Website Maintenance: The Complete Guide for Business Owners
What keeping a business website healthy actually involves, which jobs matter most, and how to decide who should do them.

Short answer
Website maintenance is the ongoing work that keeps a live site secure, working and fast: applying software updates safely, taking and testing backups, watching for security problems and downtime, keeping hosting, domain and SSL in order, and checking that forms and legal pages still do their job. Most of it is routine; its value shows on the day something breaks.
Website maintenance is the ongoing work that keeps a live business website secure, working and fast after launch. It covers software updates, backups, security monitoring, uptime checks, hosting and domain admin, and the less obvious jobs — confirming that enquiries still arrive and that the legal pages still describe what the site actually does.
None of it is glamorous, and most of it produces no visible change. That is the point. A well-maintained site is one where nothing happens, and the work only becomes visible when it was skipped.
This guide covers what website maintenance involves, how often each part needs doing, what it costs, and how to decide whether to do it yourself or pay someone. Each section links to a deeper article on that one topic.
What is website maintenance, in practical terms?
It helps to think of a site as layers, each of which can fail independently:
| Layer | What can go wrong | The maintenance job |
|---|---|---|
| Software | Outdated CMS, plugins or themes with known vulnerabilities | Updates, applied safely |
| Data | Content, orders or uploads lost to a fault, hack or mistake | Backups, tested by restoring |
| Security | Malware, spam injection, compromised admin accounts | Hardening, scanning, access reviews |
| Hosting | Slow server, outdated PHP, full disk, host outage | Hosting review, PHP upgrades |
| Availability | The site goes down and nobody notices | Uptime monitoring and a response plan |
| Function | Forms stop sending, checkout fails, links break | Functional checks |
| Performance | Gradual slowdown as content and plugins grow | Speed checks against real-user data |
| Compliance | Privacy policy, cookies and company details out of date | Periodic legal review |
| Admin | Domain, SSL or licences lapse | Renewal tracking |
Most "maintenance plans" cover the first two layers well and the rest patchily. When you compare options, compare against the whole table.
The core tasks, and why each one matters
Software updates
On WordPress, most security problems come from plugins and themes rather than WordPress itself. Updates close the holes once they are published — and publication is exactly when attackers start scanning for sites that have not updated.
The risk runs both ways. An update can break a site as easily as it fixes one, which is why updates should be applied to a staging copy first, checked, and then applied to the live site with a fresh backup taken immediately beforehand.
How to update WordPress safely covers the full routine, including which updates are fine to automate and which are not.
Backups
A backup is only worth something if it can be restored, quickly, by someone who knows how. That means:
- automated, on a schedule matched to how often the site changes
- stored somewhere other than the hosting account
- kept for long enough to go back before a problem started
- tested by actually restoring it, on a schedule
The last point is the one most often skipped. What a proper backup strategy looks like explains retention, off-site storage and restore testing in detail.
Security
Security is mostly hygiene: current software, strong unique passwords with two-factor authentication, the fewest admin accounts you can manage with, a sensible host, and something watching for changes you did not make.
WordPress security: a practical guide for business sites covers the measures that matter and the ones that are mostly theatre. If the worst has already happened, how to fix a hacked WordPress site is the step-by-step recovery.
Uptime monitoring
A monitor checks the site every few minutes from outside and alerts you when it stops responding. Without one, the first person to notice an outage is usually a customer — and most customers do not tell you, they just go elsewhere.
Website uptime monitoring explained covers what to monitor beyond the homepage, and what to do when your website goes down is the response plan for when an alert fires.
Hosting
Hosting decides the ceiling on speed and reliability, and it changes over time. Hosts retire old PHP versions, move plans, change backup policies, and occasionally get acquired and quietly get worse. A yearly look at whether the hosting still fits is part of maintenance. Choosing web hosting for a UK small business explains what to look for.
Functional checks
Forms, checkout, booking widgets, newsletter sign-ups. Anything that has to work for the site to earn money should be tested by actually using it, on a schedule. A contact form can break silently — the success message still appears, and the emails simply stop arriving.
Performance
Sites slow down gradually. A few full-size image uploads, a new plugin, a chat widget added by someone in marketing. Nobody notices any single change, and six months later the site feels sluggish. A monthly look at real-user data in Search Console catches the drift early. Core Web Vitals explained covers what to look at.
Legal and compliance
Privacy policy, cookie handling, company disclosures, terms of sale if you sell online. These drift out of date when you add a new analytics tool, a chat widget or a payment provider, and the law itself changes — UK cookie rules changed under the Data (Use and Access) Act 2025. UK website legal requirements for small businesses is the plain-English checklist.
How often should each task run?
This is a sensible default for a typical small business WordPress site. A large shop needs more; a five-page brochure site with few plugins can get away with less.
| Task | Frequency |
|---|---|
| Backups | Daily (more often for busy shops) |
| Uptime monitoring | Continuous, checks every 1–5 minutes |
| Security monitoring | Continuous |
| Security updates | As soon as practical after release |
| Routine plugin and theme updates | Weekly or monthly, staging first |
| Form and checkout test | Monthly, or after any change |
| Performance check | Monthly |
| Restore test | Monthly or quarterly |
| Plugin audit and user review | Quarterly |
| Legal pages review | Every six months, or after adding a tool |
| Domain, SSL, licences, hosting review | Annually |
For the hands-on version of the monthly routine, the WordPress maintenance monthly checklist lists what to check and why.
Does WordPress need more maintenance than other platforms?
Usually, yes — and it is worth understanding why rather than treating it as a flaw.
WordPress's strength is its plugin ecosystem. Each plugin is code written by a different developer, on a different release schedule, with its own security record. A site with twenty plugins has twenty-one pieces of software to keep current, and any of them can conflict with another after an update.
| Platform | Who patches the software | What you still own |
|---|---|---|
| WordPress (self-hosted) | You, or whoever maintains the site | Everything: core, plugins, theme, PHP, backups |
| Wix, Squarespace, Shopify | The platform | Content, apps you add, domain, legal pages |
| Static site or Next.js | The developer, via dependency updates | Dependencies, hosting, forms, domain |
Hosted builders shift the patching burden to the platform. You give up control in exchange. For a comparison of those trade-offs at build stage, custom website vs website builder goes into detail.
How much does website maintenance cost?
In the UK, pricing usually falls into three shapes: a monthly plan, an hourly or ad hoc arrangement, or doing it yourself and paying for tools. Monthly plans for small business sites typically start somewhere under a hundred pounds and rise with the number of sites, the size of the plugin stack, response time commitments, and whether content changes are included.
My own website maintenance plans start from £99/month. How much website maintenance costs in the UK breaks down what drives the price, what the cheap plans leave out, and how to compare quotes that are written very differently.
Should you do it yourself?
For a simple site, often yes. The question is less "can I" and more "will I, every month, including the month I am busiest".
DIY works when:
- the site has a small, well-maintained plugin set
- you are comfortable logging into hosting and restoring a backup
- downtime of a day would be annoying rather than expensive
- you will actually put the monthly time in the diary and keep it
Paying someone makes sense when:
- the site takes orders, bookings or a steady flow of enquiries
- there is custom code, WooCommerce, or a large plugin stack
- nobody in the business knows what to do when the site breaks
- you want someone accountable for response time
There is a middle option: automate what can be safely automated (backups, security releases, uptime alerts) and pay for help only when something breaks. That works well right up until the problem is urgent and the person you would call is booked for a fortnight.
What should a maintenance plan include?
If you pay for one, get these in writing:
- What gets updated, how often, and whether staging comes first. "Updates included" on its own tells you very little.
- Backup frequency, retention and storage location. Off-site, with at least 30 days of history.
- How often restores are tested. If the answer is "we don't", the backups are an assumption.
- What monitoring runs. Uptime, security, and ideally form delivery.
- Response time, separately for emergencies and routine requests.
- What is excluded. Content edits, design changes, fixing problems caused by third-party plugins, malware clean-up.
- Who holds the logins. You should always have owner-level access to hosting, domain and the site itself.
- A monthly report that says what was done, not just that the plan is active.
The WordPress security and maintenance showcase sets out how that routine runs in practice.
Warning signs a site is not being maintained
- WordPress dashboard showing a long list of pending updates
- plugins that have not been updated by their authors in over a year
- PHP version flagged as outdated in Site Health
- no one can say when a backup was last restored
- unknown admin users, or former staff still with access
- the SSL certificate expired once and someone "fixed it"
- enquiries dropped and nobody checked the form
- spam pages appearing in Google for your domain
If several of these apply, start with a backup you have confirmed you can restore, then work through common WordPress problems and fixes for anything already broken.
How website maintenance affects SEO
Maintenance is not an SEO service, but neglect has SEO consequences, and they are usually the slow, invisible kind.
- Hacked sites get flagged. Injected spam pages and malicious redirects can lead Google to show a warning in search results or the browser, and spam URLs under your domain can end up indexed. Cleaning up is slower than preventing it.
- Downtime during a crawl occasionally means pages are crawled less often for a while. One short outage is harmless; a site that is unreliable for weeks is not.
- Broken internal links and redirects accumulate whenever pages are renamed, quietly wasting the link value pointing at them.
- Gradual slowdown shows up in Core Web Vitals field data, which affects both rankings at the margin and conversion more directly.
- An accidental noindex after an update or a staging copy pushed live can remove a site from Google altogether.
A monthly glance at Search Console's Pages and Security reports catches most of this. How Google crawls and indexes a site explains what those reports are telling you.
How maintenance changes with the type of site
The same tasks apply everywhere, but the weight shifts depending on what the site does for the business.
| Site type | What matters most | What can be lighter |
|---|---|---|
| Brochure site, few plugins | Updates, off-site backups, form checks | Backup frequency, performance tuning |
| Lead generation site | Form delivery, uptime, tracking still firing | Content backups (changes rarely) |
| WooCommerce shop | Backups several times a day, checkout tests, payment plugin updates, staging discipline | Nothing — this is the demanding case |
| Membership or booking site | User data protection, logged-in performance, plugin compatibility | Page caching (limited use for logged-in users) |
| Static or Next.js site | Dependency updates, build pipeline, form service | Plugin audits (no plugins) |
The shop is the one where a careless update costs real money. If a payment plugin update breaks checkout at nine in the evening, every order until someone notices is lost, and customers rarely ring to tell you. For shops, staging is not optional and a test order after every update is part of the job. The WooCommerce store development guide covers why shops are built and run differently.
What a maintenance month looks like: a worked example
Say a local service business runs a 30-page WordPress site with 18 plugins, a contact form, a booking widget and Google Analytics. A sensible month looks like this:
- Daily, automatically: a backup of files and database is copied to off-site storage; uptime is checked every few minutes; a security plugin or host-level scanner watches for file changes.
- Week one: pending updates are reviewed. Six plugins have updates, one is a major version. All six are applied to staging, the site is clicked through, the booking widget is tested, and the updates go live after a fresh backup.
- Week two: a security release for one plugin lands mid-month. It is applied quickly, because the risk of waiting outweighs the risk of the update.
- Week three: the contact form and booking widget are tested end to end. The email arrives. Search Console's Core Web Vitals and Pages reports are checked for anything new.
- Week four: last night's backup is restored to staging to prove it works. A short report records what was updated, what was checked, and anything that needs a decision.
Realistically that is two to four hours of attention a month for a site of this size, more in a month with a conflict to resolve. It is the consistency that matters, not the hours.
Ownership: the part nobody thinks about until it hurts
A surprising amount of website trouble is not technical. It is someone not having access to their own site.
Before anything else, make sure that you, not a supplier, are the named owner of:
- the domain name, at the registrar, with your email address on the account
- the hosting account, or at least an owner-level login to it
- the WordPress site, with an administrator account in your name
- any paid plugin or theme licences
- Google Search Console, Google Analytics and Google Business Profile
Suppliers can and should have their own access. But if a freelancer goes quiet or an agency closes, you need to be able to hand the keys to someone else that same day. Disputes over who owns a domain are slow, stressful and entirely avoidable.
When maintenance is no longer the answer
Maintenance keeps a sound site sound. It does not fix a site that is fundamentally the wrong shape.
If every month's updates break something, if the theme is abandoned by its developer, if the page builder makes every change slow and fragile, or if the site runs on a PHP version the hosting company is about to retire and the theme will not support the next one, you are paying to hold back the tide. At that point, compare the cost of another year of firefighting against a rebuild. When to redesign or rebuild a WordPress website sets out how to make that decision honestly.
Where to go next
The articles in this cluster, grouped by the job they cover:
Cost and planning
Keeping it secure and recoverable
- WordPress security: a practical guide
- How to fix a hacked WordPress site
- Website backups: what a proper strategy looks like
- How to update WordPress safely
Keeping it online
- Choosing web hosting for a UK small business
- Website uptime monitoring explained
- What to do when your website goes down
Keeping it compliant and working
A sensible starting point
If nobody is maintaining your site today, do these four things this week: confirm you have the hosting and domain logins in your own name, set up a free uptime monitor, configure automatic daily backups to off-site storage, and restore one of them to a staging copy to prove it works.
That covers most of the catastrophic risk. Everything else can follow. If you would rather hand the whole thing over, the website maintenance service starts with an audit of where the site stands, and the WordPress development service is there if the audit shows the site needs rebuilding rather than maintaining.
Worked examples
Related services
Related reading
Maintenance & Security
How Much Does Website Maintenance Cost in the UK?
Why one quote says £30 a month and another says £300, and how to work out which one you actually need.
Maintenance & Security
WordPress Security: A Practical Guide for Business Sites
Most WordPress hacks are automated and boringly preventable. Here is what actually stops them, in order of value.
Maintenance & Security
Website Backups: What a Proper Backup Strategy Looks Like
Having backups and being able to recover are different things. Here is how to make sure you have the second.
Maintenance & Security
How to Update WordPress Safely (Core, Plugins, Themes)
Updates fix security holes and occasionally break sites. This is the routine that gets you the first without the second.
