| What the browser downloads | HTML and CSS, plus JavaScript only for the components marked as islands. | HTML, plus the stylesheet and script of the theme and of each active plugin, which most themes enqueue on every page. |
|---|
| When the page is rendered | At build time, or per request through an adapter, chosen route by route. | Per request by PHP, unless a caching plugin or a host layer serves a stored copy. |
|---|
| What has to run to serve it | A static host or CDN. A purely static build needs no database and no application runtime. | PHP and a MySQL-compatible database, kept patched, plus the plugins on top of them. |
|---|
| Security surface | A static build exposes no login and no database. Forms and dynamic parts are separate endpoints you add deliberately. | A public admin login, a database and a plugin supply chain, each of which needs updating on the site that is live. |
|---|
| Who edits content | Editors work in Markdown or MDX files, or in a headless CMS connected to the build. | Editors work in the built-in admin and publish immediately, with no build step and no developer involved. |
|---|
| What a change looks like | A commit. It can be previewed and read as a diff before anyone deploys it. | A change in the database or in the files on the server. It is only reviewable if the team keeps themes and plugins in version control themselves. |
|---|
| What it costs to keep running | Build minutes and static hosting; no runtime to patch. | Managed hosting or a server, plus plugin licences and the maintenance those updates require. |
|---|