Why Your Website Moved Off WordPress (and How to Ask for a Change)

If we manage your website, it is not a WordPress site anymore. It is a set of finished pages with no login page, so nobody logs in to edit it. Not you, and not us. When you want a change, you ask in Basecamp and we make it.

Before and after: a WordPress site versus a static site Before, every visit runs WordPress, which has three ways in: a login page, plugins and a database. After, every visit gets a finished page file, with no login, no plugins and no database on the public path. BEFORE: WordPress AFTER: static site Visitor Visitor WordPress programbuilds the page on every visit Loginpage Plugins Database 3 ways in A stolen password or old plugin can change what visitors see. Finished page filesbuilt ahead of time,checked every day,sent as they are 0 ways in No login page, no plugins, no database to break into.
Before and after. Tap a box to read more about it.

This page explains what changed, why I made the call, what happened to your old site, and exactly how to ask for a change. It is part of how our IT Support desk keeps your site safe.

What changed on my website?

WordPress is a program. Every time someone visits your site, that program wakes up, reads a database, runs its plugins and builds the page. It also has a login page, so anyone with the right password can change what your visitors see.

Most of the sites we run don’t need any of that. Every visitor sees the same page. So we build each page once, check it, and hand visitors the finished file. That is what “static” means.

Your domain did not change. Your pages, words, photos and links are the same. Before WordPress was switched off, each site was built, reviewed and independently checked.

Why did I change my mind about WordPress?

I used to be WordPress’s biggest fan. I even wrote a post called Why WordPress Is the Way, and Always Will Be. For years it was how my team and I published everything.

But I was also writing warnings. In one post I wrote that we had recently seen five clients get hacked, and all of it was easy to avoid. My advice was about the login page, because that is the address attackers hit.

This August, an essay called “The defender’s window” said the quiet part out loud. AI tools now help attackers find old flaws at machine speed. The same tools help defenders fix them first, but only if they move now. Attacks on WordPress sites are picking up. On 19 August I wrote my team: harden our own sites first, then help clients do the same.

Then we saw it up close. Here is what our IT Support desk recorded in public:

  • 5 October 2026. We cleaned up a break-in across our WordPress sites. Everything was backed up first. We removed 25,981 fake administrator accounts and changed the security keys and database passwords on 199 sites.
  • 5–6 October 2026. We moved the fleet off WordPress to static sites, then cleaned up leftover template pages on 107 of them.
  • 8 October 2026. We found a hidden card-skimmer planted on several online stores. We contained it, moved three of those sites to static, and confirmed zero customer orders were exposed.

Each of those break-ins needed a way in. A static site doesn’t offer one. You can’t guess the password to a login page that doesn’t exist.

Is a static site really safer, faster and cheaper?

Safer

A WordPress site has three doors: the login page, the plugins and the database. A static site has none of them on the public path. Our daily security audit also checks every site we manage. It compares each one to a saved copy from when it was known to be clean. If a page changes when it shouldn’t, we know that morning.

Faster

WordPress builds the page every time someone asks for it. A static page is already built, so the server just sends it. Faster pages are better for your visitors and for search.

Cheaper

Running WordPress means paying for servers and a database to rebuild pages that never change. Cutting hosting cost was one of the reasons I approved the move. Plain files cost far less to serve, and your visitors lose nothing.

What happened to my old WordPress site?

Nothing was thrown away in a hurry. We work quarantine-first: suspect files are moved aside with a way to put them back, not deleted. Here is what we keep:

  • A verified backup, always. Before a site goes static, we save a full archive of the old WordPress site. Each archive has checksums. A checksum is a digital fingerprint that proves the archive is complete and unchanged.
  • A 30-day rollback window. The old WordPress folder stays in place for 30 days after the switch, so we can undo the move fast if something is wrong. After that the folder is removed, but the verified backup stays.
  • Redirects for anything we retired. When a filler page was removed, we pointed its old address somewhere useful, so links don’t break.

Need an old page, photo or post back? Ask in Basecamp. We can restore it from the archive.

How do I ask for a change to my site?

How a change request flows You ask in Basecamp. Anyone on our Ops team or your account manager routes it. Our team and agents make the change in the site files. It is checked. It goes live and we reply in the same Basecamp thread with the link. 1. You ask in Basecamppage link + exact change 2. Ops team or account managerconfirms what you want and routes it 3. Our team and agents make itin the site’s files, never by logging in 4. Checked before it goes livea second check, then the daily audit 5. Live, with a link back to youreply in the same Basecamp thread
How a change request flows. Nobody logs in to the live site at any step.
  1. Ask in Basecamp. Post in your project. Only the named owners and users on your account should ask. New to Basecamp? Start with our Basecamp basics guide.
  2. Be specific. Give the page link, what to change and the new words or photo. A screenshot helps.
  3. Anyone on our Ops team or your account manager routes it. They confirm what you want and ask if anything is unclear.
  4. Our team and agents make the change. We edit the site’s files, never a live login. Here is how I run our AI agents as one ops desk.
  5. We check it and send you the live link in the same Basecamp thread, so you can see it yourself.

Nobody logs in to edit your site anymore, and that is on purpose. A site with no login is a site nobody can hijack with a stolen password. It also means you never have to grant us website access for a site we already moved.

Common questions

Can I still log in to WordPress?
No. On a site we moved, the login page is gone on purpose. Ask in Basecamp and we make the change.

Do I need to send you a password?
No. Never post a password in Basecamp or email. We do not need one to change your site.

Will my site look different?
No. Your domain, pages, words, photos and links stay the same. It should load faster.

Do my forms and links still work?
Each site was checked before WordPress was switched off. If something looks wrong, post the page link in Basecamp.

Can I get something back from my old WordPress site?
Yes. The verified backup is always kept. Ask in Basecamp and we restore what you need.

Who do I ask?
Post in your Basecamp project. Anyone on our Ops team or your account manager will route it.

Where can I read more?

Dennis Yu

Dennis Yu wrote this. I made the call to move our managed sites off WordPress, and I answer for it. Read more about how I work at dennisyu.com.

Originally published .

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top