Three wooden blocks labeled HTML, CSS and JavaScript stacked on a table

The Future Is Not WordPress for Small Business Web Design and Development

Let me start by saying something that might seem strange considering the headline.

WordPress is awesome.

I've built a lot of websites for small businesses, with WordPress, and there are very good reasons it became the default choice for small business websites. It has given me a career.

Clients can make relatively easy changes themselves. Multiple users can remotely log in and work on the same website. It organizes blog posts and pages beautifully, which makes sense considering blogging is what WordPress was originally built to do.

Contact forms are easy.

There's a tested plugin for practically everything.

And WordPress is absolutely ubiquitous. It currently powers somewhere around 43% of websites on the internet.

So on what planet did I come up with this hot take?

Because I'm starting to think WordPress is overkill for a lot of small businesses.

WordPress Does a Lot Because It Was Built to Do a Lot

WordPress isn't particularly lightweight.

You have a database. PHP. A theme. Plugins. Usually a page builder. Stylesheets. JavaScript. Image processing. User accounts. An administrative backend. APIs.

Pile of colorful building blocks representing the many components of a WordPress website

All of that is incredibly useful if you actually need it.

But does a local electrician with 15 pages need it?

Does a dentist?

Does a pool company?

A huge percentage of small business websites consist of a homepage, service pages, a few location pages, an about page, a contact form and a blog that gets updated occasionally.

You don't necessarily need a full database, 20 plugins and four automatically generated versions of every image to accomplish that.

WordPress has gotten considerably faster, and good hosting, caching and careful technical SEO can make a WordPress site very fast.

But you're still carrying around a lot of machinery.

Then There's the Maintenance

Don't open up a WordPress site for two months.

Log back in and see what happens.

WordPress needs an update. Seven plugins need updates. Your theme needs an update. PHP is getting old. One plugin hasn't been tested with the newest version of WordPress yet. Another plugin hasn't been updated by its developer in nine months.

Most of the time, you hit update and everything works.

Most of the time.

Until it gets stuck in mainentance mode or the whole thing blows up with an update, and you are scrambling to use rollback.

And WordPress does have security holes.

That's not really a knock on WordPress. Software has vulnerabilities, and software used by hundreds of millions of websites is an enormous target. WordPress Core has had security vulnerabilities. So have major themes and plugins.

By the time a serious vulnerability becomes public, there's a good chance security researchers, attackers or both have already been poking at it. That's why WordPress releases security updates and why keeping Core updated matters.

Then you add everything surrounding WordPress.

Every plugin you install adds code. Every user account is another login. Your theme is software. Your plugins are software. PHP is software. All of it has to be maintained.

A static website has a very different problem.

There isn't much there.

There's Not Much to Attack

Take a basic custom-coded website.

It's HTML and CSS. Maybe a little JavaScript. Maybe a few scripts handling specific functionality.

There's no WordPress login page because there's no WordPress. There's no database full of pages and users because there's no database. There's no collection of plugins waiting for security updates because there aren't any plugins. There's just very little for an attacker to grab onto and very few places for malicious code to propagate.

That doesn't make a static website magically invulnerable. The server can still be compromised. Credentials can still be stolen. Bad code can still be written.

But the attack surface is dramatically smaller.

And maintenance gets a little ridiculous.

I recently rebuilt the Tucson SEO Pros website as a custom static site. There is no WordPress core to update. There is no theme to update. There are no plugins to update.

If I don't touch the website for two months, nothing happens.

And Holy Hell Are Static Websites Fast

This is the part that really surprised me after spending years working with WordPress.

Static websites are blazing fast. The browser asks for a page. The server gives it the page. That's basically it.

There's no database query required to figure out what the page says. There's no page builder reconstructing the layout. There's no giant stack of plugins loading their own CSS and JavaScript.

After working on a static site for a while, WordPress can feel like molasses.

Yes, you can make WordPress fast.

I've done it plenty of times.

You can add caching, optimize the database, defer scripts, remove unnecessary assets, use a CDN, optimize images and spend an afternoon arguing with Lighthouse because it thinks shaving another 18 KB off an image will save civilization.

Or you can serve an HTML file.

So Why Didn't We Just Keep Building Websites This Way?

Because custom websites have their own problems.

Big ones.

If a client calls and wants to change a paragraph on a WordPress site, they can potentially log in and change it themselves.

If they want to publish a blog post, WordPress gives them a nice editor. They type the post, upload an image and hit Publish.

If five people need access to the website, they can each have an account.

WordPress handles all of that beautifully.

On a custom-coded website, somebody has to edit the actual website.

You also need a way to keep multiple developers from destroying each other's work. GitHub becomes considerably more important. Everyone needs to be working from the same project, and you need version control so there's always an undo button when somebody screws something up.

That requires at least some technical knowledge.

For years, that was enough for me to say WordPress was the obvious answer for most small businesses.

Something has changed.

AI Has Made Custom Coding More Accessible

I'm not ready to hand website development over to AI.

Not even close.

AI still does weird things. It writes too much custom CSS. It sometimes fixes one problem by creating three new ones. Give it too much freedom and you can end up with 600 lines of code accomplishing something that should have taken 60.

You still need to understand what you're looking at.

But AI is very good at helping someone who knows what they're trying to accomplish.

It can work with an existing template. It can write a mobile breakpoint. It can troubleshoot JavaScript. It can help build a small Python script that organizes blog posts.

It can look at a piece of CSS and help figure out why one page suddenly has a different margin than every other page on the website.

That changes things.

Tasks that once required considerably more custom development time are becoming easier and faster. Custom-coded websites are more within reach than they have been in years.

The Future Might Look a Lot Like the Past

In a weird way, the future of small business web development might look a lot like the past. HTML. CSS. A tiny dash of JavaScript.

A few text files holding everything together and adding functionality where it's needed.

Except this isn't 2003.

We have responsive design and mobile breakpoints. Modern CSS. GitHub. CDNs. SSL certificates. Incredibly fast hosting and FTP uploads. Better browsers. Better development tools.

And now we have AI sitting next to us when something breaks.

We're going backwards, but we're taking all the good stuff with us.

When I Wouldn't Recommend a Custom Static Website

There are still plenty of situations where I would choose WordPress. The biggest one is when non-technical people need to regularly change the website. If several employees need to log in and publish content, WordPress makes a ton of sense. If the website is constantly changing, a content management system makes sense.

And then there's ecommerce.

If you want ecommerce directly integrated into your website and don't want to offload it to Shopify or another ecommerce specialist, WordPress and WooCommerce are still one of the most realistic ways to do it.

Yes, there are custom solutions.

I generally prefer not to make myself the single point of failure for someone's ecommerce operation.

If you want to give me a large amount of money, we can work something out, though.

WordPress Isn't Going Anywhere

This isn't a "WordPress is dead" post.

That would be stupid.

WordPress powers an enormous chunk of the internet and solves real problems extremely well. There are websites I would build in WordPress tomorrow without thinking twice about it.

But I don't think WordPress is going to remain the Automattic™ answer for every small business website.

For a relatively simple small business site, we're reaching a point where the overhead of a full content management system may be harder to justify.

Custom development used to mean spending considerably more money for something that was harder to maintain.

AI is beginning to change that equation.

And after years of adding more layers between the person building a website and the HTML that eventually reaches the browser, we may start removing some of those layers again.

The future of small business web design might be a database, a content management system, a page builder and 20 plugins. Or it might just be an HTML file.

Funny how things come around.