A static web server can theoretically be induced to execute code because it still has parsers.
While I do agree a static site has a smaller attack surface, I think it’s more that nginx has way more eyes on it and a much slower development rate than your average custom configuration of WordPress plugins.
Because if you were to build your own static web server, your first version would probably more susceptible to attack than a stock WordPress installation.
While I do agree a static site has a smaller attack surface, I think it’s more that nginx has way more eyes on it and a much slower development rate than your average custom configuration of WordPress plugins.
Because if you were to build your own static web server, your first version would probably more susceptible to attack than a stock WordPress installation.