Security by separation
The public WordPress attack path disappears.
For supported published sites, visitors do not execute WordPress plugins, PHP or queries against the WordPress database.
Private authoring
Identity checks and site permissions protect the editor. It is a separate environment from the public website.
Independent releases
Publication creates a retained release. A broken or unavailable editor does not become a hidden visitor fallback.
Controlled recovery
Restore a known retained version without depending on rebuilding the original site.
A precise security promise
Removing public PHP execution removes an important class of exposure. A malicious script in published content, a compromised publishing account or a provider vulnerability can still matter. Source review, identity protection and clean recovery remain necessary.
Compatibility and source review happen before activation. Originless does not certify an infected website as clean simply because its output is static.
Review my website