Hosting, Security & Support

Website maintenance that keeps the site current, safe and edited

A website is a running system with dependencies that change whether you touch it or not. Maintenance is the difference between a site that ages gracefully and one that becomes a rebuild.

What is website maintenance?

Website Maintenance is the ongoing work of keeping a live site current and safe: core, plugin and dependency updates, security patching, uptime checks, broken link and form testing, and the content changes your team needs published. It suits Australian businesses running WordPress or a custom site with nobody internally responsible for it.

Get a fixed written quote
Typical timeline
Ongoing, with a monthly cycle and a report
What drives cost
Mainly the number and complexity of dependencies, how business critical the site is, how much content change work you want included.
Best for
Sites with no internal developer and content that changes regularly
You own
The site, the code, the accounts and the full change history
Built with
Staged updates, patch monitoring, uptime checks, monthly reporting
The changeBeforePlugins three versions behindContact form silently brokenBackups nobody has restoredNo one owns the siteAfterUpdates tested on stagingForms checked every monthRestores rehearsed offsiteA named person accountable
Most compromised small business sites were running a vulnerability with a patch available.

Your handover

The unpatched WordPress problem in Australian small business

Walk through the sites of a hundred Australian SMEs and you will find a consistent picture. WordPress core is a version or two behind. There are nineteen plugins installed, four deactivated but still present on disk, and two abandoned by their authors years ago. The admin has five accounts, two belonging to people who left, none with two factor authentication. Nobody has logged in since the agency that built it stopped returning calls.

  1. 01Weekly updates applied via staging
  2. 02Continuous uptime, malware and certificate monitoring
  3. 03Monthly backup restore verification
  4. 04Broken link, form and checkout testing
  5. 05Monthly allowance of content and small design changes
  6. 06Quarterly plugin and user access review
  • Core Web Vitals tracking against agreed thresholds
  • Short written monthly report with recommendations
  • Documented change log you keep permanently
More on the unpatched WordPress problem in Australian small business

This is not carelessness so much as an ownership gap. The site was a project with an end date, and no one converted it into an operating responsibility. The consequence is predictable, because compromise almost never begins with a sophisticated attacker choosing your business. It begins with an automated scanner testing a published vulnerability against every site on the internet, finding an outdated plugin, and injecting spam pages or a redirect. The first sign is usually a customer mentioning something odd, or a search console warning, weeks after the fact. Maintenance is unglamorous precisely because it is the work that prevents an event you then never hear about.

Content changes: the part most plans quietly exclude

Read the fine print on many maintenance plans and you will find they cover updates and monitoring only. Ask for a new team member added to the about page and it becomes a separate job with its own approval loop. That is how sites drift out of date: not because anyone decided to neglect them, but because the friction of a small change exceeded the motivation to make it.

Send an email describing what you want and we do it, with a reply confirming it is live

We include a monthly allowance of change work, and we deliberately keep the request process short. Send an email describing what you want and we do it, with a reply confirming it is live. Typical requests are new staff profiles, updated service descriptions, a seasonal banner, a price list PDF swapped, a new location added, a blog post formatted and published. Where a request is larger than the allowance, we say so before starting and quote it separately rather than silently eating into next month. If your team would rather do this work themselves, we will train them and reduce the plan accordingly, which is usually the right answer for organisations with a marketing coordinator.

How the engagement runs

Why every update goes to staging first

Applying updates directly to a live site works right up until it does not, and the failure mode is public. A plugin update changes a function another plugin depends on, a theme update overwrites a customisation someone made in a hurry three years ago, or a major version of the CMS deprecates something quietly. Discovering that on the production site during business hours is an avoidable choice.

  1. 01Stage 1Take a fresh backup of files and database before anything is touched
  2. 02Stage 2Refresh the staging environment so it reflects current production
  3. 03Stage 3Apply updates on staging and review the release notes for anything with a known breaking change
  4. 04Run the checklistHome page, key templates, navigation, search, forms, login, checkout if present
  5. 05Stage 5Compare key pages visually against the previous version to catch silent layout shifts
  6. 06Stage 6Promote to production in a low traffic window with the rollback path confirmed
  7. 07Stage 7Re-run the checklist on production and log what changed in the monthly report
DiscoverDesignBuildTestHandover
Two decisions on your side that keep the project moving

Our sequence is deliberately dull. Nothing goes to production untested, and everything is reversible within minutes. Where a client has a genuinely critical site, we hold non urgent updates until an agreed window and apply security fixes immediately, which is a different risk calculation and worth making explicitly rather than by habit.

Choose the right level

What actually happens in a maintenance month

A plan is only worth what is performed under it, so it helps to know the shape of the work. Some tasks run continuously in the background, some run weekly, and some are done once a month with a person looking at the results and deciding what to raise with you.

Cadence

01

Continuous

What gets done

Uptime and certificate monitoring, malware scanning, error logging

Why it matters

Problems are found by a system rather than by a customer

02

Weekly

What gets done

Core, plugin, theme and dependency updates applied on staging then production

Why it matters

Published vulnerabilities are exploited within days, not months

03

Monthly

What gets done

Backup restore check, broken link sweep, form and checkout test, performance snapshot

Why it matters

Catches the quiet failures that produce no error message

04

Quarterly

What gets done

Access review, plugin inventory cull, accessibility spot check, dependency audit

Why it matters

Stops the slow accumulation that turns into a rebuild

05

As requested

What gets done

Content changes, new pages, image swaps, small design tweaks

Why it matters

Keeps the site current without you waiting on a project

How we work this out during scoping

The judgement is in the exceptions. Any script can apply updates. Knowing that a particular plugin has a history of breaking layouts on major releases, so it goes to staging first and gets held back for a week, is what you are actually paying for. So is noticing that the contact form has not delivered an email in nine days because a sending domain record changed, which no update process would ever catch.

What a monthly report should tell you, and what it should not

Most maintenance reports are automated exports designed to look substantial. Forty pages of graphs, a green tick beside every item, and nothing a business owner can act on. A report that never contains bad news is not a report, it is reassurance theatre.

Ours is short and written by the person who did the work

Ours is short and written by the person who did the work. It states what was updated and whether anything needed intervention, what uptime actually was with the reason for any incident, how the site performed against its Core Web Vitals thresholds and whether that moved, what content changes we made, and what we recommend you consider next month with a rough sense of effort. If something is degrading, it says so. If we spent the month with nothing to report beyond routine patching, it says that too, in a paragraph, because your time is worth more than a padded document. Where the report keeps flagging the same structural problem, that is usually a signal the site needs a redesign rather than more patching, and we will make that argument rather than bill maintenance indefinitely.

When you do not need a maintenance plan

If you have a competent developer on staff who already owns this work, website maintenance from an external party duplicates their job and creates two parties who each assume the other is watching. Overlapping responsibility is worse than a single clear owner. Similarly, if your site is a static single page with no CMS, no forms and no dependencies, there is genuinely very little to maintain. We will point that out during scoping.

The rest of the answer

There are also cases where maintenance is the wrong purchase because the problem is elsewhere. If your concern is threat exposure and compliance obligations rather than keeping things current, you want a security assessment first. If it is server performance, capacity and restores, that is managed hosting. If what you actually need is a person who answers when a staff member cannot log in, that is technical support with a response commitment attached. And if the site is past saving, held together by plugins that conflict, the honest recommendation is to rebuild it properly with a custom theme and then maintain something worth maintaining. Firms with compliance obligations around published claims should also read how we handle sign off workflows for professional services.

How we scope it

Four ways to scope your Website Maintenance project

We do not publish package prices, because the same brief can be a short build or a long one. These are the shapes the work usually takes. Tell us which one sounds like you and you will get a fixed written quote that spells out exactly what it covers.

Setup

Set up correctly, handed over documented

Fixed written quote, agreed before work starts

  • Weekly updates applied via staging
  • Continuous uptime, malware and certificate monitoring
  • Monthly backup restore verification
Request a quote
Most common

Managed

Managed for you, with monitoring and a person to call

Fixed written quote, agreed before work starts

  • Everything in Setup
  • Broken link, form and checkout testing
  • Monthly allowance of content and small design changes
  • Quarterly plugin and user access review
Request a quote

Managed plus

High availability, hardening and a tested restore

Fixed written quote, agreed before work starts

  • Everything in Managed
  • Core Web Vitals tracking against agreed thresholds
  • Short written monthly report with recommendations
  • Documented change log you keep permanently
Request a quote

Ongoing

Patching, backups and response, every month

Rolling monthly, quoted in writing

  • Patching, backups and a restore that has been tested
  • Monitoring with a response time written into the agreement
  • Security review and dependency updates on a schedule
  • Rolling, cancel with 30 days notice
Request a quote

These are shapes, not menus. Most quotes end up somewhere between two of them, and we will say so when the honest answer is the smallest one. Describe the problem and we will tell you which it is.

Questions buyers usually ask

Frequently asked questions

Working with us

How quickly can you start maintaining a site you did not build?

Usually within a week. We begin with an audit covering update status, plugin inventory, user accounts, backup validity and any signs of prior compromise. That takes a few days and produces a written list of what needs immediate attention versus what can wait. Once the site is stabilised, the ongoing monthly cycle starts. Sites badly behind on updates need a remediation step first, which we quote separately.

Can you maintain a custom built application rather than a CMS site?

Often, yes, though the work looks different. Instead of plugin updates it is dependency upgrades, framework versions, security advisories against libraries you use, and keeping the deployment pipeline healthy. We need access to the repository and a sensible test suite, or we will build a basic one first. If the application is large or business critical, this usually pairs with a support agreement rather than a maintenance plan alone.

Detail and edge cases

What drives the price of a maintenance plan?

Mainly the number and complexity of dependencies, how business critical the site is, how much content change work you want included, and whether you need after hours coverage. A brochure site on a custom theme is a modest commitment. A store with subscriptions, integrations and a sale calendar is a different level of attention. We assess the site and send a fixed written quote for the scope.

Does maintenance include changes we ask for during the month?

Yes, up to an agreed monthly allowance of change work. That covers content edits, new pages built from existing components, image and document swaps, and small styling adjustments. Work beyond the allowance is quoted before we start, never absorbed silently or billed as a surprise. Unused allowance does not roll over, which we say plainly rather than burying it.

What if the site breaks after you apply an update?

We roll back to the pre-update state, usually within minutes because a fresh backup is taken first and updates are staged before production. Then we diagnose which dependency caused the conflict and either hold that update, patch around it or replace the component. You are told what happened in plain language, and it appears in the monthly report rather than being quietly cleaned up.

Do we stay in control of our own site?

Completely. The hosting, domain, CMS and plugin licences remain in your name, your team keeps administrator access, and we work as an additional account you can remove. Every change is logged. If you end the arrangement, there is no transition project because we never held anything you did not already have.

Ask for a maintenance audit before you commit

Send us the site address and we will tell you what state it is really in, what needs doing first and what a sensible ongoing scope looks like. We reply within one business day.