Skip to content
Artwork for Foojay.io | Friends of OpenJDK and Java Programming
Foojay.io | Friends of OpenJDK and Java Programming · Saturday · 38 min

We Left WordPress: CMS vs Static Sites, Hugo vs Jekyll vs Roq (#102)

Foojay.io quietly moved off WordPress and onto Hugo. No more CMS login, no database, no admin panel — just Markdown and AsciiDoc files, built and deployed straight from GitHub. So is a traditional CMS still the right way to run a content site in 2026, or has static tooling caught up? In this episode, Andy Damevin and Holly Cummins from the Red Hat Quarkus team join to talk through it. Andy created code.quarkus.io and Roq, Quarkus's own Java-based static site framework; Holly led the migration of quarkus.io itself from Jekyll to Roq. We go through the real security numbers behind WordPress's plugin ecosystem, and put very different static site generators head to head: Hugo and Jekyll, the veterans, versus Roq, the newcomer. Topics include: Why WordPress core is usually fine, and the plugins are where the trouble is — over 10,000 plugin vulnerabilities found since 2025 What "recovery" means for a static site versus a CMS after a hack or defacement Jekyll, Hugo, Roq and JBake compared, and why staying in Java matters (or doesn't) How to extend Roq as a Java developer, from a small PR to writing your own plugin What an actual WordPress-to-Roq migration looks like in practice Where a CMS still earns its keep despite all of this Guests: Andy Damevin on LinkedIn - Principal Software Engineer at Red Hat, Quarkus core team, creator of code.quarkus.io and Roq Holly Cummins on LinkedIn - Senior Principal Software Engineer, Red Hat Quarkus team, led the quarkus.io migration from Jekyll to Roq Links: Migrate from WordPress to Roq Roq Hugo Full show notes Timestamps: 00:00 Introduction of topic and guests 03:29 Why WordPress is not the best choice for most sites 04:36 Difference between CMS-driven websites and static websites 07:02 Jekyll versus Roq and other systems 11:04 How to extend Roq 12:59 Moving from WordPress to Roq 14:43 Pulling data with JBang or Roq from external sources into your publication process 16:09 Why should I use Roq instead of Jekyll or Hugo? 24:33 Static websites can be created with a small team and are much cheaper (or even free) to host 26:52 How many WordPress websites have a backup to recover after getting hacked? And the advantage of having your content sources on Git. 33:04 Is there still a use case for WordPress-like systems? 37:09 Conclusions

0:00-38:16

transcript

No transcript — this publisher did not publish one.

show notes

Foojay.io quietly moved off WordPress and onto Hugo. No more CMS login, no database, no admin panel — just Markdown and AsciiDoc files, built and deployed straight from GitHub. So is a traditional CMS still the right way to run a content site in 2026, or has static tooling caught up?

In this episode, Andy Damevin and Holly Cummins from the Red Hat Quarkus team join to talk through it. Andy created code.quarkus.io and Roq, Quarkus's own Java-based static site framework; Holly led the migration of quarkus.io itself from Jekyll to Roq. We go through the real security numbers behind WordPress's plugin ecosystem, and put very different static site generators head to head: Hugo and Jekyll, the veterans, versus Roq, the newcomer.

Topics include:

  • Why WordPress core is usually fine, and the plugins are where the trouble is — over 10,000 plugin vulnerabilities found since 2025
  • What "recovery" means for a static site versus a CMS after a hack or defacement
  • Jekyll, Hugo, Roq and JBake compared, and why staying in Java matters (or doesn't)
  • How to extend Roq as a Java developer, from a small PR to writing your own plugin
  • What an actual WordPress-to-Roq migration looks like in practice
  • Where a CMS still earns its keep despite all of this


Guests:

Andy Damevin on LinkedIn - Principal Software Engineer at Red Hat, Quarkus core team, creator of code.quarkus.io and Roq

Holly Cummins on LinkedIn - Senior Principal Software Engineer, Red Hat Quarkus team, led the quarkus.io migration from Jekyll to Roq


Links:

Migrate from WordPress to Roq
Roq
Hugo
Full show notes


Timestamps:
00:00 Introduction of topic and guests
03:29 Why WordPress is not the best choice for most sites
04:36 Difference between CMS-driven websites and static websites
07:02 Jekyll versus Roq and other systems
11:04 How to extend Roq
12:59 Moving from WordPress to Roq
14:43 Pulling data with JBang or Roq from external sources into your publication process
16:09 Why should I use Roq instead of Jekyll or Hugo?
24:33 Static websites can be created with a small team and are much cheaper (or even free) to host
26:52 How many WordPress websites have a backup to recover after getting hacked? And the advantage of having your content sources on Git.
33:04 Is there still a use case for WordPress-like systems?
37:09 Conclusions

links6