Why Your Website Moved Off WordPress (and How to Ask for a Change)

If we manage your website, it is not a WordPress site anymore. It is a set of finished pages with no login page, so nobody logs in to edit it. Not you, and not us. When you want a change, you ask in Basecamp and we make it.

Before and after: a WordPress site versus a static site Before, every visit runs WordPress, which has three ways in: a login page, plugins and a database. After, every visit gets a finished page file, with no login, no plugins and no database on the public path. BEFORE: WordPress AFTER: static site Visitor Visitor WordPress programbuilds the page on every visit Loginpage Plugins Database 3 ways in A stolen password or old plugin can change what visitors see. Finished page filesbuilt ahead of time,checked every day,sent as they are 0 ways in No login page, no plugins, no database to break into.
Before and after. Tap a box to read more about it.

This page explains what changed, why I made the call, what happened to your old site, and exactly how to ask for a change. It is part of how our IT Support desk keeps your site safe.

What changed on my website?

WordPress is a program. Every time someone visits your site, that program wakes up, reads a database, runs its plugins and builds the page. It also has a login page, so anyone with the right password can change what your visitors see.

Most of the sites we run don’t need any of that. Every visitor sees the same page. So we build each page once, check it, and hand visitors the finished file. That is what “static” means.

Your domain did not change. Your pages, words, photos and links are the same. Before WordPress was switched off, each site was built, reviewed and independently checked.

Why did I change my mind about WordPress?

I used to be WordPress’s biggest fan. I even wrote a post called Why WordPress Is the Way, and Always Will Be. For years it was how my team and I published everything.

But I was also writing warnings. In one post I wrote that we had recently seen five clients get hacked, and all of it was easy to avoid. My advice was about the login page, because that is the address attackers hit.

This August, an essay called “The defender’s window” said the quiet part out loud. AI tools now help attackers find old flaws at machine speed. The same tools help defenders fix them first, but only if they move now. Attacks on WordPress sites are picking up. On 19 August I wrote my team: harden our own sites first, then help clients do the same.

Then we saw it up close. Here is what our IT Support desk recorded in public:

  • 5 October 2026. We cleaned up a break-in across our WordPress sites. Everything was backed up first. We removed 25,981 fake administrator accounts and changed the security keys and database passwords on 199 sites.
  • 5–6 October 2026. We moved the fleet off WordPress to static sites, then cleaned up leftover template pages on 107 of them.
  • 8 October 2026. We found a hidden card-skimmer planted on several online stores. We contained it, moved three of those sites to static, and confirmed zero customer orders were exposed.

Each of those break-ins needed a way in. A static site doesn’t offer one. You can’t guess the password to a login page that doesn’t exist.

Is a static site really safer, faster and cheaper?

Safer

A WordPress site has three doors: the login page, the plugins and the database. A static site has none of them on the public path. Our daily security audit also checks every site we manage. It compares each one to a saved copy from when it was known to be clean. If a page changes when it shouldn’t, we know that morning.

Faster

WordPress builds the page every time someone asks for it. A static page is already built, so the server just sends it. On our sites, that cut the server’s work per page by about 90%. Your PageSpeed score stays about the same, because the design is the same. The numbers are below.

Cheaper

Running WordPress means paying for servers and a database to rebuild pages that never change. Cutting hosting cost was one of the reasons I approved the move. Plain files cost far less to serve, and your visitors lose nothing.

What changed when we measured before and after?

I didn’t want to tell you the move was better without checking. So we measured nine client sites we moved, using their homepages before and after. Here is what changed, and what didn’t.

~90%
less server work per page
About 74 ms on WordPress to 6–9 ms static, on every site we measured.
0
PHP files and plugins
Was 3,507 to 17,471 PHP files and 8 to 38 plugins per site.
74–99%
fewer files on the server
Less to patch, watch and back up.
79–99%+
less disk space
For example, dennisyu.com went from 16.37 GB to 2.71 GB.
About the same
PageSpeed score and page weight
Mobile scores moved by 6 points or less. Same design, same images.

The biggest change is on the server. WordPress had to run code and ask a database for every page. A static page is already built, so the server just sends it. These three sites show it clearly:

Bar chart: server work per page view fell from about 74 ms on WordPress to 6 ms on localservicespotlight.com, 9 ms on dennisyu.com and 6 ms on philmershon.com after moving to static.
Server work per page: about 74 ms on WordPress, 6–9 ms static.
Bar chart: executable PHP files on the server fell from 3,507 (localservicespotlight.com), 11,095 (dennisyu.com) and 15,034 (philmershon.com) to zero after moving to static.
Executable PHP files: thousands before, zero after.
Bar chart: files on the server fell from 20,803 to 4,998 on localservicespotlight.com, 49,091 to 12,580 on dennisyu.com and 28,664 to 682 on philmershon.com.
Files on the server: down 74% to 98% on these three sites.
Bar chart: site size on the server fell from 5.32 to 1.08 GB on localservicespotlight.com, 16.37 to 2.71 GB on dennisyu.com and 2.21 to 0.18 GB on philmershon.com.
Site size on the server: down 80% to 92% on these three sites.

What didn’t change? Your PageSpeed score and the size of your homepage stayed about the same. That is expected. We kept your design, text and images exactly as they were, so your visitors see the same page. The Lighthouse SEO score was also unchanged on all nine sites. The win is less work on the server, far fewer things that can be hacked and lower cost. It is not a jump in your speed score.

Bar chart: PageSpeed mobile score stayed about the same: 43 to 47 on localservicespotlight.com, 74 to 73 on dennisyu.com and 45 to 45 on philmershon.com.
PageSpeed mobile score: about the same, because the design is the same.
Bar chart: homepage download size stayed about the same: 2.68 to 2.64 MB on localservicespotlight.com, 2.11 to 2.28 MB on dennisyu.com and 2.35 to 2.35 MB on philmershon.com.
Homepage download size: about the same, for the same reason.

How we measured: Google Lighthouse 12.8.2, median of 3 runs, on October 9, 2026. “Before” is the Internet Archive copy of each WordPress homepage. WordPress server time was measured on sites still running WordPress on the same host.

What happened to my old WordPress site?

Nothing was thrown away in a hurry. We work quarantine-first: suspect files are moved aside with a way to put them back, not deleted. Here is what we keep:

  • A verified backup, always. Before a site goes static, we save a full archive of the old WordPress site. Each archive has checksums. A checksum is a digital fingerprint that proves the archive is complete and unchanged.
  • A 30-day rollback window. The old WordPress folder stays in place for 30 days after the switch, so we can undo the move fast if something is wrong. After that the folder is removed, but the verified backup stays.
  • Redirects for anything we retired. When a filler page was removed, we pointed its old address somewhere useful, so links don’t break.

Need an old page, photo or post back? Ask in Basecamp. We can restore it from the archive.

How do I ask for a change to my site?

How a change request flows You ask in Basecamp. Anyone on our Ops team or your account manager routes it. Our team and agents make the change in the site files. It is checked. It goes live and we reply in the same Basecamp thread with the link. 1. You ask in Basecamppage link + exact change 2. Ops team or account managerconfirms what you want and routes it 3. Our team and agents make itin the site’s files, never by logging in 4. Checked before it goes livea second check, then the daily audit 5. Live, with a link back to youreply in the same Basecamp thread
How a change request flows. Nobody logs in to the live site at any step.
  1. Ask in Basecamp. Post in your project. Only the named owners and users on your account should ask. New to Basecamp? Start with our Basecamp basics guide.
  2. Be specific. Give the page link, what to change and the new words or photo. A screenshot helps.
  3. Anyone on our Ops team or your account manager routes it. They confirm what you want and ask if anything is unclear.
  4. Our team and agents make the change. We edit the site’s files, never a live login. Here is how I run our AI agents as one ops desk.
  5. We check it and send you the live link in the same Basecamp thread, so you can see it yourself.

Nobody logs in to edit your site anymore, and that is on purpose. A site with no login is a site nobody can hijack with a stolen password. It also means you never have to grant us website access for a site we already moved.

Common questions

Can I still log in to WordPress?
No. On a site we moved, the login page is gone on purpose. Ask in Basecamp and we make the change.

Do I need to send you a password?
No. Never post a password in Basecamp or email. We do not need one to change your site.

Will my site look different?
No. Your domain, pages, words, photos and links stay the same. It should load faster.

Do my forms and links still work?
Each site was checked before WordPress was switched off. If something looks wrong, post the page link in Basecamp.

Can I get something back from my old WordPress site?
Yes. The verified backup is always kept. Ask in Basecamp and we restore what you need.

Who do I ask?
Post in your Basecamp project. Anyone on our Ops team or your account manager will route it.

Where can I read more?

Dennis Yu

Dennis Yu wrote this. I made the call to move our managed sites off WordPress, and I answer for it. Read more about how I work at dennisyu.com.

Originally published .

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top