Web Development

Headless CMS or WordPress? How to Choose a CMS for a UAE Business Website

SKIMBOX Team

One supplier says WordPress is fine, another says you need headless, and both are selling. Here is the honest trade: headless buys you content that feeds more than one place, and costs you the in-place editing your team actually uses. Plus what each option really costs to run.

Headless CMS or WordPress? How to Choose a CMS for a UAE Business Website

Two suppliers are telling a UAE business two different things. One says WordPress is fine and always was. The other says the future is headless and anything else is legacy. Both are selling, and the buyer has no way to tell which is describing their situation and which is describing their product line.

The honest version is smaller than either pitch. Headless is an architecture that buys you one specific thing and costs you one specific thing. Whether that trade is worth it depends on six questions about your business, none of which are about technology.

This article stays out of territory we already cover. Migration mechanics are in our replatforming guide, hardening is in our website security guide, and a platform-by-platform verdict is in our WordPress, Webflow and Next.js comparison. This one is about how to make the choice.

What headless actually means

Headless means your content is stored and delivered through an API, with the front end built as a separate application. WordPress describes the capability without the marketing term, saying its REST API lets you build a brand new interactive front-end experience or bring your content into completely separate applications [1]. Contentful describes storing content as structured entries delivered as JSON [6]. Sanity describes content held as structured data, queryable, referenceable, and ready for delivery to any channel [12].

Notice what none of those say. None of them promise faster, safer, or better. They describe a separation, and everything else follows from it.

What you actually give up

Editors lose in-place visual editing. In a traditional setup, someone updating a page works on something resembling the page. In a headless setup they work in a structured form, and the rendered result lives somewhere else.

The strongest evidence that this trade is real is not a critic's complaint. It is that both leading vendors built features specifically to close the gap. Contentful ships Live Preview, which shows content rendering in real time beside the entry editor with an inspector mode that jumps from a piece of website content to its source field [7]. Sanity ships visual editing that lets editors see drafts render on the live site, click an element to reach the right field, and watch content update as they type [13].

Those features are good. They also would not need to exist if the base experience were not detached. Anyone selling you headless without mentioning this is not describing the product honestly.

What you actually gain

You gain content that can feed more than one destination. That is the whole benefit, and it is a real one when you need it.

If a product description has to appear on your website, inside your app, and on a screen in a showroom, holding it as structured data and delivering it through an API is the correct architecture, and doing it any other way means maintaining the same words in three places. If it appears on one website and nowhere else, you are paying a monthly subscription and an extra hosting bill for a capability that will never be exercised.

The four realistic options

Traditional WordPress. Free core, in-place block editing, a documented content export, and a maintenance burden that lands on you or whoever you pay [2][5]. The editing experience is the one most UAE content staff already know.

WordPress used headlessly. Your editors keep the interface they know while the front end is rebuilt separately against the REST API [1]. The trade is that you now run two systems rather than one, each with its own hosting, deployments and maintenance. It is a genuine middle path and it is not a cheaper one.

A hosted page builder. Hosting, patching and infrastructure become the vendor's problem, which removes real work from a small team. Webflow publishes defined collaborator roles including a content editor who can edit content and collection items but not touch page layout, with publishing gated by an admin toggle [19]. What you accept is dependence on their platform and their schedule.

A dedicated headless CMS with a separate front end. Contentful and Sanity both publish clear role models, and both include a role that can draft but not publish: Contentful's Author and Freelancer roles [8], Sanity's Contributor [14]. Wiring the front end, including preview and revalidation, is developer work throughout [17].

The six questions that actually decide it

Answer these about yourself and the platform usually chooses itself.

  1. Who changes content, and how often? If a non-technical person updates pages weekly, in-place editing has real value and a structured form is a real cost.
  2. Does the same content need to appear in more than one place? This is the question headless exists to answer. If the answer is no, most of the argument collapses.
  3. Do you need independent multilingual publishing? Whether your Arabic can go live without waiting for the English is an operational question with a technical answer.
  4. What can your team actually operate? If nobody in-house can investigate a failed deployment, a headless stack adds an ongoing dependency a page builder does not.
  5. What would it cost to leave? Ask this before you sign.
  6. Where does the content sit? Worth knowing regardless of whether any rule requires it.

Security, and the statistic you should not repeat

WordPress exposure is real, and it concentrates in plugins rather than in WordPress itself. WordPress.org states that its security team resolves issues across the core software, while vulnerability reports for plugins go to the plugin developer and the plugins team, and theme reports to the theme developer [4]. Its developer documentation is blunter still, describing plugins and themes as key points of weakness.

The data supports that split clearly. A keyword search of the US National Vulnerability Database returns over eighteen thousand records mentioning WordPress plugins, against a hundred and thirty-eight for WordPress core [20]. Those are free-text matches rather than a formal taxonomy, and they are not mutually exclusive categories, so treat them as raw counts rather than a clean ratio. Even read conservatively, the direction is unmistakable.

What you should not repeat is the claim that some large percentage of hacked websites run WordPress. No official source publishes it. Every version we traced comes from a security vendor's own client caseload, which measures who hired that vendor rather than what happens across the web, and the most-quoted version is several years old. We had published a version of that claim ourselves and have now corrected it.

The useful conclusion is narrower and more actionable. Plugins are third-party code running with access to your site, and OWASP's current top ten includes a category covering software supply chain failures [21]. A site with eight maintained plugins someone reviews quarterly is safer than one with three abandoned ones.

What each option costs to run

A traditional CMS build is one cost line, and a headless build is at least three: the CMS subscription, front-end hosting, and building the front end itself. Build cost is the number everyone compares, and running cost is the number that decides it.

As checked in August 2026, Contentful published a free tier with ten users and a single space, a Lite tier at 300 US dollars a month for twenty users, and custom enterprise pricing [11]. Sanity published a free tier of up to twenty seats and a Growth tier at 15 US dollars per seat per month [16]. Strapi's self-hosted core is free under an open-source licence with paid cloud tiers starting at 35 US dollars per project per month [24]. Webflow published a Premium plan including its CMS at 25 US dollars a month billed yearly, with localisation sold as a separately metered add-on [19]. Vendor pricing pages change without notice, so confirm the current figures rather than relying on these.

The structural point matters more than any of those numbers. A headless build is at minimum three cost lines: the CMS subscription, front-end hosting, and the one-time cost of building the front end. A WordPress or page-builder build folds all three into one. Per-seat pricing adds a fourth dynamic that most businesses do not model, because it is invisible at five editors and material at thirty.

A pattern worth naming. A Dubai business is sold headless on performance and security grounds, spends more than planned on a front-end build, and two years later has a site nobody in the marketing team will touch without asking a developer first. The content goes stale, which costs far more in lost enquiries than the milliseconds ever earned. The architecture was not wrong in the abstract. It was wrong for a team of four.

Arabic content, and why you should test rather than assume

None of these platforms market Arabic handling specifically, so verify it yourself with real content. Contentful documents locale-based publishing and unpublishing that lets editors publish and unpublish content in selected locales in isolation from others [9]. Sanity documents two localisation patterns, one holding languages in a single document that publish together, and one giving each language its own document so versions publish independently [15]. Both are generic locale mechanisms. Neither is Arabic-tuned.

WordPress is the starkest case. Its own documentation states that WordPress does not support a bilingual or multilingual site out of the box, and that community plugins make it possible, with native capability described as a future roadmap item [3]. For a UAE business planning Arabic, that means a third-party plugin carries your multilingual capability.

The most honest data point comes from the W3C, which states that there is currently a lack of good editing environments for creating pages using right-to-left scripts [22]. That is a standards body saying the tooling is not solved. Have an Arabic speaker type real content into the actual editor during evaluation, because a locale checkbox on a feature page tells you nothing about what the experience is like. The layout side of this is covered in our Arabic-first RTL design guide.

Where your content actually lives

We found no UAE requirement to host website content in the country. The published summary of Federal Decree-Law No. 45 of 2021 says the law applies to processing of personal data inside and outside the country and sets out requirements for cross-border transfer and sharing of personal data [23]. That is transfer-control language, not a hosting mandate. If you operate in a regulated sector, your regulator may say otherwise, so ask them rather than us.

The factual position is still worth knowing. Contentful documents a default United States region with an EU data residency option available as a paid addition, and no Middle East region [10]. Sanity's own documentation points to an EU-hosted content store by default, though we could not confirm a specific region on a dedicated regions page, so treat that as direction rather than a fixed fact. Meanwhile Vercel documents a Dubai compute region among its global regions, though functions default to a United States region unless configured otherwise [18].

Read together, that produces an arrangement most buyers never picture: a front end rendering in Dubai, with the content it renders stored in Virginia or somewhere in the EU. That is not a violation of anything. It is simply not what people assume when they are told the site is hosted locally.

The cost of leaving, which belongs in the decision

Ask what it takes to get your content out before you put it in. This is the question buyers almost never ask and almost always regret not asking, because the answer is cheap to obtain up front and expensive to discover later.

WordPress documents a built-in export producing a file containing posts, pages, custom post types, comments, custom fields, categories, tags, custom taxonomies and users [5]. That is a genuine advantage, with an honest limit: it covers content and structure, not your design or, fully, your media. Sanity documents a command-line dataset export with options for including assets [12]. For some platforms we looked at, we could not find equivalent documented bulk-export tooling, and that absence is itself an answer worth having.

The wider point is that leaving is never only an export. It is migrating content, rebuilding the front end, and preserving search visibility through redirects, which is a project rather than a task. Our replatforming guide puts a migration from around AED 5,000, and that figure assumes the content comes out cleanly. Where it does not, the number moves.

Put concretely: a platform on a four-figure annual subscription that holds your content in a format you cannot easily extract has more pricing power over you every year you stay. That is not an accusation against any particular vendor. It is the reason to check the exit before you commit to the entrance.

What it costs with us

A focused business website starts from around AED 3,500 with us, rising once a CMS your team edits itself is part of the scope. A headless build with a separately built front end starts from around AED 10,000, because you are commissioning the front end that a traditional CMS would have handed you as a theme.

These are our own figures rather than a market survey, since no official body publishes rates for this work. Final pricing depends on scope, mostly on page count and how much of your content genuinely needs modelling rather than typing. Ongoing, a traditional site is hosting plus maintenance from around AED 150 a month, while a headless setup adds platform subscriptions and separate front-end hosting billed in dollars by someone else.

Over three years, that recurring gap often exceeds the difference in build cost. It is the part comparisons leave out because it arrives after the project is signed off.

The short version

Choose headless when your content genuinely has more than one destination, when languages must publish independently, or when your website is a product rather than a brochure. Choose a traditional CMS or a hosted builder when it is a website, your team edits it themselves, and nobody has named a second destination.

If someone is pitching you an architecture and you would like a second opinion from people who will tell you when the cheaper answer is the right one, contact us. We will ask you the six questions and tell you if the cheaper answer is the right one.

References

[1] WordPress, REST API Handbook. developer.wordpress.org

[2] WordPress, The WordPress block editor. wordpress.org

[3] WordPress, Multilingual WordPress. developer.wordpress.org

[4] WordPress, Security. wordpress.org

[5] WordPress, Tools Export screen. wordpress.org

[6] Contentful, Data model. contentful.com

[7] Contentful, Live preview. contentful.com

[8] Contentful, Space roles and permissions. contentful.com

[9] Contentful, Localization. contentful.com

[10] Contentful, EU data residency FAQ. contentful.com

[11] Contentful, Pricing. contentful.com

[12] Sanity, Content Lake. sanity.io

[13] Sanity, Introduction to visual editing. sanity.io

[14] Sanity, Roles. sanity.io

[15] Sanity, Localization. sanity.io

[16] Sanity, Pricing. sanity.io

[17] Next.js, Draft Mode. nextjs.org

[18] Vercel, Edge Network regions. vercel.com

[19] Webflow, Pricing and collaborator permissions. webflow.com

[20] NIST, National Vulnerability Database API. services.nvd.nist.gov

[21] OWASP, Top 10:2025. owasp.org

[22] W3C, Authoring HTML: handling right-to-left scripts. w3.org

[23] The Official Portal of the UAE Government, Data protection laws. u.ae

[24] Strapi, Pricing. strapi.io

Frequently asked questions

  • What does headless actually mean?

    It means your content is stored and served through an API rather than rendered by the same system that stores it, with the front end built separately. WordPress describes the capability without the buzzword, saying its REST API lets you build a brand new interactive front end or bring your content into completely separate applications. The word describes an architecture, not a quality level. Headless is not a better CMS, it is a different arrangement with different consequences.

  • What do editors lose when you go headless?

    In-place visual editing, mostly. In a traditional setup an editor works on something that looks like the page. In a headless setup they work in a structured form and the rendered result lives elsewhere. The strongest evidence this trade is real is that both leading headless vendors built features specifically to compensate: Contentful ships Live Preview with an inspector that jumps from page element to source field, and Sanity ships visual editing that renders drafts on the live site.

  • What do you gain from headless?

    Content that can feed more than one destination. Sanity describes its store as holding content as structured data, making it queryable, referenceable, and ready for delivery to any channel. If the same product description has to appear on your website, in your app, and on a screen in a showroom, that structure is the point of the whole exercise. If it only ever appears on one website, you are paying for a capability you will not use.

  • Should a small UAE business use headless?

    Usually not, and the reason is structural rather than snobbery. A headless build is at minimum three cost lines: a CMS subscription, front-end hosting, and the one-time cost of building the front end. A WordPress or Webflow build folds those into one. If you have one website, one language, a small team, and no second destination for your content, that extra structure buys you very little and costs you every month.

  • When is headless genuinely the right call?

    When the same content has to appear in more than one place, when different languages need to publish independently of each other, or when your website is a product rather than a brochure. Those are architecture problems that a single rendered site cannot solve cleanly. Everything else people cite for headless, including performance and security, can usually be achieved more cheaply another way.

  • Can I use WordPress headlessly?

    Yes, and it is a genuine middle path that keeps your editors on an interface they already know. The content team carries on using the same block editor while the front end is built separately against the REST API or GraphQL. The honest caveat is that you now run two systems rather than one: the WordPress install and a separate front-end application, each with its own hosting, deploys, and maintenance.

  • Is WordPress insecure?

    The exposure is real and it concentrates in plugins rather than in WordPress itself. WordPress.org states that its security team resolves issues in core software, while vulnerability reports for plugins and themes go to the individual plugin or theme developer. A keyword search of the US National Vulnerability Database returns over eighteen thousand records mentioning WordPress plugins against a hundred and thirty-eight for WordPress core. That gap is the whole story.

  • Is it true that most hacked websites run WordPress?

    No official source publishes that figure, and we are not going to repeat it. Every version of that percentage we traced comes from a security vendor's own client caseload, which measures who hired that vendor rather than what happens across the web, and the most commonly quoted version is now years old. The defensible point is narrower and more useful: the risk lives in plugins, so plugin discipline is the control that matters.

  • How many plugins is too many?

    The number matters less than whether anyone owns them. Each plugin is third-party code running with access to your site, maintained by someone you have no relationship with, and OWASP's current top ten includes a category covering software supply chain failures. A site with eight actively maintained plugins someone reviews quarterly is in better shape than one with three abandoned ones. Audit what you have before counting.

  • Does a hosted builder like Webflow avoid the security problem?

    It moves it rather than removing it. Hosting, platform patching, and infrastructure become the vendor's responsibility, which genuinely reduces what your team has to do. What you take on instead is dependence: you cannot patch, migrate, or restructure on your own schedule, and your content lives in their system on their terms. For many UAE SMEs that is a good trade. It is still a trade.

  • What does a headless CMS actually cost?

    As checked in August 2026, Contentful published a free tier with ten users and one space, and a Lite tier at 300 US dollars a month for twenty users. Sanity published a free tier of up to twenty seats and a Growth tier at 15 US dollars per seat per month. Strapi's self-hosted core is free with paid cloud tiers. Vendor pricing pages change without notice, so confirm current figures directly.

  • Does headless cost more than WordPress?

    Usually yes over time, because of how the cost splits. WordPress core is free and you pay for hosting and maintenance. A headless build adds a CMS subscription and separate front-end hosting on top of the one-time cost of building a front end that a traditional CMS would have given you as a theme. The per-seat element is real too: some headless platforms charge per editor once you pass their free tier.

  • Is per-seat pricing a problem?

    It is if your content team grows and nobody modelled it. Sanity publishes a per-seat rate past its free seat allowance, and Contentful's tiers come with user caps that push you upward as your team expands. Neither is expensive at small scale. Both become a line item worth forecasting at twenty or thirty people, which is exactly the sort of cost that surprises a business two years after the decision was made.

  • Does UAE law require my website content to be hosted in the UAE?

    We found no such requirement in the published summary of the data protection law. Federal Decree-Law No. 45 of 2021 applies to processing of personal data inside and outside the country and sets out requirements for cross-border transfer and sharing of personal data. That is transfer-control language rather than a hosting mandate. If you are in a regulated sector such as health or finance, your regulator may impose its own rules, so confirm with them.

  • Where does content actually sit with the main headless platforms?

    Outside the region, as things stand. Contentful documents a default US region with an EU data residency option available as a paid addition, and no Middle East region. Sanity's content store sits in Europe by default with enterprise region discussions available, and again no Middle East option. That is a factual asymmetry worth knowing rather than a compliance failure, and it applies regardless of where your front end renders.

  • Can I host the website itself in Dubai?

    The front end, yes. Vercel documents a Dubai compute region among its global regions, so a Next.js front end can be deployed close to UAE users, though functions default to a US region unless you configure it explicitly. That matters for latency more than for law. It also means the front end and the content store can end up in different parts of the world, which is worth understanding before you claim anything about where your data lives.

  • How well do these platforms handle Arabic content?

    Check rather than assume, because none of them market Arabic specifically. Contentful and Sanity both provide locale mechanisms, and both support publishing one language independently of another, but neither documents Arabic or right-to-left handling as a distinct feature. The W3C states plainly that there is a lack of good editing environments for creating pages using right-to-left scripts. Have someone type real Arabic into the actual editor before you commit.

  • Does WordPress support multiple languages?

    Not natively. WordPress's own documentation states that it does not support a bilingual or multilingual site out of the box and that community plugins make it possible, with native capability described as a future roadmap item rather than something shipped. For a UAE business planning Arabic, that means your multilingual capability is a third-party plugin with all the maintenance and upgrade exposure that implies. Plan for it rather than discovering it.

  • Can different languages be published independently?

    On the dedicated headless platforms, yes, and it is a genuine advantage. Contentful documents locale-based publishing and unpublishing that lets editors publish content in selected locales in isolation from others. Sanity documents two patterns, one where languages live in one document and publish together, and one where each language is a separate document that publishes independently. If your Arabic content is written weeks after the English, that difference is operational, not theoretical.

  • Who can publish without a developer?

    Both headless platforms publish explicit role definitions, and both include a draft-but-cannot-publish role. Contentful documents Author and Freelancer roles that can create and edit but not publish, alongside Editor and Admin. Sanity documents a Contributor role with write access to drafts that cannot publish, alongside Editor, Administrator and Viewer. Map those roles onto your actual team before choosing, because a workflow change is harder to absorb than a tool change.

  • What happens to my content if I want to leave?

    Ask this before you sign, not after. WordPress has a documented built-in export producing a file containing posts, pages, custom post types, comments, custom fields, taxonomies and users, though that covers content structure rather than your design. Sanity documents a command-line dataset export including assets. We could not confirm an equivalent documented bulk export for every platform we looked at, which is itself a useful answer.

  • Will headless make my site faster?

    It can, but performance is a consequence of how a site is built rather than of where the content is stored. A carefully built WordPress site on good hosting can outperform a carelessly built headless one. If speed is the actual problem, measure it first and find out whether the cause is images, third-party scripts, hosting, or rendering, because three of those four are unaffected by your choice of CMS.

  • Should I move off WordPress if it works today?

    Not without a specific reason you can name. Replatforming carries real cost and real risk to your search visibility, and a site that editors can update and that loads acceptably is doing its job. Good reasons to move include a genuine second destination for your content, multilingual publishing your current setup cannot handle, or a maintenance burden nobody is carrying. Being unfashionable is not one.

  • What questions should I actually ask myself?

    Six of them. Who changes content and how often. Does the same content need to appear in more than one place. Do you need independent multilingual publishing. What can your in-house team actually operate. What would it cost to leave. And where does the content sit. Answer those honestly and the platform choice usually makes itself, which is why we do not lead with a feature matrix.

  • What does a CMS-based website cost with SKIMBOX?

    A focused business website starts from around AED 3,500 with us, rising once a CMS your team edits is part of the scope. A headless build with a separately built front end starts from around AED 10,000, because you are commissioning the front end that a traditional CMS would have supplied as a theme. These are our own figures rather than a market survey. Final pricing depends on scope, particularly page count and how much content has to be modelled.

  • What is the ongoing cost difference?

    A traditional site is hosting plus maintenance, and ours starts from around AED 150 a month. A headless setup adds a CMS subscription and separate front-end hosting on top of that, each billed by the platform in dollars and each subject to their pricing changes rather than yours. Over three years that recurring difference frequently exceeds the difference in build cost, which is the part most comparisons leave out.

  • Is a page builder good enough for a real business?

    For a great many UAE businesses, yes, and the resistance to saying so is usually commercial. If your site is a credible brochure with a contact form and a blog, a hosted builder handles it while removing an entire category of maintenance work from your plate. The limits appear when you need custom functionality, complex content relationships, or integration with your other systems.

  • How do I stop this decision being made by whoever is selling to me?

    Ask each supplier two questions: what their recommendation would cost you to leave, and what your team can change without them. Those cut through most of a pitch, because they surface lock-in and dependency, which is where the real long-term cost sits and which no feature comparison shows you. A supplier who answers both plainly is worth more than one with a better slide about performance. If either answer is vague, treat the vagueness as the answer.

  • Can I change my mind later?

    Yes, but at a cost that varies enormously by what you chose. Moving between systems means migrating content, rebuilding the front end, and preserving your search visibility through redirects, which is a project in its own right. That is precisely why the cost of leaving belongs in the original decision rather than being discovered during it. Our migration guide covers what that move actually involves.

SKIMBOX Team

Tech Consultancy

Get fresh writing in your inbox

One email a fortnight. No filler.

By subscribing, you agree to our privacy policy.

Want us to build something?

We work with teams across MENA, UK, USA, and India to build products, run programs, and grow.

Get in touch

Continue reading