WordPress has many problems with the way it's usually used that you don't get with static site generators though:
- WordPress can be auto-updating but when you update the core files, theme, and plugins, and want to upgrade PHP, there's lots of incompatibilities that can take your site down and cause other problems so it's not set and forget.
- Most sites also require a combo of plugins because core is missing essentials (e.g. page caching, SEO tags, contact forms, image optimisation), where each can give page speed, security, and maintenance issues.
- Dynamic PHP code is inherently less secure than static HTML files e.g. there's been remote code execution exploits via WordPress contact form and caching plugins in the past which isn't something you have to worry about with static sites.
- Versioning, deploys and updates via Git and CI/CD isn't standard practice with the WordPress community either. Plugins that update themselves and write files to the server is the norm which is another source of stability and security problems.
- Configuration being split across the filesystem and the database gets in the way of predictable staging/production deploys and QA.
- When writing PHP theme templates, there's minimal default escaping when you output fields so you have to be extra careful to not introduce exploits.
Static sites are fundamentally more secure, more performant and easier to test by default. There's bandaids to some of the above but you'll be fighting against WordPress standard practices all the time.
I'm still trying to find a good open source WYSIWYG page builder experience here that can compete with WordPress though. Using WordPress as a CMS and a static site generator to deploy it is an option though.