@Heisenberg - Have you considered other platforms such as Jekyll? This way, you won't need to worry about security as much as Wordpress. For example, looking through a few sites linked here, I can already see potential problems and plugins. For example, Divi Builder had a security vulnerability allowing arbitrary files to be downloaded. Having the /wp-admin/ unchanged makes it perfect for an automated scanner to execute the exploit. However, the sites people have linked to here are up to date with plugins, but imagine if a zero-day that can be automatically executed.
Wordpress is a PITA to manage in terms of security and security plugins won't help because it'll always end up being a plugin you've installed having a zero-day vulnerability that you aren't aware of until it's too late.