

Someone should be watching your site.
watching your site
Website maintenance services are the quiet work that keeps a business website online: updates tested before they ship, backups you have actually restored, uptime and forms monitored, security patched fast, and small improvements every month instead of a crisis every spring. It sits under everything else we do — SEO, paid search and conversion work all depend on a website that stays up.
Tell us a little about your brand and we'll be in touch within 24 hours to lock in a time.

THE FOUR LAYERS
What a maintenance plan really covers.
really covers
Security, reliability, upkeep and improvement. Most plans on the market stop at the first two and call the third an extra. We run all four, because a website that is patched and online but slowly rotting still costs you enquiries every month.
Security & patching
Backups & uptime
Technical health
Improvement & reporting
Patch fast, because attackers are automated.
The threat is volume, not genius. Patchstack's security report counted 11,334 new vulnerabilities across the WordPress ecosystem in 2025, a 42% increase on the previous year, with 91% of them in plugins and only six in core. Wordfence's annual report reached the same conclusion from its own data: plugin vulnerabilities made up 96% of everything disclosed. Nobody targets your business by name; a scanner finds an outdated component and moves on to the next website.
So we treat patch speed as the headline metric. Components are inventoried with an owner, security releases are applied on a defined clock, updates run in a staging copy with visual and functional checks before production, and anything abandoned upstream gets replaced rather than nursed. That last point matters more than it sounds: Patchstack found 46% of vulnerabilities did not receive a fix in time for public disclosure, so an unmaintained plugin is a decision, not bad luck.
On top of that sit the ordinary hardening jobs — a web application firewall, sensible user roles and two-factor access, hardened logins, file integrity monitoring, and malware scanning with a written response plan for the day something gets through.
- Component inventory with a named owner and a patch clock
- Security releases tested in staging, then shipped, not queued
- Abandoned plugins replaced instead of frozen in place
- Firewall, two-factor access, hardened logins, role hygiene
- Malware scanning plus a written incident response plan
11,334
new WordPress ecosystem vulnerabilities in 2025
91%
of them found in plugins, not core
A backup you have never restored is a rumour.
Everyone has backups. Far fewer teams have restored one on purpose, in front of a stopwatch, into a working copy. We do that on a schedule: off-site copies of files and database, retention agreed against how much content you would tolerate losing, and a rehearsed restore so the recovery time is a known number instead of a hope.
Monitoring covers more than a ping. Uptime from several locations, certificate expiry, DNS changes, error rates in the logs, and — the one most plans forget — the actual business paths: does the contact form still send, does the booking step still complete, does checkout still take a card. Broken forms are the most expensive silent failure on the web, because traffic and rankings look perfectly healthy while the enquiries stop.
When something does break, you reach a named engineer with your site's documentation already in hand, and the fix is logged so the same fault does not return next quarter.
- Off-site backups of files and database with agreed retention
- Rehearsed restores, so recovery time is measured, not assumed
- Uptime, certificate, DNS and error-rate monitoring
- Synthetic checks on forms, bookings and checkout
- A named engineer to reach when it matters
46%
of vulnerabilities lacked a vendor fix at disclosure
Small faults compound into lost traffic.
Websites decay in undramatic ways: a redirect chain from a campaign two years ago, a noindex left on a template after a staging copy went live, structured data broken by a plugin update, a sitemap that stopped regenerating, images uploaded at four megabytes because nobody set a pipeline. Google publishes its own list of the changes that cost sites traffic — host and URL changes, moves to HTTPS and site reorganisations feature heavily, and all of them are maintenance events rather than marketing ones.
So every month we crawl the website, diff it against the last crawl and act on the differences: broken links and redirect chains, indexation drift, schema validity, Core Web Vitals per template. The benchmark says this is where most of the market sits — the Web Almanac reports 48% of mobile origins passing all three Core Web Vitals, up from 36% in 2023 — so steady upkeep is a competitive position, not housekeeping.
Anything larger than a maintenance fix is written up as a scoped recommendation with an estimate, so you decide whether it belongs in the plan or in a project.
- Monthly crawl diffed against the previous month
- Broken links, redirect chains and indexation drift fixed
- Structured data and sitemaps validated after every release
- Core Web Vitals watched per template, not site-wide
48%
of mobile origins pass all three Core Web Vitals
Hours that make the site better, not just current.
Every plan includes development hours that belong to you, and we would rather spend them on something measurable than bank them: a clearer enquiry form, a faster template, a landing page for the campaign starting in three weeks, accessibility fixes, a content type your team keeps asking for. Where the work needs design or copy, our design and content teams pick it up without a new contract.
Reporting is short and honest: what we patched, what we monitored, what broke and how long it took to fix, what we improved, what we recommend next and roughly what it would cost. One page, monthly, written by the person who did the work — not a forty-page automated export nobody opens.
You keep the accounts, the repository, the documentation and the runbook. If you ever move on, everything the next team needs is already written down.
- Development hours included and actively spent
- Design and content support available without a new contract
- A one-page monthly report written by the engineer
- Runbook, credentials and documentation owned by you
1 page
monthly report, written by the engineer who did the work
Restores tested on a schedule, not assumed to work
You own the hosting, accounts, repository and runbook
A named engineer who knows your build
Long-term lock-ins
We made the difference for those brands
01 — The challenge
Nothing was wrong until everything was.
The website was built well, launched, and then left alone. Two years later a plugin update breaks the checkout on a Saturday, the last backup is from a hosting panel nobody has logged into, and the developer who built it has changed careers. Meanwhile the contact form has been failing quietly for six weeks and the traffic reports look fine.
“We only think about the site when it stops working.”
That is the normal state of affairs, and the numbers explain why it ends badly: 11,334 new WordPress ecosystem vulnerabilities were disclosed in 2025, 42% more than the year before, and 96% of disclosures in Wordfence's 2024 report came from plugins. Attacks are automated, so being small is not cover. Add the invisible failures — a form that stopped sending, a certificate about to lapse, a template quietly slowing down — and the cost of doing nothing arrives all at once instead of monthly.
02 — Our approach
Take it over properly, then keep it boring.
We start with an onboarding website audit: hosting, stack, plugin and component inventory, backup reality, security posture, technical health, and every credential written into a runbook so the knowledge is not in one person's head. Then we fix what is already broken before promising to maintain it. From there the rhythm is deliberately dull. Security patches on a defined clock, tested in staging with visual and functional checks before production. Off-site backups with rehearsed restores. Monitoring on uptime, certificates, DNS, error rates and the business paths that actually earn money — forms, bookings, checkout. A monthly crawl diffed against the last one, so indexation drift and broken links get caught early. Included development hours spent on real improvements. And a one-page monthly report from the engineer who did the work, ending in what we recommend next.
03 — What we did
Onboarding, then a rhythm you can forget about.
Two weeks to take it over properly, then a monthly cycle of patching, monitoring, upkeep and improvement with one written report.
Weeks 1-2 / Takeover
Inventory everything and write the runbook
Hosting, stack and components inventoried, credentials collected into a runbook, backups verified by an actual restore, and existing faults listed with estimates.

Weeks 2-4 / Remediation
Fix what is already broken
Outstanding security releases applied, abandoned components replaced, broken forms and redirect chains repaired, monitoring and off-site backups put in place.

Monthly / Cycle
Patch, monitor, crawl, improve
Updates on a clock with staging checks, uptime and form monitoring, a monthly crawl diffed against the last, and included hours spent on real improvements.

Monthly / Report
One page, written by the engineer
What was patched, what broke and how fast it was fixed, what improved, and what we recommend next with a rough cost.

WHAT YOU GET
What is in the plan every month.
every month
All of it happens in your own hosting, accounts and repository, documented as we go and yours to keep.
Tested updates and patching
Core, plugin, theme and dependency updates applied on a clock and checked in staging before they reach your visitors.
Backups with rehearsed restores
Off-site copies of files and database, agreed retention, and a restore rehearsed on a schedule so recovery time is known.
Uptime and journey monitoring
Uptime, certificates, DNS and error rates plus synthetic checks on the forms, bookings and checkout that earn the money.
Hardening and malware response
Firewall, two-factor access, role hygiene, file integrity and malware scanning with a written response plan.
Monthly technical health pass
A crawl diffed against last month: broken links, redirect chains, indexation drift, schema validity and vitals per template.
Included improvement hours
Development time that belongs to you, spent on measurable improvements rather than banked and forgotten.
HOW WE WORK
Operating standards, not promises.
Operating standards

Built on trust. Proven by results.
We partner with SMBs and Fortune 500 companies to deliver more than reach — we bring clarity, execution, and measurable outcomes. Every successful partnership starts with a strong culture fit and a shared drive to grow.








CASE STUDIES
Case studies
Video Ads
Static Ads























































































FAQ
What teams ask us first.
What is actually included in website maintenance?
Four things, and you should expect all four rather than the first two. Security: patching on a defined clock, hardening, malware scanning and a written response plan. Reliability: off-site backups with rehearsed restores, plus monitoring of uptime, certificates, DNS and the business journeys that earn money. Technical health: a monthly crawl for broken links, redirect chains, indexation drift, schema and vitals per template. And improvement: included development hours spent on making the site better. If a plan offers only updates and a backup, it is a hosting add-on rather than maintenance.
Can we not just let our host handle updates?
Automatic updates are useful and they are not a plan. They apply changes without checking that your particular combination of theme, plugins and custom code still works afterwards, which is how a Saturday outage happens. They also do nothing about abandoned components, and that gap is the real exposure: Patchstack reported 91% of 2025's WordPress ecosystem vulnerabilities in plugins and 46% of them still without a vendor fix at disclosure. Someone has to decide what to replace, test what to ship, and own the outcome. That decision is the service.
How quickly do you apply security patches?
On a clock that matches severity. Anything actively exploited or rated critical is treated as an incident and shipped the same day, with a staging check where the code allows and a virtual patch at the firewall where it does not. Routine security releases go through the normal weekly cycle: staging copy, visual and functional checks on the pages that matter, then production with a rollback ready. Feature updates that carry no security weight can wait for the monthly window, because an unnecessary change on a Friday is its own risk.
What happens if the site is hacked or goes down?
You reach a named engineer who already has your runbook, and the plan is written before the day it is needed. For an outage: confirm the fault, get the site serving again from cache or a restore, then diagnose properly rather than in a panic. For a compromise: isolate, take a forensic copy, clean or rebuild from a known-good backup, rotate every credential, patch the entry point, then request review where search or browser warnings are involved. Afterwards you get a written account of what happened and what we changed so it cannot repeat.
Do you also fix the things that were built badly?
Yes, and we separate the two honestly. Onboarding always includes remediation: outstanding patches, abandoned components, broken forms, redirect chains, missing monitoring. That is part of taking a site over properly rather than an upsell. Where the underlying build is the problem — a page builder emitting megabytes of markup, a theme with a decade of layers, an integration held together by hand — we scope it as a project with a price, whether that is a redesign, speed engineering or a custom build, and keep maintaining the current site meanwhile.
How are the included hours used, and do they roll over?
They are used, which is the important part. Each month we agree what the hours go on: a clearer enquiry form, a faster template, a campaign landing page, accessibility fixes, a content type your team keeps requesting. If a month is quiet we propose something measurable instead of leaving the time idle. Unused hours roll for one month so a bigger job can be planned across two, and we tell you plainly when a request needs more time than the plan holds, with an estimate, before we start rather than after.
Will maintenance help our search rankings?
Indirectly and reliably. Search does not reward maintenance as such, but it punishes what happens without it: pages that disappear behind a stray noindex, redirect chains left from an old campaign, sitemaps that stop regenerating, templates that slow down until they fail their vitals. Google's own guidance on why site traffic drops is largely a list of maintenance events. Keeping those clean protects the rankings you already earned; growing them is a different job, which is what our SEO team does.
How much does website maintenance cost?
It depends on two things: how complex the build is and how much included development time you want. A brochure website with a handful of components and no integrations is a modest monthly fee covering patching, backups, monitoring and a health pass. A store or a website with CRM, payment and feed integrations costs more because more can break and the checks are daily. Plans with meaningful improvement hours cost more again and usually return the most. We quote a fixed monthly figure after the audit, with response times written into it — never an hourly rate you find out about after an incident.
Can you work alongside our internal developer?
Yes, and it is a common split. Your developer keeps the product work and the roadmap; we take the parts that are easy to postpone and expensive to postpone — patch cycles, backups and restore drills, monitoring, the monthly health pass, out-of-hours cover. Everything we do lands in your repository through your review process and is written into the shared runbook, so nothing depends on us being available. Where a website is complex we hold a short monthly session with your developer so priorities do not collide.
How do we choose a website maintenance company?
Ask what the plan measures, not what it lists. Four questions sort the market fast. How quickly are critical security releases applied, and is that written into the agreement? When was the last restore rehearsed, and how long did it take? What exactly is monitored — uptime only, or the forms and checkout that earn the money? And how many development hours are included, with who deciding what they go on? Cheap plans usually mean automatic updates and a backup nobody has tested, which is hosting with a nicer name. Whichever agency you choose, insist that hosting and every account stay in your business's name.
What if we want to leave?
You can, and it should be uneventful. Plans run monthly after the first term, the hosting and every account stay in your name throughout, and the runbook — credentials, component inventory, monitoring configuration, restore procedure, change log — is maintained as a deliverable rather than as our private notes. On the way out we hold a handover call with whoever takes over and answer their questions afterwards. We would rather be kept because the reports are useful than because leaving is difficult.


























































































.webp)
.webp)


