Updates applied on staging first
Platform core, plugins and themes updated on a copy, checked, then pushed live with a rollback path. Updates applied directly to production are how sites break on a Friday evening.
Most annual maintenance contracts are priced low and scoped vaguely, which works until the month you need something. Here is what a real one covers.
A genuine website maintenance contract covers platform and plugin updates applied on staging, off-server backups that have been test-restored, security monitoring, uptime monitoring and a defined number of content changes. Most low-cost AMCs in this market cover hosting and little else, and the difference only becomes visible the month something breaks.
Platform core, plugins and themes updated on a copy, checked, then pushed live with a rollback path. Updates applied directly to production are how sites break on a Friday evening.
A backup on the same server disappears with the server. Off-server storage, several retained versions rather than only the newest, and a restore actually tested rather than assumed.
File integrity checks, malware scanning, and someone who notices. Most compromises we clean up ran undetected for weeks on sites that had a security plugin installed and nobody reading it.
A cached homepage can respond normally while the database is down and every form on the site is failing. Checks should include a database-driven page and the enquiry form endpoint.
Hours or requests per month, stated. Unlimited changes is either priced with a large margin or quietly rationed, and both sides end up unhappy.
A named response time you can hold them to. An AMC with no stated turnaround is a hosting bill with a better name.
| Often excluded | Why it matters |
|---|---|
| Design changes of any kind | Every visual tweak becomes a separate quote |
| New pages | Adding a service page is billed as a project |
| Plugin licence renewals | Premium plugins silently stop updating |
| Malware cleanup | The one thing you most need it for |
| Restoring from backup | Backups are taken, restoring is chargeable |
| Performance work | The site slows year on year and nobody owns it |
| Anything urgent | No stated response time means no obligation |
None of these are unreasonable to exclude. What is unreasonable is not saying so until the month you need one. Ask for the exclusion list in writing before signing, and if there is not one, that is your answer.
| Ask them | A good answer sounds like | Walk away if |
|---|---|---|
| Who owns the code and files? | You do, unconditionally, written into the contract | Ownership depends on staying with them |
| Can I open three things you built? | Live URLs you can check yourself | Screenshots and a portfolio PDF |
| What is explicitly not included? | A written list with change pricing agreed up front | Everything is included, which means nothing is defined |
| Who does the work day to day? | People you meet before signing | The pitch team is never seen again |
The exclusions question is the one most people forget, and it decides whether the final invoice matches the quote.
Works if someone genuinely owns it and has time. It fails quietly, because nobody notices that updates stopped until something is exploited.
Predictable and someone is accountable. Worth paying for if the scope and response time are written down and the exclusions are visible.
Extremely common and the reason most compromised sites get compromised. If you are not going to maintain a WordPress site, a static site or a hosted platform is the more honest choice.
An annual maintenance contract covering ongoing upkeep of your site. What it actually includes varies enormously, so the useful question is not the price but what is excluded. Ask for the exclusion list in writing before you sign.
Platform and plugin updates applied on staging, off-server backups that have been test-restored, security and uptime monitoring, and a defined number of content changes with a stated response time. Anything vaguer is a hosting bill with a better name.
Security patches as soon as they are tested, ideally within days. Plugin and core updates monthly on staging. Content whenever it changes. Sites left unupdated for a year are the ones that get compromised, and it is nearly always through a known plugin vulnerability.
If it runs on WordPress or any CMS, yes, because unmaintained installs get compromised through known vulnerabilities. A purely static site needs far less. If you will not maintain a CMS site, that is an argument for building it differently.
No, and conflating them is the most common misunderstanding in this market. Hosting keeps the server running. Maintenance keeps the software updated, backed up, monitored and secure. Many low-cost AMCs are really just hosting.
Check whether cleanup is in your contract, because it frequently is not. Recovery means restoring a clean backup from before the compromise, patching the vulnerability, removing injected files and requesting a review if Google has flagged the site. This is why backup retention matters.
Yes, if someone genuinely owns it. Apply updates on staging, keep off-server backups, test a restore quarterly, and monitor uptime. It fails when it is nobody's specific job, which is the usual outcome.
Yes. We audit what exists first, including what has been left unpatched, and tell you honestly what state it is in before quoting. Occasionally the audit shows the site should be rebuilt rather than maintained, and we will say so.
Send us what you are trying to fix and we will tell you what it takes, what it costs, and whether we are the right people for it. If we are not, we will say so.