A WordPress site got hacked through a stale plugin, and going static dropped the attack surface to near zero.
A small business site ran WordPress with 16 plugins; one unpatched contact-form plugin let an attacker inject spam pages, and Google flagged the domain. Cleanup, reindexing, and lost trust cost two weeks and a real ranking dip. They rebuilt as a static site, no PHP, no database, no plugin to exploit, with forms handled by a hosted service. Twelve months later: zero incidents, and hosting dropped to free. Every WordPress plugin is a door someone else installed and may forget to lock. Fewer moving parts, fewer ways in.
Agree? Or am I wrong?
Drag Drop Done
@DragDropDone
A WordPress site got hacked through a stale plugin, and going static dropped the attack surface to near zero.
Этот пост опубликован в Telegram-канале Drag Drop Done. Подписаться можно по ссылке: @DragDropDone.