← Back to Blog

Fewer ways in: why static sites are harder to attack

Illustration of a green shield and padlock over a circuit board, representing a secure static website

Hardly a week goes by without another security hole in the news: Log4j, a popular CMS plugin, SQL injection in a widely used framework. Most of them have something in common. They depend on code running on a server, usually with a database behind it.

So what happens if your website doesn't have those things at all?

Where the risk sits

A typical dynamic website, whether it runs on a CMS, a custom application or one of the popular frameworks, is built in layers: a web server, then application code running on every request, then a database. Each layer gives attackers something to aim at.

What each layer exposes

  • The database can be targeted with SQL injection to read, change or delete data.
  • The application code can suffer remote code execution, template injection or broken authentication.
  • The web server itself can be probed for path traversal, header injection and denial of service.
  • Plugins and themes bring in other people's code, along with whatever is out of date in it.

A static site served from a CDN removes the database and the application layer entirely. No database means no SQL injection. No code running per request means no remote code execution or template injection through the site itself. What's left is a web server handing out files, which is about as well understood and well hardened as anything on the internet.

Diagram of the layers in a dynamic website, from database to application code to plugins to web server, with the layers a static site removes crossed out
A static site takes away the layers where most website attacks happen.

Speed helps security too

Speed is usually sold as a user experience benefit, but it helps security as well. A static site on a CDN:

A dynamic site under attack burns through processor time, memory and database connections, so the more popular it gets, the more fragile it becomes. A static site works the other way round: more traffic means more of it is served from cache, which makes it quicker and cheaper.

"The most secure code is the code that never runs. The fastest code is the code that's already written."

What about the dynamic bits?

Contact forms, search and customer logins are all perfectly reasonable things to want, and none of them needs your whole website to run on a server. Static sites handle them like this:

The principle is to keep the website static and pass anything dynamic to a specialist service built for that job. The parts an attacker can reach stay small, and you don't lose any features.

How we build

Every Daedalus Design project is a static site unless there's a good reason for it not to be. You get a professional website with an AI assistant, far less for attackers to work with, quick loading wherever your visitors are, and prices from £359. The best security is the kind you don't have to think about.

Want a site with less to attack?

Every package is built the same way, with fixed prices agreed before we start.

View Our Packages →

Daedalus Design builds professional websites with AI assistants for UK businesses, and writes about where automation is actually useful in web design.