Maintenance is the easiest line to cut, because nothing visibly happens when you pay for it. That is also precisely what you are paying for. The problem is that the cost of not having it arrives all at once, usually at the worst moment.
What is actually being maintained
A website is not a finished object. It sits on software that keeps changing underneath it.
- Security patches. Platforms and plugins publish fixes constantly, and published fixes are public notice of the vulnerability. Automated scanners find unpatched sites within days, not months.
- Compatibility. Hosts upgrade PHP and database versions. Plugins stop being updated. Browsers change. A site that worked perfectly at launch can break without anyone touching it.
- Backups, and the proof they restore. An untested backup is a hope. Part of maintenance is periodically restoring one to confirm it works.
- Uptime monitoring. Somebody should know the site is down before a customer tells you.
- Speed. Sites get slower as content and images accumulate. Left alone, a fast site becomes a slow one in about a year.
- Small changes. Prices, staff, hours, a new service. Usually minutes each, but only if someone is available to do them.
Eighteen months without it
The pattern is consistent enough to predict. Months one to three, nothing happens and the decision looks correct. Around month six a plugin update is skipped because nobody is watching, and a form quietly stops sending. Around month nine the host upgrades PHP and part of the site breaks.
Somewhere past a year an unpatched vulnerability gets exploited — usually not a targeted attack but an automated scanner that found an old version and injected spam links, which Google then penalises. The site has also been getting steadily slower, and the person who built it has moved on.
The recovery costs more than three years of maintenance, and the rankings take months to come back.
Telling a real plan from an invoice
Maintenance is sold with the same words by people doing very different amounts of work. Ask these:
- "What do you actually do each month, and do I get a report?" A real plan produces evidence: what was updated, what was found, what was fixed.
- "How many hours of changes are included, and what happens after that?" Vague allowances lead to arguments.
- "What is your response time for a site that is completely down?" It should be a number, and it should be different from the response time for a typo.
- "Are backups tested?" Ask when a restore was last performed.
- "If a plugin update breaks the site, who fixes it and is that extra?" This is the scenario the whole arrangement exists for.
Doing it yourself, honestly
This is entirely reasonable if you will genuinely do it. That means a recurring calendar entry, applying updates on a staging copy first, verifying backups restore, watching uptime, and keeping enough technical understanding to recognise a problem.
The failure is not deciding to self-manage. It is deciding to and then not doing it, which is the same as having no maintenance while believing you have some. If the honest answer is that nobody will, pay someone.
What we cover is set out on the website maintenance page, deliberately itemised so you can compare it against anything else you are quoted — including doing it yourself.
If you have a site that has been running unattended for a while, send us the URL and we will tell you what is out of date and what is exposed. Knowing is free, and it is usually less alarming than people fear.
