Picture a plumbing contractor in Winchester. His website went up in 2019 — a WordPress site, built by a freelancer who has since moved on to other things. It looked good, it showed up on Google, and nobody has logged into it since. Then one Tuesday a customer mentions that when she searched for his business, her browser warned her the site might be hacked. He has no idea how to check, no idea who to call, and no idea how long it's been that way.
That contractor is hypothetical. The pattern isn't — and it's worth understanding before you build or rebuild your business website, because the standard advice ("just use WordPress, everyone does") skips over the part that actually determines whether your site stays safe.
According to W3Techs, WordPress powers 41.5% of all websites — 59.2% of sites built with any known content management system. That popularity is deserved. WordPress is capable, flexible software with a massive ecosystem. But if you're weighing WordPress vs a custom website for your small business, the honest comparison isn't about which software is better. It's about who's going to look after the thing.
WordPress Isn't the Risk. Unmaintained WordPress Is
Patchstack's 2025 State of WordPress Security report found 7,966 new vulnerabilities in the WordPress ecosystem in 2024 — about 22 every day. Here's the part most people miss: 96% of those were in plugins, 4% in themes, and only 7 vulnerabilities all year were in WordPress core itself. The people who build WordPress do a good job. The exposure comes from everything bolted onto it.
A small business WordPress site often runs a dozen or more plugins — a contact form here, an SEO helper there, a photo gallery, a page builder. Each one is a separate piece of software from a separate developer, updated (or abandoned) on that developer's schedule. And the same Patchstack report found 43% of those vulnerabilities required no login at all to exploit. Attackers don't need your password. They need one outdated plugin, and automated scanners hunt for those around the clock.
The consequences show up in the cleanup data. Sucuri, a company that removes malware from websites for a living, has consistently found in its annual Website Threat Research Reports that WordPress makes up the large majority — typically over 90% — of the infected CMS sites it cleans, and most of those were running outdated core, plugins, or themes.
Read that carefully. The sites getting hacked aren't hacked because they're WordPress. They're hacked because they're WordPress and nobody was updating them.
The Maintenance Job Nobody Actually Owns
Keeping a WordPress site healthy is a real, recurring job: core updates, plugin updates, theme updates, checking that an update didn't break the layout, backups before each change, renewing plugin licenses, and watching for signs of compromise. Industry cost guides like Kinsta's put professionally maintained WordPress at roughly $50 to $500 per month for maintenance services — and that's on top of hosting and plugin or theme license renewals. Those are estimates, but the shape of them is right: done properly, WordPress is a subscription, not a one-time purchase.
Now ask who's doing that job at a typical rural Ontario small business. A three-person accounting office in Chesterville or a contractor in Embrun doesn't have a web person. The freelancer who built the site finished the project years ago. The owner has a business to run. We've written before about how micro businesses handle IT with no spare hands — the website ends up in the same bucket as the aging backup drive. Everyone assumes it's fine, right up until it isn't.
So the site sits there, quietly aging. Every month, more of those 22-a-day vulnerabilities apply to it.
A Custom-Coded Site Removes Most of the Attack Surface
There's a different way to build a business website: write it as code, purpose-built for your business, and publish it as fast, pre-built pages. This is how we build sites at CinnTech — custom-coded, designed and run like managed IT — and it's how cinntech.com itself is built, using the same underlying technology (Next.js) that companies like Netflix and Nike use for their sites.
The security argument is structural, not a matter of vigilance. A custom-coded site has no plugin system, no database, and no admin login page — the three things that get WordPress sites hacked. There's no plugin to fall out of date, no database to inject malicious code into, no login form for bots to hammer with password guesses. Most of the weekly maintenance surface simply doesn't exist. You can't forget to update a plugin you don't have.
Speed comes along for free. Because the pages are pre-built rather than assembled from a database on every visit, they load fast — and that matters twice. Google's own Search Central documentation lists Core Web Vitals (loading speed, interactivity, visual stability) among the page-experience signals it uses in ranking. And Google's mobile speed research with SOASTA found that as a page's load time goes from 1 second to 3 seconds, the probability of a visitor bouncing increases 32% — from 1 to 5 seconds, 90%, and from 1 to 10 seconds, 123%. A slow site doesn't just annoy people. It sends them to your competitor before your homepage finishes loading.
When WordPress Is the Right Choice
This isn't a hit piece, so here's the honest other side. WordPress is a good fit when:
- You edit content yourself, constantly. If you're updating menus, listings, or event calendars every week, the WordPress editor is genuinely convenient, and a custom site would slow you down.
- You need plugin-dependent features. A booking system, a membership area, or a large online store may be far cheaper to run on established WordPress plugins than to build from scratch.
- You have a tight budget and someone who will actually maintain it. A WordPress site with a named person applying updates, testing them, and keeping backups is a perfectly reasonable setup.
Notice the pattern in all three: WordPress works when someone is actively engaged with it. The trouble is that most small business sites are set-and-forget — a digital brochure that changes a few times a year. For that job, WordPress carries a maintenance burden with none of the payoff.
Comparing the Real Cost
The sticker prices mislead in both directions. WordPress looks cheap up front, but done responsibly it carries that $50-500 monthly maintenance estimate plus hosting and license renewals — indefinitely. Skip the maintenance and the cost doesn't disappear; it converts into risk, and eventually into an emergency cleanup at the worst possible time.
For comparison, our custom-coded builds start at $2,000, with an optional AI chatbot add-on for $500. Site Shield, our website care plan, runs $100, $150, or $250 per month depending on tier. That fee isn't for just hosting — the site runs on our managed servers, and the plan is us taking care of it: monitoring, daily backups, updates to the underlying platform, all included at every tier, because we don't believe security should be the upgrade. Over a few years, the totals land closer together than most Eastern Ontario business owners expect. The difference is what you're paying for: with one, you're funding an ongoing defence of a large attack surface. With the other, most of that surface was never built.
If you want a real number for your situation instead of ranges, a quote takes about two minutes.
The Bottom Line
WordPress powers two out of every five websites for good reasons, and if someone is actively maintaining yours, it can serve you well for years. But the data is blunt: nearly eight thousand new vulnerabilities in one year, 96% of them in plugins, and cleanup firms consistently finding that the hacked sites are the neglected ones. For a small business with nobody assigned to website upkeep — which describes most of them — an unmaintained WordPress site is a slow-motion liability.
A custom-coded site takes the opposite approach: remove the plugin system, the database, and the admin login, and there's very little left to attack or to maintain. Faster for your visitors, better positioned in search, and no monthly update chores hanging over anyone's head.
If your current WordPress site is already hacked or broken, that's usually a rebuild conversation rather than a repair — get in touch and we'll give you a straight answer either way. And if you're simply deciding what your next website should be built on, now you know the real question to ask: not "WordPress or custom," but "who's going to look after it."
Sources:
- W3Techs, "Usage statistics and market share of WordPress" (live, updated daily)
- Patchstack, "State of WordPress Security in 2025"
- Sucuri, Website Threat Research Reports (annual)
- Google Search Central, "Understanding page experience in Google Search results"
- Think with Google / SOASTA, "Mobile site speed: what do users expect?"
- Kinsta, "How Much Does a WordPress Website Cost?"
CinnTech
Managed IT · Eastern Ontario
CinnTech has been serving small and micro businesses in Eastern Ontario since 2010. Our team writes these guides to help business owners make sense of IT and cybersecurity without the jargon.
Managed IT Starting at $50/Month
Stop Dealing With IT Problems Yourself
Device Shield handles updates, monitoring, and security so you can focus on running your business.
See Our Plans


