PHP and database server CDN or object storage, often free Backups Database and file backups, on a schedule Version control is the backup Maintenance Core, plugin and theme updates Rebuild only when content changes Security Firewall, malware scans, patching Nothing to patch on the server Less to rent, back up, patch and monitor. The savings repeat every month. Bars are relative and illustrative
Less to rent, back up, patch and monitor. A static site needs no managed server running code and a
database, its history is its backup, and it is rebuilt only when the content changes. The savings repeat every
month.
7. The summary
WordPress vs Static Website: 7. Final summary
Five checked benefits: Faster, More Secure, Lower Cost, Easier To Maintain, Better Scalability. A recap card shows the six-stop WordPress chain above the one-stop static chain.
Why convert to static? The same content, delivered a better way 07 / 07 Faster 1 stop instead of 6 for every visit More Secure No PHP, database or admin login to attack Lower Cost CDN hosting instead of servers, backups and patching Easier To Maintain Nothing to update or patch on a server Better Scalability Edge caching absorbs traffic spikes From 6 stops to 1 Every page view, for every visitor WordPress 6 stops Static 1 stop Convert once. Serve fast, safely and cheaply from then on.
Convert once. Serve fast, safely and cheaply from then on.
What a static site does not do on its own
A static site is pages, news, documents and forms. Anything that needs something running behind the
pages for each visitor, Stillsite provides as an add-on, built for you and looked after the same way;
the form on a Stillsite site already has a small service behind it, and it is part of the plan.
Nothing is ruled out: ask, and we will tell you what it involves. The pricing page lists
the first packs, with lots more to follow.
What this means for your site
A Stillsite site is the static one: rebuilt once, served fast from then on, with nothing to patch and
nothing to break into. How it works says what the rebuild involves.