Skip to content
WordPress Maintenance

Your site, measured and corrected every month

We do not run through a short checklist and declare the job done. We measure every page, every request, every loaded resource and every setting that affects speed, security or position in Google. You get the numbers, the changes and the reasoning behind them.

Everypage, measured individually
EveryHTTP request, analysed
Everyplugin, configured and tracked
Monthlyreport with comparable numbers
The problem

A site does not break. It degrades slowly.

Nothing falls over visibly. Page weight grows as content is added. A plugin update rewrites the markup and flattens the heading structure Google was relying on. A security header disappears after a server move. Six months later the site is slower, less accessible and less visible, and nobody noticed because nobody was measuring.

We set numeric thresholds

Every discipline gets a concrete target, agreed in advance. LCP under 2.5 seconds. INP under 200 milliseconds. Accessibility at 100. Zero unresolved critical vulnerabilities. Thresholds turn "the site is fine" from an opinion into a verifiable statement.

We measure everything, not a sample

Every address in the contract, on mobile and desktop, with real visitor data where traffic allows and lab data where it does not. Results are kept, so this month always compares against last month.

We fix, then re-measure

An unmeasured fix is a hope. Every change is validated with exactly the test that found the problem, and the before and after figures go into your report.

What we cover

Six disciplines, audited every month

Each with its own method, its own tools and its own pass criteria.

Security

One defined countermeasure per class of attack, not a plugin installed and forgotten. Response headers, application hardening, filtering at the network edge, file integrity monitoring, least privilege on the filesystem and a tested recovery procedure.

Verified with: vulnerability scanners, checksum comparison, TLS analysis, access logs.

Performance

Core Web Vitals for every page, on mobile and desktop. Server response time, caching strategy, image processing, font loading, script execution and the cost of database queries, each measured separately, so we identify the real bottleneck rather than guess it.

Verified with: Lighthouse, CrUX field data, the request waterfall, the slow query log.

Technical SEO for Google

Titles, heading hierarchy, canonicals, internal link depth, orphan pages, crawl budget, index coverage, redirect chains and structured data validity. Checked for every address, reported for every address.

Accessibility

WCAG 2.2 level AA as the starting point. Automated testing catches roughly a third of real problems, so contrast, focus order, keyboard traps, form semantics and the screen reader journey are also checked by hand.

Readability by AI

Search no longer means only people typing. Assistants and agents read the site as structured text. Valid JSON-LD, semantic HTML, consistent entities, an llms.txt declaration and data rendered on the server rather than injected by script.

Configuration and the module lifecycle

A typical WordPress site runs between fifteen and forty plugins, most configured once and never revisited. We take responsibility for configuring each one: the caching layer, image processing, the SEO plugin, forms, the security suite, the backup system, analytics and the CDN. Each set up for your site rather than left on defaults, checked for conflicts (two caching layers, two plugins writing canonicals, two optimisers processing the same file), tracked for abandonment and replaced when it becomes a vulnerability.

The method

What "we measure everything" actually means

We do not tick a fixed list. For every page in the contract we work through the layers below, and every item found is recorded, measured and either fixed or explained.

The layers analysed for every page
LayerWhat we inventoryWhat we measure
Network and delivery DNS, TLS, HTTP/2 and HTTP/3, CDN, compression, response headers Time to first byte, TLS negotiation time, edge cache hit rate, compressed size against real size
Server and PHP PHP version, OPcache, memory limits, worker processes, cron Page generation time, memory used per request, scheduled tasks that never run
Database Queries per page, indexes, autoloaded options, revisions, transients Query count, slowest queries, options table size, total time spent in the database
Every request on the page All loaded files: CSS, JavaScript, fonts, images, iframes, third party tags How many requests, from which domains, how many bytes each, how long they block rendering, which can be deferred or removed
Rendering Load order, critical CSS, fonts, the main image, elements that shift LCP, INP, CLS, total blocking time, on mobile and desktop, separately
Document structure Heading hierarchy, semantic landmarks, alt attributes, form labels, focus order Accessibility score, contrast errors, elements unreachable by keyboard, problems found by hand
Signals for Google Title, description, canonical, robots, structured data, internal links, sitemap What is indexed against what should be, orphan pages, depth from the home page, schema validation errors
Security Response headers, file permissions, accounts, plugin versions, entry points Missing or misconfigured headers, known vulnerabilities, unexpectedly modified files, access attempts
Content and media Every image, video, PDF and uploaded file Real size against displayed size, format, compression, whether dimensions are declared, whether lazy loading is applied correctly
Why not a fixed list

A fixed checklist ages. Last year INP did not exist as a metric. Two years ago nobody was thinking about the site being read by AI agents. The method stays the same, we inventory every layer and measure what we find there, but the concrete list of checks is updated every month, alongside what Google asks for and what appears as a vulnerability.

Process

What a month actually looks like

The same sequence every cycle, so results are comparable and nothing depends on anyone's memory.

Collection

Automated scans run against every address in the contract: performance on mobile and desktop, header and certificate inspection, accessibility audit, structured data validation, index coverage, and a plugin version inventory compared against vulnerability databases.

Comparison

Results are compared against the previous cycle. Anything that moved in the wrong direction is a regression and its cause is traced: a content change, a plugin update, a new third party tag or a change at the host.

Intervention

Fixes are applied on staging first, verified there, then promoted. Every change is recorded together with what it was meant to improve, so a later regression can be tied to the decision that produced it.

Re-check and report

The same tests run again after the changes. You get the before and after figures for every address, what we changed, what we recommend and what is blocked by a decision that belongs to you rather than to us.


Records and change control

Every action leaves a trace: what changed, when, by whom, why and how to roll it back. Backups are verified by restoring them, not by ticking that the file exists. Access is least privilege, on individual accounts, not on a shared password.

If you are working towards ISO 27001, this overlaps with the Annex A controls on change management, logging, backup, access control and supplier relationships. We are not a certification body and we will not say your site is certified, but the audit trail is exactly the one an auditor asks for.

What we do not do

  • We do not promise a score that depends on a decision that belongs to you
  • We do not apply updates straight to production without staging
  • We do not report a fix we have not re-measured
  • We do not keep a plugin alive just because removing it is inconvenient
  • We do not guarantee a site cannot be broken into. Nobody honest does
Plans

The price depends on how many pages we manage

Because that is what determines the real volume of work. A page under management is audited, optimised, re-checked and reported on in every cycle.

Essential

UP TO 10 PAGES

150

plus VAT, per month
12 month contract


  • All six disciplines
  • Monthly report with figures for every page
  • Premium licences for caching and image optimisation, included
  • Verified backups, held off the server
  • Cloudflare configured, not merely switched on
  • Incident response, included
Start with Essential
Most chosen

Professional

UP TO 25 PAGES

220

plus VAT, per month
12 month contract


  • Everything in Essential
  • Staging environment maintained permanently
  • Structured data for every page type
  • Search Console and indexing monitoring
  • In depth quarterly audit
Start with Professional

Business

UP TO 50 PAGES

400

plus VAT, per month
12 month contract


  • Everything in Professional
  • Content Security Policy, implemented
  • Performance budgets enforced per page type
  • Priority on incidents
  • Dedicated point of contact
Start with Business
Why a 12 month contract

Because one month means nothing in this work. The first month goes on inventory and fixing what is broken, the second on stabilisation, and measurable results in Google appear after the third. A one month subscription would mean taking your money for the hard part and leaving exactly when it starts to produce.

Billing stays monthly, so you do not pay a year in advance. What is committed for 12 months is the length of the engagement, so that both of us work on a horizon where results can actually be seen.

Above 50 pages, or for WooCommerce stores where catalogue size fundamentally changes the work, we quote individually.

Frequently asked questions

How does the contract work?

The engagement runs for 12 months and is billed monthly, so you do not pay a year up front. The one year commitment exists because the first month goes on inventory and fixing what is broken, the second on stabilisation, and measurable results in Google appear after the third. A one month subscription would mean paying for the hard part and never reaching the part that produces.

What exactly counts as a page?

Any address we take responsibility for measuring and optimising: a page, an article, a product, a category or a campaign page. We agree the list together at the start and adjust it as the site changes.

Do I have to move hosting to you?

No. The service works on the hosting you already have. Some optimisations do depend on server level control, for example HTTP headers, PHP configuration and object caching. Where we do not have access, we tell you exactly what stays untouched and what it measurably costs you.

How do you relate to ISO 27001?

We are not a certification body and we will never claim your site is certified. What we do is keep the evidence an auditor asks for: change records, access control, verified backups, logs and a documented recovery procedure.

What happens if the site is compromised?

We isolate it, preserve the evidence, restore from a backup verified as clean, identify and close the entry point, rotate every credential, request review wherever a browser or search engine flagged the site, then give you a written report on what happened. The response is included, not invoiced separately at the worst possible moment.

Can we start with an audit, before the subscription?

Yes, and for most sites it is the natural step. The audit covers all six disciplines and you get the conclusions whether or not you continue. You will know exactly what you would be buying.

Tell us your website address

We analyse it properly and tell you exactly what we would do, including the cases where the honest answer is that you do not need us.

EN

Request a free audit

Tell us your website address. We review it across all six disciplines and send you the findings, whether or not we end up working together.

Your details come straight to us. We do not use them for anything else and we do not pass them on.