WordPress or PrestaShop?
The real question is who keeps it up to date.
Both work. Both break. What decides is almost never the software chosen: it is the name written against the line “who looks after it”.
Published on 4 August 2026 · 6 min read · by the SkyNet technical team
The site did not go down that day.
On a Thursday morning, an online shop returns a blank page. The manager calls the agency: the quote is three years old, the contact no longer works there. He calls the hosting provider, which confirms it updated the version of PHP (the language that runs the site on the server) overnight — as announced six months earlier by email. The site, however, had stayed on the old one.
Nobody was at fault that Thursday. The fault dates from the day the site went live, when everyone shook hands without writing down who would look after the site the next day.
One was born to publish,
the other to sell.
WordPress — writing
A CMS (content management system: software for creating pages without coding). Born to publish, and it does it better than most. It can sell too, with an extension: for a dozen product lines and simple payments, that is reasonable.
PrestaShop — selling
Selling is built into the core: catalogue, variants (size, colour), stock, VAT, carriers, returns, credit notes. What has to be bodged together elsewhere is already provided for. In exchange, it demands more operational discipline.
Both work. The wrong choice does not bring a site down: it adds friction. You pay for it in hours, not in outages. That is why this question, asked first, takes the place of the right one.
Four lines,
and a name against each one.
A website is not an object you deliver. It is a service that runs every day, on a server that changes without asking your opinion. The four lines opposite are worth all the tool comparisons put together.
Four disciplines,
and not the same person.
- Who updates — the core, the theme (the styling), every extension. And who then checks that the site still works: an unverified update is a gamble.
- Who backs up — the files and the database (where orders, customers and text live). Backing up the files alone does not give you back a shop.
- Who restores — neither the same person, nor the same skill. You find out at the worst possible moment.
- Who answers — a number, opening hours, a response time. Not the address of a form.
The test that separates everyone. Ask for the date of the last successful restoration — not of the last backup. A backup that has never been restored is not a backup: it is a file you hope is good. We apply the same rule to our links: what has not been tested is not in place.
Eight extensions,
are nine pieces of software.
A plugin (a module added to obtain a function: a form, a payment, a link to the carrier) is a real piece of software, written by someone else, with its own update rhythm.
Each one brings a function and a dependency, at the same time. An extension abandoned by its author does not become useless: it becomes a door that nobody watches any more.
- Look at the date of its last update before its ratings.
- Ask what breaks if it disappears. A form can be replaced; a payment flow, far less quickly.
- Get it into the contract. A plugin that is not in it is maintained by nobody.
Nothing breaks all at once.
That is exactly the problem.
A site left without updates does not switch off: it drifts. And the day it shows, the backup you want to restore already contains the problem.
Eighteen months,
told in order
Nobody is doing anything wrong. That is exactly why it happens.
- Falling behind feeds itself — the wider the gap grows, the riskier updating seems. So we wait.
- The server, meanwhile, moves on — your hosting provider follows its own timetable, not yours.
- The bots are not targeting you — they sweep through addresses. Being small protects you from nothing.
The updates pile up
“12 updates available”. Nobody clicks: nobody knows what to do if the site breaks afterwards.
Nobody dares any more
The delay becomes a reason to do nothing.
The hosting provider changes PHP
An extension left behind stops working. It is no longer a tick box, it is a project.
The door stays open
A long-published vulnerability is exploited. Unknown pages appear, and the search engines index them.
The backup does not save you
You have to go back to before the intrusion. Without its date, you restore the problem along with the site.
A site does not stop because it was badly chosen. It stops because it was left on its own.
A site lives on an infrastructure, not in a vacuum.




The grid,
in five lines.
What should guide the choice — and what has to be planned for alongside it.
| Your situation | What is reasonable | What to plan for |
|---|---|---|
| Content, little or no selling | WordPress | A named person, even on a very part-time basis |
| Variants, stock, carriers, returns | PrestaShop | A running budget, not just a build budget |
| A few products, one delivery method | WordPress and a sales plugin | The payment funnel must be named in the contract |
| A site that already works | No change of tool | The useful project is maintenance, not a rebuild |
| Nobody in-house, no contract | Neither one, for now | Settle that line first. The tool comes afterwards |
The maintenance contract kept to a minimum.
Six lines. If one is missing, ask why before you sign.
- How often updates are made, and their scope: core, theme, plugins — each one named.
- How often backups run, how long they are kept, and where they live: not on the site’s server.
- A periodic restore test, with a written date and a report.
- The response time in the event of a complete outage, and the hours during which it applies.
- Who holds the credentials: hosting, domain name and administration must be in your name.
- What is not covered. A contract silent on its exclusions cannot be read.
What we do not promise. That a site will never be compromised: nobody can write that honestly. What we do write is the time to get back online and how far back the backups go. And we put forward no figure on sites left without maintenance: we have not measured it.
We work with Accor and Logis Hôtels hotels. They trust us.
The site, the link and the workstation:
the same team.
Our services rely on ISO 27001 and HDS certified data centres located in France. The link, the workstation and the website are held by the same team, in Rouen. One number when it breaks.
What to remember
- The tool decides the everyday friction, rarely from the outage.
- What really decides: the name next to “who updates, who backs up, who restores, who answers”.
- Every plugin is one more piece of software to maintain, and one more door.
- A backup that has never been restored is not a backup. Ask for the date of the last successful restore.
- Hosting, domain name, administration: in your name. Always.
Let us take the inventory of your site before talking about it
Give us your website address and the name of your hosting provider. We tell you which extensions are no longer maintained, whether the backups exist, and whose name your credentials are in. A written review, not a quote in disguise.