The site was delivered, the invoice is paid, the team has ticked off the project. A few months later you notice that the contact form no longer sends anything, or a customer writes that the payment page gives an error, or that their browser shows a red warning. Nobody changed anything, and yet something broke.
This happens because a site is not a finished object. It is a service that runs on a server, on a programming language, on a platform and on dozens of integrations, and all of them change without asking you. If nobody keeps up with them, the site appears to work, then breaks suddenly.
Below you will find what real upkeep means, point by point, what is safe to leave on automatic and what is not, how to tell you are paying for nothing and what to ask for in a contract. At the end there is a checklist you can go through on your own.
Why a site does not stay “done”
WordPress publishes new versions a few times a year, and between them come minor updates, many with security fixes. The theme and the plugins each have their own rhythm: on a typical site with 20-30 plugins, updates show up almost every week. Each one fixes something, sometimes a vulnerability already exploited by bots that look for sites that have not been updated.
Under WordPress sits PHP, which changes versions and drops old functions. The hosting provider moves the server to a new version and an old theme starts throwing errors. Above sit the browsers and Google, which change their requirements around speed, security and the way they display results.
And around it all sit the integrations: the payment processor, the courier, the invoicing software, the email service. All of them have APIs that change, get retired or require new keys. An old courier API that stops responding does not show an error on your site. Orders simply stop getting shipping labels, and you find out when customers ask where their parcel is.
What real maintenance means, point by point
“Maintenance” is a word that covers both one hour a month of clicking “Update all” and a genuine service. The difference shows in the list.
Updates applied on time, but tested
Updates are applied regularly, weekly is a good rhythm, and security fixes within a few days at most. But not blindly. Either they are applied first on a copy of the site and the important pages are checked, or they are applied on the live site and someone checks right after: the home page, a product page, the cart, the checkout, the contact form. Neither option means “auto-update on everything”. More on that below, in a separate section.
Automatic backup, in another place, tested
The backup runs daily, without human intervention, and is kept somewhere other than the site’s server. A backup on the same server disappears together with the server. And it gets tested: periodically, someone restores the site from the backup to a test address and checks that everything is there. A backup that nobody has ever restored is an assumption, not a safety net.
Uptime monitoring, with alerts
A service checks the site every few minutes and sends an alert when it does not respond or responds with an error. The goal is simple: you find out before your customers do. If the news that the site is down reaches you from a customer, the monitoring does not exist.
Security monitoring
Files modified compared to the original version, successful logins from unusual places, administrator users that appeared overnight. These are the signs of a compromised site, and they are only visible if someone looks for them. A firewall and a scanner help, but someone has to read what they report. What a security upkeep service for WordPress tracks on a regular basis is exactly this short list, checked constantly.
A log of what was done
A simple record: the date, what was updated, what came up. When something breaks three weeks later, the log tells you what was touched last.
A monthly check of the things that break silently
Forms, order emails and payments have an unpleasant property: when they break, they give no visible error. The form shows “Message sent” and the message goes nowhere. The order confirmation email leaves and is rejected by the recipient’s server. Card payment gets stuck at the last step for only some of the customers. Once a month, someone sends a test form, places a test order and checks whether the emails arrived.
Renewals: domain, certificate, licenses
The domain expires once a year and, if it is not paid, the site and the email disappear on the same day. The SSL certificate usually renews automatically, but “usually” is not “always”. The licenses of the theme, of premium plugins and of email services expire too, and a plugin without a license no longer receives updates, including the security ones. All of them have a date in the calendar and a person responsible.
Speed and errors from Search Console
A monthly check of speed on mobile and desktop, plus a pass through Search Console, where Google tells you itself which pages it cannot access, what is slow and what has dropped out of the index. It takes no more than a quarter of an hour, but without it you only learn about problems when traffic drops.
A person who responds within an agreed time
The rest can be partly automated. This point cannot. When the site is down or the checkout does not work, someone responds in hours, not days, and that time is written down somewhere.
What is safe to leave on auto-update and what is not
WordPress can apply updates on its own, and the temptation is to turn everything on and forget about it. The rule from practice is split.
| Component | Auto-update | Why |
|---|---|---|
| Minor updates of the WordPress core | Yes | They are security and bug fixes, tested on millions of sites, with a very low risk of breaking something. |
| Small plugins, with no visual impact | Usually yes | A redirects or sitemap plugin rarely changes anything visible. It still gets checked afterwards. |
| Large plugins (SEO, forms, cache) | No | They change behaviours, sometimes the data structure too. A new cache version can serve empty pages without any error. |
| The theme and the page builder | No | The theme and the builder are updated together. If only one of them is updated, pages can go empty while the server keeps answering “everything is fine”. |
| WooCommerce and the payment, courier and invoicing plugins | No | An update can break the checkout or stop shipping labels from being issued. The customer sees a nice page and an order that never completes. |
| The PHP version | No | It is tested on a copy first. An old theme can produce a white error page across the whole site. |
The common reason is that a broken update does not announce itself. The server responds with HTTP 200, the page loads, only it is empty or the pay button does nothing. Uptime monitoring does not catch this. Only a person looking at the site after the update catches it.
Checking after an update means opening the site without cache and without being logged in, like a visitor. As a logged-in administrator, many cache plugins show you the fresh version, while visitors get something else.
How to tell you are paying for nothing
If you already have a maintenance contract, the signs that the service exists only on the invoice are fairly clear.
- You receive no report, not even a monthly email with what was done.
- You cannot see the date of the last backup and nobody can tell you the same day.
- The WordPress version is a few months behind. You can see it directly in the admin area, in the bottom corner or under “Dashboard”, “Updates”.
- Plugins have updates waiting, and the number in the “Updates” menu has two digits.
- The certificate has expired at least once and you found out from the browser warning.
- The site went down and nobody told you; you found out from a customer or on your own.
- Answers to a problem come in days, not hours.
Any one of these is a sign. Three together mean you do not have maintenance, you have a subscription.
What to ask for in a maintenance contract
A good contract is recognised by how concrete it is. “Monthly maintenance” says nothing.
- The list of activities, point by point: updates, backup, monitoring, checks, renewals. What is not on the list does not get done.
- The frequency for each one: weekly, daily, monthly. Not “periodically”.
- Response time and resolution time for incidents, separately for “site down” and for “something is not working”. Hours, not days.
- Proof of backup: where it is kept, how often, for how long, when it was last tested by restoring it.
- A short monthly report: what was updated, what came up, what is next. One page is enough.
- Access to accounts and sources: domain, hosting, WordPress admin, the theme and the plugins with their licenses. The site is yours, not the provider’s.
- What happens when the contract ends: handover of the access details, the latest backup and the log, within a written deadline.
If the provider cannot answer these points on one page, they usually do not do them in practice either. What a WordPress upkeep and updates service includes, for example, is easy to compare with the list above.
What it costs to do nothing
The cost of maintenance shows up monthly on the invoice. The cost of not having it shows up once, but much larger, and you do not choose when it comes.
A site compromised through an outdated plugin means, in the order you feel them: cleaning the site, which can take from a few hours to a few days depending on how deep the infection went; spam pages indexed by Google, which lower your positions and can take months to disappear from the results; sometimes a warning in the browser or in Google’s results, which stops almost all traffic until it is lifted; and your team’s time, which instead of selling goes to answering confused customers and suppliers.
An expired domain means the site and the email are off. A checkout broken by an unchecked update means lost orders without any alert, sometimes for days in a row.
As an order of magnitude, an emergency intervention usually costs as much as many months of upkeep, and the lost sales and positions are not part of that invoice.
Maintenance does not mean nothing will ever break. It means that, when something breaks, there is a backup from yesterday, an alert within minutes and a person who knows what was touched last.
Checklist
- The WordPress version is the current one or at most one behind.
- The number of updates waiting is zero or close to zero.
- You know where the latest backup is, how old it is and when it was restored as a test.
- Uptime monitoring exists and you know who receives the alert.
- Someone checks modified files and logins at least weekly.
- The contact form and the order email were tested this month.
- Card payment was tested with a real order this month.
- The domain, the certificate and the licenses have their expiry dates noted and a person responsible.
- Search Console was opened this month and has no unresolved errors.
- There is a log of what was done, with dates.
- The response time for “site down” is written in a contract.
- You have access to all accounts: domain, hosting, admin, licenses.
Log in to the site’s admin area and write down three things: the WordPress version, the number of updates waiting and the date of the last backup. The first two are under “Dashboard”, “Updates”. The third you look for in the backup plugin or ask your provider for. If you cannot find it, you already have your answer.