What maintenance actually is
A WordPress site is not one piece of software. It is WordPress itself, a theme, somewhere between five and fifty plugins written by different people, the version of PHP your host runs underneath, and a database holding all of it together. Each of those parts gets updated on its own schedule, and each update can fix a security hole, break something else, or both.
Maintenance is the work of keeping all of those parts current and working together, keeping a copy you can go back to, and noticing quickly when something goes wrong. That is the whole job. It is not the same as content changes, SEO or redesign work, and a plan that blurs those together is usually hard to compare with anything else.
What a proper plan includes
These are the six things worth paying for. If a plan does not mention one of them, ask about it directly.
1. Updates, applied with care
WordPress core, the theme and every plugin, checked at least weekly and applied promptly when an update fixes a security problem. Done properly, a backup is taken first, the update is applied, and someone looks at the key pages afterwards: home page, contact form, anything that takes payment. On bigger sites, updates are tested on a staging copy before they touch the live one. PHP versions matter too. When your host retires an old version, a site that has not been kept current can break overnight.
2. Backups that live somewhere else
Files and database, both, on a schedule that matches how often the site changes. Daily is sensible for anything with orders, bookings or a blog. The copies need to be stored off the server, because a backup kept in the same hosting account disappears with it when the account is compromised or suspended. Keep several weeks of history, not just last night's copy, since an infection is often found days after it arrived.
3. Restore tests
The step almost everyone skips. A backup you have never restored is a hope, not a backup. Every few months, someone should take a recent copy and restore it somewhere safe to prove the files and database are complete and that the site actually comes back. The first time you find out a backup is broken should not be the day you need it.
4. Uptime monitoring with a human on the end
A service checks the site every few minutes and sends an alert when it goes down or the security certificate is about to expire. The part that matters is who receives the alert and what they do with it. An email nobody reads at 2 a.m. on a Saturday is monitoring in name only.
5. Security hardening
Most of this is set once and checked occasionally, rather than done weekly:
- Accounts. Every administrator is a named person who still needs access, with a unique password and two-factor sign-in. Old staff and old developers are removed.
- Less surface. Unused plugins and themes are deleted, not just deactivated. Every one left installed is code that can still be attacked.
- Sensible settings. File editing from the dashboard is switched off, file permissions are correct, login attempts are limited, and the hosting account runs a current PHP version.
- Watching for changes. Something keeps an eye on unexpected new files, new administrator accounts and spam pages showing up in Google.
6. A short report and a named person
Once a month: what was updated, whether backups ran, any downtime, anything that needs a decision. And a person you can reach when something looks wrong, with a stated response time. Without a report, there is no way to tell a plan that is doing the work from one that is just billing.
What it costs in the market
Prices vary widely, but plans fall into four rough bands, and the price mostly tracks how much human attention is involved.
- Bundled with hosting. Many hosts switch on automatic updates and nightly backups as part of the hosting fee, so it costs little or nothing extra. Useful, but nobody checks the site after an update and the backups often sit on the same servers.
- Basic freelance plans. Usually somewhere in the tens of dollars a month. Updates, backups and an uptime check, mostly automated, with limited checking after updates and little or no time for fixes.
- Managed plans with a person behind them. Typically around the low hundreds a month. Updates applied and checked, off-site backups, restore tests, hardening, monitoring with a real response, a monthly report and a small amount of time for fixes.
- Shops, memberships and large sites. Several hundred a month and up. Staging and testing for every update, faster response commitments, and more hours, because a broken checkout costs money by the hour.
What moves a site up or down those bands is fairly predictable: how many plugins it runs, whether it takes payments or holds customer accounts, how fast you need someone to respond, and how much change work is included each month. A five-page brochure site with eight plugins does not need the same plan as an online store with forty.
Weigh a plan against what a cleanup costs, not against zero. Our malware removal runs $800 to $3,500 depending on how far an infection has spread, before you count the days of lost enquiries or a Google warning on your domain. A year of solid maintenance on a small site usually costs less than one bad week.
What cheap plans quietly leave out
A low price is fine if the work is real. These are the gaps that show up most often when we look at a site that was "on a plan" and still got into trouble:
- Everything set to update automatically, with no backup first and nobody checking after. The site breaks on a Tuesday night and you find out from a customer on Thursday.
- Backups kept on the same server. When the hosting account is compromised or suspended, the backups go with it.
- Backups that have never been restored. The database part turns out to have been failing for months.
- A security plugin installed and called security. Scanning plugins are good at flagging known problems. They do not remove old admin accounts, delete abandoned plugins or update anything for you.
- Premium plugins with lapsed licences. The site shows them as up to date because the update channel stopped working, which is worse than showing them as out of date.
What happens when nobody maintains it
Neglect is slow and then sudden. A typical path looks like this.
The first few months: nothing visible happens. A few plugins fall behind. One of them gets a security update with a public notice describing the hole it fixes.
Somewhere after that: automated software that crawls the web for that exact plugin version finds your site. Nobody chose you. The bots try every site they can find, and yours answered. The first sign is often subtle: a redirect that only fires for visitors arriving from Google, or hundreds of spam pages under your domain that you never see because you never search for them.
Then the visible part: Google flags the site and visitors get a red warning screen, or your host suspends the account for sending spam. Enquiries stop. If the backups were on the same server, or were never tested, there is no clean copy to go back to.
The other common failure is less dramatic. Your host retires an old PHP version, the site was never updated to cope, and it shows an error page until someone pays for an emergency fix.
If you are already at the warning-screen stage, our guide on what to do when WordPress is hacked walks through the first hour, step by step.
Doing it yourself, and what to ask a provider
A small site can be maintained by its owner in about half an hour a month, if you actually do it every month:
- Take a full backup, files and database, and download a copy to somewhere that is not the server.
- Apply updates one at a time, checking the home page and contact form after each, and send yourself a test enquiry.
- Delete any plugin or theme you are not using, and remove any administrator who no longer needs access.
- Search Google for
site:yourdomain.caand look for pages you did not write. - Every few months, restore a backup to a test copy and confirm it works.
If you would rather pay someone, ask these before you sign:
- How often are updates applied, and does anyone check the site afterwards?
- Where are backups stored, how long are they kept, and when did you last test a restore?
- Who gets the downtime alert, and how quickly do they act on it?
- Is a malware cleanup included if the site is hacked while on the plan, or is it extra?
- Do I keep full admin access, and do I get my backups if I leave?
A provider who answers all five clearly is probably doing the work. One who answers with a list of plugin names probably is not.
