Choosing & comparing

A CMS or no CMS
on your website?

A content management system (such as WordPress or Joomla) makes publishing and extending things yourself easy. A pure HTML site delivers minimal complexity, top speed and hardly any CMS maintenance.

Here we place both worlds side by side: vulnerabilities, costs, speed — and when which approach is smartest.

  • HTMLA small attack surface, no CMS updates.
  • CMSFlexible management, but ongoing maintenance.
  • BespokeWe build both — honest advice.

Two different philosophies

With an CMS site runs software on the server that assembles pages: a database, an admin log-in, themes and often dozens of plug-ins. That gives power and convenience, but also structural maintenance: every link in that chain can need security updates.

With an static HTML site the live site consists of fixed files (HTML, CSS, images). There is no CMS that you have to update to “stay secure” in the same sense as with WordPress or Joomla. Hosting and any custom scripts do remain relevant; the largest part of the classic CMS attack surface disappears.

The comparison in brief

A comparison between static HTML, WordPress and Joomla on seven points.
Topic Static HTML WordPress Joomla
Editing content yourself Via us or in HTML No built-in editor Yes Via admin and editor Yes Via the backend
Database on the server No database Not needed by default MySQL/MariaDB MySQL/MariaDB
Speed of first load Very high The server delivers directly Good to medium Depends on theme and plug-ins Good to medium Cache & extensions determine a lot
Hosting (per year) € 69,-/year HTML-only package, without email € 135,-/year Basic package suitable for a CMS
Maintenance (per year) No fixed amount Costs only when changes are made, on request € 379,-/year Updates, backups and fixed hours — see website maintenance. Exact terms are always stated in the quotation.
Custom build price (from) € 399,- Custom-built, no CMS layer € 999,- Custom-built on a CMS
Vulnerability pressure (CMS layer) Very low No CMS to patch High Mainly via plug-ins/themes Medium Lower than the WP ecosystem, but structural

Vulnerabilities: what do the figures say?

Public databases and security overviews count reports — not automatically “hacked sites”. Even so, a clear pattern emerges: the larger the ecosystem and the more extensions, the more known vulnerabilities are added each year that you have to track and mitigate with updates.

  • WordPress ecosystem (2024): 7,966 new vulnerabilities in the core, themes and plug-ins combined — an increase of 34 % compared with 2023. 97 % of those are in plug-ins, 3 % in themes and only 0,2 % in the WordPress core itself.
  • Joomla ecosystem (2024): approximately 43 new CVEs across the Joomla core and common extensions combined. Far fewer in absolute terms, partly because the Joomla Extensions Directory (~5,700 extensions) is also roughly 10× smaller than the WordPress plug-in repository (~59,000). Updates are still needed.
  • For reference: within those ecosystems the core itself is actually very small. In 2024 the WordPress core had around 13 CVEs, the Joomla core around 15. The vast majority of the risk therefore lies in plug-ins/extensions and themes.
  • Static HTML: no CMS layer, so 0 CMS or plug-in CVEs to keep track of. The server, TLS and any form or analytics code do still need attention — just as with any other site.

Sources. WordPress ecosystem: Patchstack, State of WordPress Security in 2024. Joomla ecosystem (rolling 365 days, tag “Joomla”): CVE Daily; Joomla core specifically: akaoma.com (vendor: Joomla). Size of the extension market: Joomla Extensions Directory and a WordPress Plugin Directory. Counting methods differ per source; use the chart below as an order of magnitude, not as an exact prediction for one specific site.

To scale: the number of new vulnerabilities in 2024 per ecosystem (core + themes/extensions + plug-ins). Source: Patchstack & CVE Daily.
WordPress ecosystem core + themes + plug-ins 7.966
Joomla ecosystem core + extensions 43
Static HTML 0

Linear to scale: the WordPress ecosystem = 100 %, the Joomla ecosystem ≈ 0,54 % (43 ÷ 7,966), static HTML = 0 %. WordPress also has around 10× as many plug-ins available as Joomla has extensions, which explains part of the difference. Counting methods differ per source; use this as an order of magnitude.

Benefits of a pure HTML website

  • Fewer moving parts — no CMS core, theme stack or plug-in chain to keep running.
  • No mandatory CMS maintenance fee — pay for hosting and for changes when you need them (see also website without maintenance costs).
  • Top performance — the server delivers static files; ideal for Core Web Vitals and modest hosting.
  • A smaller attack vector — no /wp-admin or Joomla backend that looks the same on every installation by default.
  • Predictable costs — a lower entry price for custom work (with us from € 399,-).
  • More sustainable per visit — less server work per page; see CMS vs. HTML sustainability.
  • No supplier lock-in — universal technology that virtually any web builder can take over, so you are not tied to one party or one platform.

When is a CMS the better choice?

Choose a CMS if you want to publish frequently yourself , have many authors, need complex permissions, or want to standardise integrations with other systems via the CMS. WordPress and a Joomla are then a powerful foundation — provided you take the maintenance seriously or outsource it.

In summary

HTML wins on simplicity, speed and predictable ongoing costs for typical presentation sites — often exactly the reason to choose a website without WordPress. CMS wins on autonomy and scalable management. The answer to “a CMS or not?” is therefore: it depends on how you work — and we will help you weigh that up honestly.

Get in touch All web design options