Website Maintenance: What It Should Cover
Home  /  Blog

Website Maintenance: What It Should Cover

The Short Answer: Proper website maintenance covers five things, updates tested before they go live, backups that have actually been restored once, security monitoring, speed and error checks, and small content edits. Anything narrower is hosting with a nicer name. Judge a plan by what it promises to catch, not by how many hours it bills.

Maintenance is usually sold as a monthly line item and bought as an insurance policy. Neither party says out loud what it is insuring against. So the plan runs quietly for a year, nothing visibly breaks, and the owner starts wondering what exactly the money buys.

Then something does break. A plugin update takes the booking form down on a Friday night. A backup turns out to be six weeks old, or corrupted, or stored on the same server that just failed. And the answer to “was that covered?” depends entirely on a scope nobody read closely at signing.

This guide works through the decision the way a consultant would before signing anything. What the work genuinely contains, what belongs to you rather than the agency, how to read a quote without being sold hours, and how to tell six months in whether the plan is doing anything. The video below covers the practitioner side if you want that grounding first.

The Ultimate WordPress Maintenance Checklist: Backups, Updates, Staging, and Monitoring

Source video: The Ultimate WordPress Maintenance Checklist: Backups, Updates, Staging, and Monitoring

PART 1 · DIAGNOSE

What Website Maintenance Actually Covers

IN BRIEFReal maintenance covers five layers: tested updates, verified backups, security monitoring, performance and error checks, and minor content edits. Hosting covers none of them. If a quote lists only “updates and backups”, it is describing two of the five. That gap is what turns a routine website build into an expensive rescue job.

The word covers too much ground, which is exactly why quotes vary so wildly. Break it into layers and the differences between plans become obvious.

  • Updates, tested before they go live. Core, plugin and theme updates applied on a staging copy first, so a broken checkout is found there rather than by a customer.
  • Backups that have been restored at least once. An untested backup is a belief, not a safeguard. Off-site storage matters as much as frequency.
  • Security monitoring. Malware scanning, login protection, and someone who notices when a plugin you use is disclosed as vulnerable.
  • Performance and error checks. Speed, uptime, broken links, failed forms, 404s and PHP errors, the quiet faults nobody reports until enquiries drop.
  • Small content edits. Price changes, new staff photos, a closed public holiday notice. Usually capped by hours, and the cap is where disputes start.

Two layers are missing from that list on purpose. Hosting is a separate purchase, and so is anything strategic: new pages, campaign landing pages, redesigns. Bundling those in makes a plan look generous and makes the real maintenance harder to audit.

Bottom Line: Maintenance is five layers, not two. Count how many a quote covers before you compare it to any other quote.

Not sure which layers your current plan actually covers?

A short diagnosis maps what is being done, what is assumed, and what nobody owns. See how the Blueprint diagnosis works

BENCHMARK BRIEFING 1 OF 4

Where Website Breakages Actually Come From

IN BRIEFGrouped by vulnerability type, the bulk of what threatens a small business site needs no login at all to exploit. That is the argument for monitoring rather than annual reviews, and it sits behind every serious care plan scope.

Most Common WordPress Vulnerability Types, First Half of 2025
The five most frequently disclosed WordPress vulnerability types in the first half of 2025, their share of all disclosures, and whether exploiting them typically requires an account on the site.
Vulnerability type Share of disclosures Login usually needed?
Cross-Site Scripting (XSS) 34.7% No
Cross-Site Request Forgery (CSRF) 19.0% No
Local File Inclusion (LFI) 12.6% No
Broken access control 10.9% Varies
SQL injection (SQLi) 7.2% Varies

Compiled by IZI Digital Marketing from Patchstack’s 2025 mid-year WordPress vulnerability report, January–June 2025. Not measured client results.

Two figures from the same report explain why the middle column matters so much. Patchstack recorded roughly 6,700 new vulnerabilities in the ecosystem across those six months, and classed 41.5% of them as realistically exploitable, up from 30.4% the year before. Around 89% sat in plugins rather than in the core software, which is the part most owners never think about.

The practical consequence is unglamorous. Nothing here is stopped by good design or by a careful web developer. It is stopped by somebody applying patches promptly, on a schedule, and checking the site still works afterwards.

Bottom Line: The risk lives in plugins, and most of it needs no account to exploit. Update cadence beats every other safeguard on a small business site.

PART 2 · DIAGNOSE

Maintenance, Support and Hosting Are Three Different Purchases

IN BRIEFHosting keeps the server running. Support answers when you ask. Website maintenance is the only one of the three that does work you did not request. Most disputes with a website designer come from paying for one and expecting another.

The distinction sounds pedantic until an invoice arrives. Hosting is infrastructure, uptime, storage, server-level security. Support is reactive. You report a problem, somebody fixes it, sometimes billed by the hour. Maintenance is proactive, and proactivity is the only part that prevents rather than repairs.

Bundled offers blur all three deliberately. “Free hosting and maintenance for the first year” usually means hosting plus whatever the agency feels like doing. When the year ends and the renewal quote arrives, there is no agreed scope to renew against.

Consultant’s Note: Ask one question before signing any plan: “If my site goes down at 9pm on a Saturday, what happens?” The answer separates a maintenance agreement from a maintenance promise. If there is no stated response window and no named person, you have bought a monitoring dashboard, not cover.
Bottom Line: Buy the three separately, or at least price them separately. Bundles hide which one you are actually short of.

BENCHMARK BRIEFING 2 OF 4

Where the Hours in a Maintenance Retainer Go

IN BRIEFModelled as shares of a month rather than hours, testing and verification dominate a sound retainer, not content edits. Owners who expect a plan to behave like a design service are usually surprised by that split, and by how little it resembles one-off speed work.

Modelled Split of Monthly Effort in a Small Business Maintenance Plan
An illustrative model of how monthly effort in a small business website maintenance plan distributes across task areas, with the working cadence for each area.
Task area Modelled share of monthly effort Cadence
Updates and post-update testing

30%

Weekly
Security monitoring and scans

16%

Continuous
Backups and restore verification

15%

Daily, tested quarterly
Broken links, forms and 404s

13%

Monthly
Speed and Core Web Vitals checks

12%

Monthly
Small content edits

9%

On request
Reporting and review

5%

Monthly

Illustrative model by IZI Digital Marketing, built on standard WordPress care-plan task lists and Google’s Core Web Vitals documentation. Not measured client results.

Roughly six in ten units of effort go into updating, securing and verifying, which produces nothing visible when it succeeds. Content edits, the part owners notice most, sit near the bottom. A plan weighted the other way around is a design retainer being sold as protection.

Bottom Line: Good maintenance mostly produces non-events. Judge it on what did not happen, not on what you can see.

PART 3 · DESIGN

In-House, Retainer or Call Someone When It Breaks?

IN BRIEFThe right model follows how much the site earns and how fast a failure hurts. A brochure site with no forms can survive ad-hoc care; a site that takes bookings cannot. Match the model to revenue dependency before you compare any two website plans.

There are only three honest models, and the choice turns on one question: how many hours of downtime before it costs you a customer you would have kept?

DECISION BOX · HOW TO COVER YOUR SITE

Option Fits when Response speed Main risk
Ad-hoc, call when broken Brochure site, no forms or bookings Days Faults found by customers
Agency retainer Site generates enquiries or orders Hours, if stated in writing Vague scope, unused hours
In-house or hybrid Complex site, technical staff already employed Immediate Single point of failure when they leave

Verdict: Choose a retainer once the site produces enquiries you would miss for a day. Stay ad-hoc while it is a digital brochure, and go hybrid only if the technical person is already on payroll for other reasons.

Bottom Line: Cover follows revenue dependency. The more the site earns unattended, the less you can afford to notice problems late.

BENCHMARK BRIEFING 3 OF 4

What Each Kind of Neglect Costs You Later

IN BRIEFModelled by recovery effort rather than ringgit, the expensive failures are the slow ones, lost rankings and silent form breakages, not dramatic outages. Both are also the failures a monthly technical check catches earliest.

Modelled Recovery Burden by Type of Neglected Maintenance
An illustrative model comparing how long different neglected website maintenance failures typically go unnoticed and how much recovery effort each demands relative to routine monthly maintenance.
Failure Typically noticed after Modelled recovery effort
Site fully down Minutes to hours

Low

Contact form silently failing Weeks

High

Malware or spam injection Days to weeks

Very high

Gradual speed decay Months

Medium

Ranking loss from broken pages Months

Severe

Illustrative model by IZI Digital Marketing, built on failure patterns described in Google’s crawling and indexing error documentation. Not measured client results.

The pattern is consistent: the faster you notice, the cheaper the fix. An outage announces itself, so it gets solved the same day. A form that stops emailing announces nothing, and by the time somebody asks why the phone went quiet, the enquiries are gone for good.

Bottom Line: Loud failures are cheap. Quiet ones are expensive, and monitoring exists almost entirely for the quiet ones.

Worried the quiet failures are already running?

A one-off check on forms, indexing and speed usually finds them in an afternoon. Review our website design and care approach

PART 4 · DEPLOY

What Belongs to You, Not to the Agency

IN BRIEFDomain, hosting account, admin logins and a copy of the backup should sit in your name regardless of who does the work. Ownership is the difference between changing supplier and rebuilding, and it matters most during a site migration.

This is the part of the arrangement nobody raises while the relationship is good. It only surfaces when you want to leave, which is exactly the wrong moment to discover the domain is registered to somebody else.

  • Domain registration in your company name. Not the agency’s, not a staff member’s personal email. Check the registrar record, not the invoice.
  • Hosting account under your billing. Reseller hosting is fine, provided you can be given direct access on request.
  • Administrator login for the site. One that stays yours, separate from the agency’s working accounts.
  • A backup copy you can reach. Stored somewhere you control, not only in the agency’s dashboard.
  • Analytics and Search Console ownership. You should be the property owner; the agency should be a user.
Consultant’s Note: None of this implies bad faith. Most access tangles happen because a developer set things up quickly during a launch and nobody tidied afterwards. Ask for an access audit at the six-month mark, when it is an admin task rather than a negotiation.
Bottom Line: Own the domain, the hosting, the admin account and a backup. Everything else is negotiable.

BENCHMARK BRIEFING 4 OF 4

How Malaysian Incident Reports Moved Through Late 2025

IN BRIEFReported intrusions fell across the final quarter of 2025 while data-breach reports rose, which is a shift in attack shape rather than a fall in risk. It is context worth having before you choose a digital marketing partner to look after the site.

Malaysian Cyber Incident Reports, Q3 to Q4 2025
Cyber incidents reported to Malaysia’s national computer emergency response team in the third and fourth quarters of 2025, by category, with the direction of change between quarters.
Category Q3 2025 Q4 2025 Direction
All reported incidents 2,020 1,881 Down 7%
Intrusion, including defacement 173 101 Down
Data breach 142 171 Up 20%

Compiled by IZI Digital Marketing from MyCERT’s Cyber Incident Quarterly Summary Report, Q4 2025. Not measured client results.

Within the quarter, reported intrusions ran at 53 in October, 26 in November and 22 in December. Read that alongside the rising data-breach column and the message is not “relax”. It is that credential and data exposure is doing the work that defacement used to, and neither is prevented by anything visible on the front end of your site.

Bottom Line: Fewer defacements does not mean fewer problems. Login hygiene and patching still carry the load.

PART 5 · DRIVE

How to Tell Whether the Plan Is Actually Running

IN BRIEFFour checks settle it in under an hour: submit a test enquiry, ask for a restore, read a monthly report, and check plugin update dates. Any plan that cannot pass all four is being paid for something it is not doing.

How to audit a website maintenance plan in an hour

Run these four checks yourself, once a quarter. They need no technical skill and no cooperation from anyone.

  1. Send a test enquiry. Use the live contact form as a customer would, from a personal email, and confirm it arrives in the inbox that actually gets read.
  2. Ask for a restore, not a backup. Request that last week’s backup be restored to a staging copy. A provider who cannot do this in a working day does not have a working backup.
  3. Read one monthly report properly. Look for what was updated, what broke, and what was decided, not a dashboard screenshot with green ticks.
  4. Check the plugin update dates. In the admin panel, look at when things were last updated. Months of untouched plugins is the whole answer.
Bottom Line: A maintenance plan you never test is an assumption. Test it quarterly and it becomes a control.

FAQ

Frequently Asked Questions

1. How often should website maintenance be done?

Weekly for updates, continuously for security monitoring, monthly for speed and error checks. That cadence depends on how much the site earns, a booking or e-commerce site needs weekly attention, while a small brochure site can reasonably run on a monthly cycle with automated monitoring in between.

2. Is website maintenance the same as hosting?

No. Hosting keeps the server running and is usually automated. Website maintenance is human work done on your specific site, updating, testing, monitoring and fixing. It depends on your setup whether they come from the same supplier, but they should always be priced and scoped separately.

3. What happens if I skip website maintenance for a year?

Usually nothing visible, until something fails badly. It depends on the plugins involved, but a year of missed patches leaves known vulnerabilities open, and updating a long-neglected site becomes a project rather than a task because several versions must be jumped at once.

4. Can I do website maintenance myself?

Yes, for a simple site, provided you use a staging copy for updates and verify backups. It depends on your tolerance for a Saturday spent fixing a plugin conflict. Most owners find the value in delegating not the doing, but the remembering.

5. Should maintenance include SEO work?

No, and bundling them hides both. Maintenance keeps the site healthy so search engines can crawl it; SEO decides what the site should rank for. Technical overlap exists around speed and errors, but strategy and content belong to a separate scope with separate goals.

THE VERDICT

Buy the Scope, Not the Hours

Website maintenance is bought badly because it is compared badly. Two quotes with similar monthly figures can cover entirely different work, and the cheaper one is often cheaper because it quietly excludes testing, restore verification and monitoring, the three things that decide whether a failure is a nuisance or a week.

So compare scopes, not prices. Count the five layers. Ask what happens at 9pm on a Saturday. Confirm the domain and backups are yours. Then run the four checks each quarter, and you will know within a year whether the plan is protecting anything.

Not sure what your current website maintenance actually covers?

Book a free Blueprint consultation, we’ll audit the scope you’re paying for against the five layers, show you which gaps carry real risk, and hand you a plain checklist you can take to any supplier.

Book my free consultation

Have a campaign in mind? Let's talk.