I'm in favor of static HTML myself where possible, but it's not hard to maintain a secure Wordpress install. Keep automatic updates enabled and don't install any third party plugins.
It's that second part that most people screw themselves with.
When the maintenance is "ensure auto updates are on, and don't do anything that would not get updated automatically" it's not like it requires regular effort.
> Whereas if you just have a collection of articles that you want to keep around as an archive, if you convert them to a static site, you can basically forget about them afterward...
Your web server, your operating system, etc. still require at bare minimum the same level of maintenance.
You can outsource that maintenance to someone else of course, but you can do the same with WP as well.
--
My point is that WP alone doesn't massively increase the maintenance burden, it's what people tend to do with (to?) WP that increases the burden and eventually leads to unmaintained sites.
no dog in the fight here but I felt impelled to point out that ensuring auto updates are on solves almost all security holes except for the security hole it opens up.
In almost any computing context, but especially in the context of a personal blog, the vast majority of exploits are against known security holes for which patches have already been released and those with automatic updates enabled are already safe from.
Yes, hypothetically updates can deliver new flaws of their own and even potentially intentional malicious code, but from a practical sense it's not worth worrying about if you're using mainstream software packages on a major OS.
More effort that you'll be able to exert when you're dead.
Although I highly doubt learning a jekyll config would be harder than managing a PHP daemon, web proxy and mysql database.