WordPress websites, without the spin

We love WordPress. We still would not pick it for your website.

No meetings, no proposals - see how the build works or browse example sites

No database to hack
Nothing to patch, ever
Roughly 10x faster loads
Yours to keep

WordPress is an incredible tool and it runs a huge slice of the internet. We used it for years. But it is a database-driven system, and in 2026 a live database on the public web is a job that never ends - updates, plugins, passwords, patches. For a typical Aussie small business with three pages of services and a contact form, it is machinery you do not need, with risk you do not want. Here is the honest case, and the cases where we would still say yes.

The system

What WordPress actually is

WordPress is a free, open-source content management system. It started in 2003 as blogging software and grew into the default way to build a small business website - at its peak roughly forty percent of the web ran on it. You write your pages in a dashboard, and it stores them in a database on your hosting server. Themes change the look; plugins add features like contact forms, sliders, search engine tools, and booking buttons.

That is also the whole problem in one sentence: every WordPress site runs a database, and that database lives on a server connected to the public internet. Not a locked cupboard. The internet itself.

The risk

A database on the internet is an attack surface

Anything you can reach from the web, other people can try to reach too. WordPress admin logins sit at predictable URLs, and automated botnets scan for them around the clock - wordpress-login.php, wp-admin, the login page, the plugins directory, the database connection. They do not care who you are. A plumber in Penrith with a two-year-old WordPress site is not a target in the way a bank is; he is a machine that scans the same few million sites every day and fires at whichever one answers.

Most WordPress "hacks" are not clever break-ins by people. They are automated scans that find an out-of-date plugin or a weak password and take it from there. The site then serves spam links, redirects visitors to scam pages, or quietly joins a botnet - usually for weeks before anyone notices.

The upkeep

In 2026, that database is a roster, not a feature

  1. 01

    The updates never stop. WordPress core ships new versions, every plugin you installed ships new versions, and every month or two one of them is patching a security hole. Your login password wants changing, your admin usernames want hardening, your backups want checking. A site is only as current as its oldest plugin, and the oldest plugin is the one you forgot about.

  2. 02

    If you walk away from it - six months, a year, the way most businesses walk away once the site is "done" - every missed update is a door left open. The scans find it eventually. This is why auto-updates are sold so hard: they are a workaround for the fact that the system needs constant attention, and even then auto-updates only cover what the developers knew about at the time.

  3. 03

    So the honest question for 2026: does a three-page brochure site need a live database at all? The answer is no. A database exists to publish changing content. A local business site changes a phone number twice a year.

The honest bit

When WordPress is still the right call

This is not a WordPress hit piece. It is one of the best software projects of the last twenty years, we have built with it for a long time, and we recommend it in the right circumstances every single week.

WordPress is the right choice when you have tens of thousands of pages or products, genuine editorial workflows with many authors, complex e-commerce at scale, or a big ecosystem of specialist plugins that would take years to rebuild. And it is the right choice when you employ someone - a developer, a system administrator, an agency on retainer - whose actual job is monitoring it, updating it, and keeping it running smoothly. If a full-time person is being paid to mind the shop, WordPress is a fantastic shop.

What it is not, in 2026, is the right default for a typical Aussie small business with three pages and a contact form, bought once and forgotten. For that, the database is a liability you are paying interest on every month you do not think about it.

The receipts

Recent receipts, not scaremongering

This is not hypothetical hand-waving. Look at the pattern of the last two years. WordPress 6.7 shipped in November 2024, and 6.7.1 followed within a fortnight as an emergency security release patching a flaw the update itself had introduced. The WP-Automatic plugin had a SQL injection vulnerability disclosed in 2024 - security researchers counted more than a million sites exposed, and it was exploited in the wild before most site owners even knew the plugin existed.

In 2025, researchers tracked campaigns shoving cryptocurrency-stealing redirects into thousands of out-of-date WordPress sites at once - not by hacking anything clever, just by replaying known exploits against installs nobody had patched. The sites were three, four, sometimes eight versions behind.

And AI makes it worse every year. Attackers now use AI to scan for weaknesses and write exploit code faster than the patch cycle can respond. Every one of those automated scans runs against every WordPress site on the internet, and yours is among them.

The cheap build

What a cheap "WordPress website" usually is

Here is what you are really buying when you pay a few hundred dollars for a WordPress site. A developer buys or downloads a theme, changes the colours and the logo, and installs the usual free plugins - a form plugin, an SEO plugin, a security plugin, a caching plugin, a slider. It can be a perfectly serviceable site.

The catch is the maintenance ledger it leaves behind. That one theme and those six or eight plugins are seven to nine separate update queues, and every one of them is a potential breakage or a potential entry point. The open-source free plugins are excellent - they are exactly what a professional with monitoring tools would use. But the monitoring is the job. If the developer walks away, or you bought it from someone who was never going to stick around, you have inherited a countdown.

The alternative

What you get instead, and why it is better here

Our sites are hand-coded and static. There is no database sitting on the internet, so there is nothing to brute-force, no plugin queue to run, no login page to scan for, no updates that can ship a new vulnerability. A static page is served as-is and is gone - loads in the same time it takes to fetch a file, typically ten times faster than the same page on WordPress, and it never breaks after an update because there are no updates to apply.

If you do want to change your own copy later, the optional CMS add-on is a simple Pages CMS sitting over the same hand-coded files. Your edits go straight into the published site - they are not stored in a database on your server, because there is no database. That is the whole safety argument in one sentence.

For 99 percent of small businesses in 2026, the answer is not a database. It is a fast, static, secure site that nobody has to maintain - what the $500 AUD + GST flat rate actually buys you, with the files and domain in your name. If you are genuinely set on a WordPress website and understand the upkeep, we can still build and maintain that for you - it runs through our agency, Underdog Digital, properly scoped rather than squeezed into a flat fee.

WordPress, asked plainly

Straight answers.

No hedging, no fine print. If it is not here, email us - a human replies.

[email protected]
Is WordPress unsafe?
Not exactly. WordPress is fine when it is actively maintained. The problem is that "actively maintained" means core updates, plugin updates, password hygiene, and monitoring - forever, by someone. A static site removes the entire category of risk by removing the database and the plugin stack.
Doesn't auto-update fix all of this?
It covers the things the developers already knew about. It cannot cover a vulnerability that ships inside a new update (WordPress 6.7's emergency 6.7.1 patch did exactly that), a plugin whose author abandoned it, or a password already out in the wild. Auto-update is a mitigation, not a cure.
My WordPress site has never been hacked in ten years.
That is survivorship bias and it is genuine luck. The scans run every night regardless. Many sites are compromised and serve junk to visitors for months without the owner noticing - the traffic, not the hack, is usually what gets noticed. When was the last time you logged in and checked the version, the plugins, and the logs?
Can I still get a WordPress website from you?
Yes. If WordPress is a hard requirement for your business - you specifically need it, or an existing site you must keep - we can build and maintain it through Underdog Digital. The point of this page is to make the choice honest, not to refuse the job.

Set on WordPress anyway? That is a legitimate choice for some businesses, and we will not argue you out of it. We build and maintain WordPress sites too - properly scoped, through Underdog Digital.

The alternative

The site your business actually needs has no database in it.

$500 AUD + GST. Three hand-coded pages, live, secure, yours to keep. No constant updating required.

No database
Nothing to hack, ever
Nothing to update
No plugins, no patch Tuesdays
Full ownership
Code and files are yours
Australia-wide 🇦🇺
Built remotely, delivered cleanly
Before checkout

Quick answers

Is it flat rate? Yes. The website is one payment. CMS is optional +$100 AUD + GST.

$500 AUD + GST covers a custom, hand-coded website of up to three pages, responsive design, a working contact form, technical SEO foundations, launch hosting, SSL, baseline security, and 30 days of post-launch support. There are no mandatory platform subscriptions or agency retainers. Add the CMS only if you want to edit page content yourself.

See exactly what the price includes
Do I own the site? Yes. All files, all code. No lock-in.

You receive the source code and website files outright. Your domain stays registered in your name, and the site is not tied to WordPress, Wix, Squarespace, Webflow, or a proprietary page builder. Move hosts or hire another developer whenever you like.

See what is included and excluded
Revisions? Two rounds of reasonable tweaks after launch.

Both rounds cover reasonable copy changes, presentation tweaks, and layout adjustments inside the agreed design. Extra pages, new functionality, major integrations, or a completely different design direction are quoted separately.

See the full build process
Buy Now - $500 AUD (+ GST)