Most website maintenance services sold to small businesses are hosting with a nicer name on the invoice. A real care plan covers seven things, and the gap between the two is invisible right up until the morning your site is down or defaced. The wider case for building it properly in the first place sits in our guide to affordable web design for small businesses.
Timing is the item that matters most, and almost every plan gets it wrong.
The five-hour problem
Attackers move fast. The median gap between a WordPress flaw becoming public and mass exploitation is five hours. Not five days. Roughly 20% of the most-targeted flaws see attacks within six hours, 45% within a day, and 70% within a week.
Now read a typical care plan. Monthly updates. That means your site can sit exposed for up to thirty days on a flaw attackers began using the same afternoon it was announced.
Share of top-targeted WordPress vulnerabilities exploited after public disclosure. Median window to mass exploitation: five hours.
Twenty percent of top-targeted vulnerabilities are exploited within six hours, forty-five percent within twenty-four hours and seventy percent within seven days.

So the first question to ask a provider is not what they update. Ask how fast, and whether anybody watches between runs. Weekly is fine for a brochure site. Monthly is not, for anything taking money.
What actually breaks
Owners assume WordPress itself is the weak point. It is not. The numbers are lopsided enough to change where you spend.
Plugins account for 91% of WordPress vulnerabilities. Core produced just two in all of 2025. Across the wider ecosystem that year, researchers disclosed 11,334 new flaws — a 42% rise, with the genuinely dangerous ones up 113%.
| Source | Share of vulnerabilities | What it means for you |
|---|---|---|
| Plugins | 91% | Every plugin you install is a maintenance liability |
| Themes | Most of the remainder | Abandoned themes are the worst offenders |
| WordPress core | 2 issues in 2025 | Effectively not your problem |
Two things follow. Plugin count is a risk metric, not a feature list. A site running 34 plugins is far more exposed than one running 12. And a good plan removes plugins as well as updating them. Almost none do, because removal takes judgement and updating is a button.
One more figure worth sitting with. Around 52% of plugin developers release no patch before the flaw becomes public, and 46% of disclosures arrive with no fix at all. Updating promptly is necessary. It is not sufficient.
The seven things a real plan covers
Score any quote against these seven. Most website maintenance services cover three or four, and price as though they cover all seven.
Seven items: scheduled updates, staging tests, tested off-server backups, uptime monitoring with human alerts, plugin removal, form testing, and a written response time.
The two that matter most
Of the seven, items three and six are the ones we would refuse to go without in any website maintenance services agreement. An untested backup and a silently broken contact form are the two failures that cost real money and produce no visible symptom until somebody asks why nobody has called.
What maintenance usually means on an invoice
Here is the uncomfortable part, and we are describing our own industry.

A large share of care plans amount to reseller hosting, an automated plugin updater, and a monthly PDF listing what the updater did. Human involvement is close to zero. The margin is excellent, which is why the model persists.
None of that is fraud. The updates genuinely happen. Judgement is what goes missing. Nobody decides whether to delay an update, nobody notices when a developer abandons a plugin, and nobody checks the site still works afterward.
Three questions expose it quickly. When did you last restore one of my backups? What did you remove from my site in the past year? Who gets alerted at 2am if the site goes down, and what do they do? Vague answers to all three mean you are buying hosting.
What it should cost
No figures here on purpose, because the sensible number differs sharply between the UK and the US. The shape holds in both markets.
| Tier | Suits | What you get |
|---|---|---|
| Basic | Brochure sites, no transactions | Hosting, backups, monthly updates, uptime alerts |
| Standard | Lead-generating sites with forms | The above, weekly, staged, plus form testing and a small monthly content allowance |
| Commerce | Anything taking payment | Weekly or faster, staging, checkout testing, priority response, security scanning |
The jump from basic to standard is where the money starts working, because that is where a person enters the process. Paying more for the commerce tier is worth it only if you actually take payment — otherwise you are buying reassurance.
For market-specific numbers, our breakdowns of website design cost in the UK and small business website cost both include annual running costs.
What happens without a plan
Going without website maintenance services rarely produces drama. It produces decay, then one bad morning.
| Elapsed | What tends to happen |
|---|---|
| Months 1–6 | Nothing visible. Plugins drift behind, an SSL certificate quietly nears expiry. |
| Months 6–12 | A plugin update breaks a layout nobody notices. Contact form stops delivering after a mail change. |
| Year 1–2 | A theme licence lapses. Speed degrades as image sizes creep. Search rankings soften. |
| Any time | A disclosed vulnerability gets exploited. Recovery costs more than years of maintenance would have. |
The last row is the one people picture, but the middle rows do more cumulative damage. A form that stopped delivering in March and nobody noticed until August costs more than most hacks, and it never appears in a security statistic.
Worth noting that weak or stolen passwords contributed to 81% of hacked WordPress sites. Two-factor authentication and removing dormant admin accounts costs nothing, and belongs in any set of website maintenance services you pay for.
Why website maintenance services matter for search rankings
Owners think of maintenance as insurance. It is also a ranking input, and that connection is rarely made in a sales conversation.
Speed drifts. Images uploaded at full size. Plugins layering scripts. A database filling with old revisions. None of it happens overnight, and all of it shows up in Core Web Vitals in the end. A site that loaded in 1.4 seconds at launch often measures 3 seconds two years later, with nobody having touched the design.
Downtime hurts too. A site that is unreachable when Google crawls it gets crawled less often afterward, which slows how quickly new pages get indexed. Neither effect is dramatic on its own. Together, over two years, they explain a lot of rankings that quietly faded without an algorithm update to blame.
Broken links are the third piece. Pages get deleted, external sites disappear, and nobody checks. Our small business SEO checklist covers the audit side, but the point here is that a maintenance plan which never looks at links is only doing half the job.
So when you compare website maintenance services, ask whether anybody checks performance and links, or only whether the software is current. Those are different products at similar prices.
Switching provider without breaking anything
If you decide to move your website maintenance services elsewhere, the sequence matters more than the timing.
Get your logins first, while the relationship is still cordial. Domain registrar, hosting, and the site’s own admin account, all in writing and all in accounts owned by the business. Then take a full backup yourself and store it somewhere you control, before anybody touches anything.
Only after those two steps should you give notice. Doing it the other way round occasionally results in a scramble, and in rare cases with a provider who is difficult about handover. It is a small precaution and we have never regretted advising it.
Who should own this inside your business
One thing separates firms that stay on top of website maintenance services from firms that do not, and it is not budget.
Somebody has to own it by name. Not “the office manager will look at it” and not “our web guy handles that”. A named person, with the logins, who checks a short list every month. Where nobody owns it, nobody does it, and that holds whether you pay for website maintenance services or handle it yourself.
Give that person three things. The hosting and domain logins, in writing, in an account under the business name rather than an employee’s personal email. A one-page checklist. And ten minutes a week that nobody interrupts.
The logins point matters more than it sounds. We regularly meet firms locked out of their own domain because it sits in the personal account of somebody who left in 2023. Recovering it takes weeks, and occasionally it fails entirely.
Signs your current plan is not working
Five symptoms that your website maintenance services are not earning their fee. All easy to check without technical knowledge.
| Symptom | What it usually means |
|---|---|
| Your monthly report is identical every month | An automated tool is producing it and nobody reads the output |
| Nothing has ever been removed from your site | Updating happens, auditing does not |
| You found the outage before they did | Monitoring either does not exist or alerts nobody |
| Small changes take a week | You are not a priority, and the response time was never agreed |
| You cannot name who to call | The most common failure of all, and the easiest to fix |
Two or more of those is worth a conversation with your provider before it is worth changing provider. Most respond well to a direct question, and the ones who do not have answered it for you.
Doing it yourself
Handling your own website maintenance services is entirely possible for a simple site, and we would rather say so than pretend otherwise.
Set core and security releases to update automatically. Update plugins manually once a week after taking a backup. Test your contact form on the first of every month. Delete anything you have stopped using. Turn on two-factor authentication for every admin account, and remove the accounts belonging to people who left.
That takes twenty minutes a week and covers most of the risk. Where it falls down is judgement — knowing that a particular plugin update is best delayed, or spotting that a developer stopped maintaining something two years ago. That gap is what you are actually buying when you pay for website maintenance services.
If your site takes payments or bookings, buy the plan. If it is five pages and a phone number, the twenty minutes is genuinely enough, and our small business hosting guide covers the server-side half.
Are monthly updates enough?
Not for a site that takes money. The median window between a vulnerability being disclosed and being exploited at scale is five hours, so a monthly cycle can leave you exposed for weeks. Weekly plus a process for urgent security releases is the realistic minimum.
Can I just turn on automatic updates?
For WordPress core and security releases, yes — do it today. For plugins, automatic updates straight to a live site occasionally break layouts or checkout at times nobody is watching. Staging plus a weekly manual run is safer.
How many plugins is too many?
There is no hard number, but plugins cause 91% of WordPress vulnerabilities, so each one is a liability rather than a free feature. If you cannot say what a plugin does, remove it and see whether anything breaks.
What should I ask before signing a care plan?
When did you last restore one of my backups, what did you remove from my site this year, and who is alerted if it goes down overnight. Vague answers to all three mean the plan is hosting with a different label.
Is my host’s backup enough?
Usually not on its own. Host backups often live on the same infrastructure as the site and can be lost alongside it. Keep at least one copy somewhere else, and confirm somebody has actually restored from it.
My site is fine and I have never maintained it. Why start?
Because nothing visible happens for months. Failures accumulate quietly — a form that stopped delivering, a certificate about to expire, a plugin abandoned by its developer. Then the cost arrives all at once, long after the neglect.
A short monthly checklist
Print this. Think of it as website maintenance services you run yourself. It takes ten minutes and it catches most of what goes wrong.
| Check | How | Time |
|---|---|---|
| Contact form still delivers | Send one from your phone | 2 min |
| Site loads on mobile | Open it on 4G, not office wifi | 1 min |
| Backup exists and is recent | Look at the date, not the setting | 1 min |
| Updates are current | Check the admin dashboard count | 1 min |
| No unknown admin accounts | Read the user list | 2 min |
| Certificate not near expiry | Click the padlock in the address bar | 1 min |
Six checks, ten minutes, once a month. Do that and you have covered more ground than plenty of paid website maintenance services manage, which says more about the market than about the checklist.
The user list is the one people skip and the one that surprises them. Old freelancer accounts, a developer from two agencies ago, sometimes an account nobody recognises at all. Remove what should not be there.
The one test worth running today
Forget the brochures on website maintenance services for a moment. Submit your own contact form from your phone, then check the inbox it should reach.
We run this on every site we audit and it fails more often than any other single check. It costs nothing, takes ninety seconds, and it is the clearest evidence of whether anybody is actually maintaining your website or simply billing you for it.
If it fails, you have learned something about your current provider. If it passes, do the backup restore question next.
Vulnerability and exploitation figures are published WordPress security data for 2025–2026 and are cited below. This is general commercial guidance, not security consultancy. Last reviewed August 2026.