WordPress vs a custom website: the plugin bargain
91% of the 11,334 WordPress vulnerabilities disclosed in 2025 were in plugins, and core accounted for six. What that costs monthly, when WordPress is still the right answer, and what our approach costs you.
Published:
Quick answer: WordPress maintenance runs $50 to $1,000 a month, with agency plans clustering between $200 and $1,000. We do not build on WordPress, so we have an obvious interest here and you should read this with that in mind. What follows is the argument anyway, including the part where WordPress wins and the part where our approach costs you something real.
The security figures come from Patchstack's State of WordPress Security in 2026, which counts the ecosystem's disclosed vulnerabilities each year, read in August 2026. The maintenance figures come from published 2026 pricing guides. One number in the security report explains the entire maintenance market.
What does WordPress maintenance cost?
| What you are buying | Typical price | What it is actually for |
|---|---|---|
| Basic care plan | $20 to $50 a month | Backups and update runs |
| Standard plan | $50 to $200 a month | Updates, security scans, uptime |
| Agency plan | $200 to $1,000 a month | The above, plus a person to call |
| Enterprise with an SLA | $5,000 to $10,000 a month | Response times in writing |
| Our hosting | €29 a month | SSL, backups, monitoring, updates |
There is a trap in that table worth naming. Care plans often exclude hosting and email, so a $150 plan is a $350 line once the infrastructure it sits on is added back. The published guides say this plainly and buyers still get surprised by it.
But the interesting question is not what the plans cost. It is what they exist to do.
Is WordPress secure?
WordPress core is. The ecosystem around it is a different question, and the split is stark.
Patchstack counted 11,334 new vulnerabilities across the WordPress ecosystem in 2025, up 42% on the year before. Of those, 91% were in plugins and 9% in themes. WordPress core itself accounted for six, all low priority.
Six, out of eleven thousand.
So the honest answer is that WordPress is not insecure. The software written by the WordPress project is some of the better-audited code on the web. What is insecure is the pile of third-party code that a WordPress site is mostly made of, and that pile is not optional, because it is the entire reason to choose WordPress in the first place.
The plugin bargain
Here is the deal WordPress offers, stated plainly, because almost nobody states it.
You get software that is free, that can be made to do nearly anything, and that any developer on earth can already work with. In exchange, your website becomes an assembly of code written by people you have never met, on maintenance schedules you do not control, and their Tuesday becomes your Tuesday.
That is the plugin bargain, and it is a genuinely good deal for a lot of people. It is also the whole explanation for the maintenance market above. You are not paying someone to look after your website. You are paying someone to watch other people's code on your behalf, forever.
Two more numbers from the same report finish the thought. 46% of the vulnerabilities disclosed last year had no patch from the developer at the moment they were made public. And for the ones that get attacked hard, the weighted median time to a first exploit is five hours, with roughly half of high-impact vulnerabilities exploited inside a day.
Now hold that against a maintenance plan that runs updates once a month.
A monthly maintenance plan is a 720-hour response time to a five-hour problem.
This is not a criticism of the people selling those plans. They are doing real work and the alternative, nobody watching at all, is considerably worse. It is a criticism of the shape of the problem. The plan cannot close a gap that size, because the gap is not caused by inattention. It is caused by the number of suppliers.
WordPress vs a custom website: what actually differs?
Not the design, and not really the price. Three things differ, and only three.
Who wrote the code you are running. On WordPress, mostly strangers, and a lot of them. We are not going to pretend we write everything ourselves: we build on Next.js, which is third-party code maintained by Vercel, and we host there too. The difference is the count and the accountability. One framework with a company and a security team behind it is a different risk from thirty plugins by thirty individuals on thirty release schedules, and the count is exactly what the numbers above measure.
Where new functionality comes from. This is the one that matters most and gets discussed least. On WordPress you install it yourself, at eleven at night, for free or for $59. On a custom site you ask, and it gets built, and it has a price and a date. That is slower and it costs money.
Who carries the update. On WordPress the notifications arrive in your dashboard and become your decision. On a custom site, if the arrangement is honest, they never reach you at all.
That is the whole comparison. Everything else, speed, SEO, design quality, is a function of how well the thing was built, not which of the two it is. A carefully built WordPress site beats a careless custom one on every measure, and you should distrust anyone who tells you otherwise.
When is WordPress the right choice?
Often. WordPress runs a large share of the web and that is not a mass delusion.
Choose it when you need a specific ecosystem that already exists: a full shop with WooCommerce, memberships, courses, bookings, an events calendar. Rebuilding those from scratch is expensive and worse. Choose it when you have technical staff, because then the dashboard is a capability rather than a liability. Choose it when you want to hire from the largest pool of developers available for any web platform, or when leaving your current agency without leaving your website is a priority.
Choose something else when your website is five pages that describe what your business does, when nobody in the building wants to be responsible for a plugin, and when the functionality you need is functionality you can name today.
That last condition is the real test, and it is worth being honest about which side of it you are on before anyone quotes you anything.
What we build instead, and what it costs you
We build on Next.js and host on Vercel, and the website ships as one piece, written and tested together, with everything under the hood our job rather than yours. You never see an update screen. The editing system you get is for content, so text, images and new pages assembled from blocks you already have are yours to change at any time, at no cost. It is not for installing code, and that is the point rather than a limitation we are apologising for.
That is not a claim that nothing can ever go wrong with our code. Anyone telling you their software has no bugs is selling you something. It is a claim about who the problem belongs to, and about how many separate parties have to act before it gets fixed.
A built example, if you want one rather than an argument: frauenarzt-luebeck.de, a medical practice site with no dashboard for anyone at the practice to look after.
Now the cost of it, stated straight, because a piece like this is worthless without it.
You cannot add a feature by yourself on a Tuesday evening. If you want a booking system, a members area or a calculator, you ask us, we quote it, and it has a price and a date. On WordPress you would have searched a plugin directory and had something running before dinner. Sometimes that plugin would have been fine.
You are also tied to a smaller number of people, though less than the word "custom" suggests. Next.js and Vercel are both mainstream, so what you own is not a private dialect: any React developer can read it and most agencies already work with it. The pool is still smaller than WordPress's, which is the largest of any web platform, and we are not going to argue that gap away. It is the difference between hiring from a smaller pool and hiring from the biggest one, not the difference between having options and having none.
If that trade sounds wrong for you, WordPress is genuinely the better answer and we would rather you knew that now than after an invoice. Where the money goes in either case, and what a website costs before any of this starts, is a separate question we ran the numbers on in what a website costs.
Five questions to ask before you pick a stack
Whoever builds it, five questions settle the part of this that matters:
- How many pieces of third-party code will my website be running?
- When a vulnerability is disclosed, who acts, and how fast?
- What does the monthly plan cost once hosting and email are added back?
- What happens the first time I want functionality that does not exist yet?
- If I want to leave, what exactly do I take with me?
Five answers describe a stack better than any feature list. Here are ours:
| Question | Our answer |
|---|---|
| Third-party code | One framework, Next.js, rather than a shelf of plugins. None of it is yours to track. |
| Vulnerabilities | Ours to act on. No notification reaches your inbox and no decision waits on you. |
| The monthly cost | €29 a month, hosting included, not added back later. |
| New functionality | You ask, we quote it with a price and a date. Slower than a plugin, and deliberate. |
| Leaving | The domain, the content and the code are yours from day one. We hand it over free. |
If you want to see what that costs before it starts, our website package is published in full. Or book an intro call. It takes twenty minutes and costs nothing.