Part II of the static web handbook covers what happens once your site works: keeping it secure, keeping it fast, and selling from it. A static site is already hard to attack and quick to load, and a few server settings and habits keep it that way.
The foundations (HTML, CSS, JavaScript, site structure, generators and publishing) are in Handbook for mastering the principles of static web development. This page adds security, performance and e-commerce, and follows the same setup: a static site uploaded to public_html on shared hosting.
Serve the site only over HTTPS, keep secrets out of front-end code, update your build tools, and add security headers such as a Content Security Policy once you have tested them. For speed, size images correctly, minify CSS and JavaScript with your generator's build, and give fingerprinted files long browser-cache lifetimes. To sell from a static site, use a payment gateway's hosted checkout or a hosted e-commerce service, with a small server-side script to confirm payments.
1. Security: smaller surface, not zero
A static site has no database and no server code per visit, so SQL injection and most server-side attacks have nothing to hit. What remains:
- Your build tools and dependencies. Keep the generator and npm packages updated, and run
npm auditbefore you build. - Third-party scripts. Every analytics, chat or widget script runs with full access to your page. Add only the ones you need, from sources you trust.
- Forms and small scripts. A contact form's PHP handler is server code: validate every field on the server, and never put an API key or password in JavaScript.
- Your hosting login. A stolen FTP or control panel password lets someone replace every page. Use strong passwords and two-factor sign-in.
2. HTTPS and security headers
Every Domain India shared hosting plan includes a free SSL certificate: AutoSSL with Let's Encrypt on cPanel, and Let's Encrypt on DirectAdmin. Once it is issued, send all visitors to HTTPS. mod_rewrite works in .htaccess on our cPanel, DirectAdmin and Webuzo servers:
RewriteEngine On
RewriteCond %{HTTPS} !=on
RewriteRule ^ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]Security headers go in the same .htaccess. Wrap them in IfModule so the site keeps working if the headers module is not available, and test each page afterwards:
<IfModule mod_headers.c>
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Content-Security-Policy "default-src 'self'; img-src 'self' data:; frame-ancestors 'self'"
</IfModule>A strict Content Security Policy blocks anything it doesn't list, including analytics, fonts, maps and payment scripts. Start with Content-Security-Policy-Report-Only, watch the browser console, add the sources you really use, and only then switch to the enforcing header. Add HSTS (Strict-Transport-Security) only when every subdomain works over HTTPS, because browsers remember it.
3. Performance: keep the static advantage
Caching rules for .htaccess, again wrapped so they are skipped if the module is missing:
<IfModule mod_headers.c>
<FilesMatch "\.(css|js|woff2|webp|avif|svg|png|jpg)$">
Header set Cache-Control "public, max-age=31536000, immutable"
</FilesMatch>
<FilesMatch "\.html$">
Header set Cache-Control "no-cache"
</FilesMatch>
</IfModule>Use a year-long lifetime only for files whose names change when their content changes. Otherwise returning visitors keep the old version.
On our cPanel servers, pages can also be served from a server-side cache for up to 120 minutes. Add ?t=1 to an address to check that an update is live. Measure with Lighthouse in Chrome DevTools and aim for good Core Web Vitals: Largest Contentful Paint, Interaction to Next Paint and Cumulative Layout Shift.
4. Selling from a static site
A static site can sell, as long as the payment itself happens somewhere secure:
- Hosted checkout or payment links. A gateway such as Razorpay can host the payment page, so card and UPI details never touch your site.
- Embedded checkout with server confirmation. Open the gateway's checkout from your page, then confirm the payment with a small server-side script and a webhook. See Razorpay integration in PHP and Node.js.
- Product data. Keep products in a JSON or Markdown file that your generator builds into pages, or pull them from a headless CMS or e-commerce API at build time.
- Stock and orders. Once you need live stock levels, customer accounts or order management, a hosted e-commerce service or a dynamic shop fits better than a static site.
5. Pitfalls to avoid
- Too much client-side JavaScript, which slows the first view and hides content from search engines. Generate pages at build time.
- Skipping accessibility: headings in order, alt text, contrast and keyboard access.
- Forgetting redirects when you rename pages. Add a 301 in
.htaccessfor every old address. - No version control. Keep the source in Git, and upload only the build output.
6. Where Domain India fits
Any Domain India shared hosting plan (cPanel, DirectAdmin or Webuzo) can serve a static site, with free SSL and .htaccess support. Upload the build output to public_html with the File Manager or FTP. Prices on the cards are live and exclude 18% GST.
- 25 GB NVMe SSD Storage
- 50 GB Monthly Bandwidth
- 1 Website
- 10 Email Accounts
Is a static website secure?
It is much harder to attack than a dynamic site, because there is no database or server code per visit. You still need HTTPS, updated build tools, trusted third-party scripts, server-side validation for any form handler, and strong hosting passwords.
How do I force HTTPS on a static site?
Once the free SSL certificate is active, add a mod_rewrite rule to .htaccess that redirects any request not on HTTPS to the same address over HTTPS with a 301. mod_rewrite works in .htaccess on Domain India cPanel, DirectAdmin and Webuzo hosting.
How do I make a static site load faster?
Size and compress images in WebP or AVIF, minify CSS and JavaScript with your generator's build, self-host fonts as WOFF2, and give fingerprinted files long browser-cache lifetimes. Measure with Lighthouse.
Can a static website take payments?
Yes. Use a payment gateway's hosted checkout or payment links, or open its checkout from your page and confirm each payment with a small server-side script and a webhook. Never trust a success message from the browser alone.
Ready to publish? Read part 1 of the handbook, then choose cPanel hosting for your site.
Upload your files with the File Manager or FTP. Free SSL is included with every hosting plan.
See hosting plans