WordPress websites, explained plainly
WordPress is brilliant. That does not mean it is right for you.
No meetings, no proposals - see how the build works or browse example sites
It powers a big share of the web, it is genuinely excellent, and we have built with it for years. But WordPress is a database-driven system, and a database sitting on the public internet in 2026 is a job that never ends: core updates, plugin updates, usernames, passwords, patches. For a British tradesperson with three pages and a contact form, it is a lot of machinery that keeps needing attention. Here is the honest breakdown, and when we would still say WordPress is the right call.
What WordPress is, in one paragraph
WordPress is a free, open-source content management system. It began in 2003 as blogging software and became the standard way to build small business websites - at its peak somewhere around forty percent of the web ran on it. You edit pages in a dashboard, and it stores everything in a database on your hosting server. Themes control the look; plugins bolt on features such as contact forms, sliders, SEO tools and booking systems.
That description contains the entire argument: every WordPress site runs a database, and that database lives on a server connected to the public internet. Not behind your firewall, not on your laptop. On the internet, where everyone is pointing.
An online database is an open door to try
If something is reachable from the web, someone is probing it. WordPress admin pages sit at predictable addresses, and automated botnets scan the same handful of sites day and night - the login page here, the plugin directory there, the database connection underneath. They are not targeting you personally. A gas engineer in Gloucester with a WordPress site fifteen months out of date is simply one of several million machines being rattled for what shakes loose.
The overwhelming majority of WordPress compromises are not audacious human break-ins. They are automated scans that find an outdated plugin or a weak password and work from there. The site then hosts spam, redirects visitors to junk pages, or gets folded into a botnet, often for weeks before anyone realises.
In 2026, the database is a duty, not a perk
- 01
The maintenance never pauses. WordPress core issues new versions, every plugin you have installed issues new versions, and at least monthly one of them is closing a security hole. Passwords need rotating, admin users need pruning, backups need testing, logs need a glance. And a site is only as safe as its oldest plugin - the one you installed in 2021 and forgot existed.
- 02
Leave the site alone for six months or a year, which is what most businesses do once it is "finished", and every missed update is a lock left undone. The scans find it eventually. Auto-update exists precisely because the system cannot go unmanaged; and even then it only patches what was known when the patch was written.
- 03
So the fair question for 2026 is whether a small business site needs a live database at all. A database is for publishing changing content. A typical site changes its opening hours and its phone number.
When WordPress is genuinely the right decision
We are not here to bury WordPress. It is one of the most significant pieces of software of the past twenty years, we have used it professionally for a long time, and we still recommend it in the right circumstances.
That means: tens of thousands of pages or products, real multi-author editorial workflows, e-commerce at scale, or a specialised plugin ecosystem that would be impractical to replicate. And it means a business with someone whose job is to keep it running - a developer, a system administrator, an agency on a maintenance contract - who updates it, monitors it, backs it up, and notices when something looks off. WordPress with a full-time keeper is a superb platform.
What it is not, in 2026, is the sensible default for a British sole trader with three pages and a contact form, bought once and then ignored. For that particular job the database is mostly liability.
Proof it happens, not scare stories
Take the last two years as evidence. WordPress 6.7 arrived in November 2024 and 6.7.1 followed within a fortnight as an emergency security release, patching a vulnerability that came in with the update itself. In 2024 the WP-Automatic plugin had a SQL injection vulnerability disclosed - researchers counted over a million exposed sites, and it was being exploited before many owners knew the plugin existed.
Through 2025, researchers documented campaigns injecting cryptocurrency-stealing redirects into thousands of neglected WordPress sites in one sweep - no clever intrusion, just known exploits replayed against installs nobody had patched. Sites three, four, sometimes eight versions behind, silently serving junk to visitors and search engines alike.
And AI has changed the tempo. Attackers use it to scan for weaknesses and produce working exploits faster than the patch cycle turns. Those scans reach every WordPress site on the internet, including the one you were told was fine.
What a cheap "WordPress website" actually delivers
When you buy a low-cost WordPress site, here is the reality. A developer purchases or downloads a theme, restyles it with your colours and logo, and installs the usual free plugins - a form plugin, an SEO plugin, a security plugin, a caching plugin, maybe a slider. Done well, it is a perfectly respectable website.
The hidden cost is the ledger it hands you. One theme and six or eight plugins is seven to nine separate update streams, and every one is a possible breakage or a possible entry point. The open-source plugins are not the problem - a professional with monitoring tools uses them happily. The monitoring is the job. If nobody is being paid to do it, and the developer moved on to the next customer, the countdown starts.
What you get instead, and why we chose it
Our builds are hand-coded and static. There is no database on the internet, so there is nothing to brute-force, no plugin queue to run, no login page for scanners to find, and no update that can introduce a fresh vulnerability. A static page is a file being fetched - it loads in roughly the time it takes to download it, typically an order of magnitude faster than the same page on WordPress, and it cannot break after an update because there is no update.
Want to change your own copy? The optional CMS add-on is a simple Pages CMS layered over the same hand-coded files. Your changes are published straight into the site - they are not filed in a database on a server, because there is no database. That is the security argument in a single sentence.
For 99 percent of small businesses in 2026 the right tool is not a database; it is a fast static site nobody has to maintain - which is exactly what the £500 flat rate buys, with the files and the domain in your name. And if you are set on WordPress regardless, aware of the upkeep and wanting it anyway, we can build and maintain that as well - properly scoped through our agency, Underdog Digital, rather than shoehorned into a flat fee.
Straight answers.
No hedging, no fine print. If it is not here, email us - a human replies.
[email protected]Is WordPress unsafe?
Do the auto-updates not sort it?
I have run WordPress for years and nothing has ever happened.
Can I still buy a WordPress site from you?
Set on WordPress anyway? That is a legitimate choice for some businesses, and we will not argue you out of it. We build and maintain WordPress sites too - properly scoped, through Underdog Digital.
The website your business actually needs has no database in it.
£500 flat. Three hand-coded pages, live, secure, yours to keep. No constant updating required.