Security · 10 min read

What WordPress maintenance should cost, and what it should include.

Most WordPress sites that get hacked were not attacked by anyone in particular. They were simply left alone for long enough. Here is what keeping one healthy involves, and how to tell a real plan from a monthly invoice.

01

What maintenance actually is

A WordPress site is not one piece of software. It is WordPress itself, a theme, somewhere between five and fifty plugins written by different people, the version of PHP your host runs underneath, and a database holding all of it together. Each of those parts gets updated on its own schedule, and each update can fix a security hole, break something else, or both.

Maintenance is the work of keeping all of those parts current and working together, keeping a copy you can go back to, and noticing quickly when something goes wrong. That is the whole job. It is not the same as content changes, SEO or redesign work, and a plan that blurs those together is usually hard to compare with anything else.

02

What a proper plan includes

These are the six things worth paying for. If a plan does not mention one of them, ask about it directly.

1. Updates, applied with care

WordPress core, the theme and every plugin, checked at least weekly and applied promptly when an update fixes a security problem. Done properly, a backup is taken first, the update is applied, and someone looks at the key pages afterwards: home page, contact form, anything that takes payment. On bigger sites, updates are tested on a staging copy before they touch the live one. PHP versions matter too. When your host retires an old version, a site that has not been kept current can break overnight.

2. Backups that live somewhere else

Files and database, both, on a schedule that matches how often the site changes. Daily is sensible for anything with orders, bookings or a blog. The copies need to be stored off the server, because a backup kept in the same hosting account disappears with it when the account is compromised or suspended. Keep several weeks of history, not just last night's copy, since an infection is often found days after it arrived.

3. Restore tests

The step almost everyone skips. A backup you have never restored is a hope, not a backup. Every few months, someone should take a recent copy and restore it somewhere safe to prove the files and database are complete and that the site actually comes back. The first time you find out a backup is broken should not be the day you need it.

4. Uptime monitoring with a human on the end

A service checks the site every few minutes and sends an alert when it goes down or the security certificate is about to expire. The part that matters is who receives the alert and what they do with it. An email nobody reads at 2 a.m. on a Saturday is monitoring in name only.

5. Security hardening

Most of this is set once and checked occasionally, rather than done weekly:

  • Accounts. Every administrator is a named person who still needs access, with a unique password and two-factor sign-in. Old staff and old developers are removed.
  • Less surface. Unused plugins and themes are deleted, not just deactivated. Every one left installed is code that can still be attacked.
  • Sensible settings. File editing from the dashboard is switched off, file permissions are correct, login attempts are limited, and the hosting account runs a current PHP version.
  • Watching for changes. Something keeps an eye on unexpected new files, new administrator accounts and spam pages showing up in Google.

6. A short report and a named person

Once a month: what was updated, whether backups ran, any downtime, anything that needs a decision. And a person you can reach when something looks wrong, with a stated response time. Without a report, there is no way to tell a plan that is doing the work from one that is just billing.

03

What it costs in the market

Prices vary widely, but plans fall into four rough bands, and the price mostly tracks how much human attention is involved.

  • Bundled with hosting. Many hosts switch on automatic updates and nightly backups as part of the hosting fee, so it costs little or nothing extra. Useful, but nobody checks the site after an update and the backups often sit on the same servers.
  • Basic freelance plans. Usually somewhere in the tens of dollars a month. Updates, backups and an uptime check, mostly automated, with limited checking after updates and little or no time for fixes.
  • Managed plans with a person behind them. Typically around the low hundreds a month. Updates applied and checked, off-site backups, restore tests, hardening, monitoring with a real response, a monthly report and a small amount of time for fixes.
  • Shops, memberships and large sites. Several hundred a month and up. Staging and testing for every update, faster response commitments, and more hours, because a broken checkout costs money by the hour.

What moves a site up or down those bands is fairly predictable: how many plugins it runs, whether it takes payments or holds customer accounts, how fast you need someone to respond, and how much change work is included each month. A five-page brochure site with eight plugins does not need the same plan as an online store with forty.

The comparison that matters

Weigh a plan against what a cleanup costs, not against zero. Our malware removal runs $800 to $3,500 depending on how far an infection has spread, before you count the days of lost enquiries or a Google warning on your domain. A year of solid maintenance on a small site usually costs less than one bad week.

04

What cheap plans quietly leave out

A low price is fine if the work is real. These are the gaps that show up most often when we look at a site that was "on a plan" and still got into trouble:

  • Everything set to update automatically, with no backup first and nobody checking after. The site breaks on a Tuesday night and you find out from a customer on Thursday.
  • Backups kept on the same server. When the hosting account is compromised or suspended, the backups go with it.
  • Backups that have never been restored. The database part turns out to have been failing for months.
  • A security plugin installed and called security. Scanning plugins are good at flagging known problems. They do not remove old admin accounts, delete abandoned plugins or update anything for you.
  • Premium plugins with lapsed licences. The site shows them as up to date because the update channel stopped working, which is worse than showing them as out of date.
05

What happens when nobody maintains it

Neglect is slow and then sudden. A typical path looks like this.

The first few months: nothing visible happens. A few plugins fall behind. One of them gets a security update with a public notice describing the hole it fixes.

Somewhere after that: automated software that crawls the web for that exact plugin version finds your site. Nobody chose you. The bots try every site they can find, and yours answered. The first sign is often subtle: a redirect that only fires for visitors arriving from Google, or hundreds of spam pages under your domain that you never see because you never search for them.

Then the visible part: Google flags the site and visitors get a red warning screen, or your host suspends the account for sending spam. Enquiries stop. If the backups were on the same server, or were never tested, there is no clean copy to go back to.

The other common failure is less dramatic. Your host retires an old PHP version, the site was never updated to cope, and it shows an error page until someone pays for an emergency fix.

If you are already at the warning-screen stage, our guide on what to do when WordPress is hacked walks through the first hour, step by step.

06

Doing it yourself, and what to ask a provider

A small site can be maintained by its owner in about half an hour a month, if you actually do it every month:

  • Take a full backup, files and database, and download a copy to somewhere that is not the server.
  • Apply updates one at a time, checking the home page and contact form after each, and send yourself a test enquiry.
  • Delete any plugin or theme you are not using, and remove any administrator who no longer needs access.
  • Search Google for site:yourdomain.ca and look for pages you did not write.
  • Every few months, restore a backup to a test copy and confirm it works.

If you would rather pay someone, ask these before you sign:

  • How often are updates applied, and does anyone check the site afterwards?
  • Where are backups stored, how long are they kept, and when did you last test a restore?
  • Who gets the downtime alert, and how quickly do they act on it?
  • Is a malware cleanup included if the site is hacked while on the plan, or is it extra?
  • Do I keep full admin access, and do I get my backups if I leave?

A provider who answers all five clearly is probably doing the work. One who answers with a list of plugin names probably is not.

Questions

Common questions about WordPress upkeep.

What owners ask when the renewal invoice arrives, or right after something has broken.

Don't see your question?

Call (902) 225-5280 [email protected]
Q.01

How often should WordPress plugins be updated?

Check weekly and apply security updates as soon as they are released, since that is when the hole becomes public knowledge. Routine feature updates can wait a few days for other sites to find the bugs, as long as a backup is taken before each one.

Q.02

Is it safe to let WordPress update itself automatically?

For minor core releases, generally yes. For plugins and themes it is a trade-off: you get security fixes quickly, but nobody notices if an update breaks a form or a checkout. If you use auto-updates, pair them with daily off-site backups and a quick check of key pages.

Q.03

Where should WordPress backups be stored?

Somewhere other than the server the site runs on, with several weeks of history. A backup inside the same hosting account is lost along with the site if that account is compromised or suspended.

Q.04

What is a restore test, and why does it matter?

It means taking a real backup and restoring it to a test copy to prove the site comes back complete. Backups fail quietly, often on the database side, and a restore test is the only way to find that out before the day you need one.

Q.05

Is paid maintenance worth it for a small brochure site?

It depends on whether anyone will reliably do the monthly routine. A five-page site with few plugins can be kept safe by its owner in half an hour a month. If that is not going to happen, paying for maintenance costs far less than a cleanup.

Ready when you are

Not sure what state your site is in?

Send us the address. We will tell you what is out of date, whether anything looks wrong, and whether it needs a cleanup, some tidying, or nothing at all.

Most enquiries get a reply the same day, usually within a couple of hours.