Hardly a week goes by without another security hole in the news: Log4j, a popular CMS plugin, SQL injection in a widely used framework. Most of them have something in common. They depend on code running on a server, usually with a database behind it.
So what happens if your website doesn't have those things at all?
Where the risk sits
A typical dynamic website, whether it runs on a CMS, a custom application or one of the popular frameworks, is built in layers: a web server, then application code running on every request, then a database. Each layer gives attackers something to aim at.
What each layer exposes
- The database can be targeted with SQL injection to read, change or delete data.
- The application code can suffer remote code execution, template injection or broken authentication.
- The web server itself can be probed for path traversal, header injection and denial of service.
- Plugins and themes bring in other people's code, along with whatever is out of date in it.
A static site served from a CDN removes the database and the application layer entirely. No database means no SQL injection. No code running per request means no remote code execution or template injection through the site itself. What's left is a web server handing out files, which is about as well understood and well hardened as anything on the internet.
Speed helps security too
Speed is usually sold as a user experience benefit, but it helps security as well. A static site on a CDN:
- soaks up floods of traffic at the edge of the network before they reach your server
- has no database connections to run out and no application to overload
- keeps serving cached pages even if the build system is briefly down
- costs very little to scale to huge numbers of visits
A dynamic site under attack burns through processor time, memory and database connections, so the more popular it gets, the more fragile it becomes. A static site works the other way round: more traffic means more of it is served from cache, which makes it quicker and cheaper.
"The most secure code is the code that never runs. The fastest code is the code that's already written."
What about the dynamic bits?
Contact forms, search and customer logins are all perfectly reasonable things to want, and none of them needs your whole website to run on a server. Static sites handle them like this:
- Forms go to a form service or a small serverless function that emails you or passes the enquiry on. There's no database on the website.
- Search can use a hosted service such as Algolia or Meilisearch, or a small index built into the page with a library like Fuse.js.
- Logins, where they're really needed, can be handed to a dedicated identity provider such as Auth0, Clerk or Firebase Authentication.
- Live data like bookings, payments or CRM records comes from the services you already use, through their own secure connections.
The principle is to keep the website static and pass anything dynamic to a specialist service built for that job. The parts an attacker can reach stay small, and you don't lose any features.
How we build
Every Daedalus Design project is a static site unless there's a good reason for it not to be. You get a professional website with an AI assistant, far less for attackers to work with, quick loading wherever your visitors are, and prices from £359. The best security is the kind you don't have to think about.
Want a site with less to attack?
Every package is built the same way, with fixed prices agreed before we start.
View Our Packages →Daedalus Design builds professional websites with AI assistants for UK businesses, and writes about where automation is actually useful in web design.