WordPress maintenance in detail: what running a website involves
A WordPress website is not finished at launch. It consists of the WordPress core, a theme and usually anything from a handful to several dozen plugins — software from different developers, each releasing updates independently. Running a WordPress site therefore mainly means keeping these parts up to date, compatible and secure.
What WordPress maintenance actually covers
At its core it is about updates — but not every update is the same. Security updates should be applied promptly, while major version jumps of a page builder or shop plugin need testing because they can change layouts or features. Good maintenance treats these cases differently and never applies updates to the live site without a backup.
- Core, plugin and theme updates — after a fresh backup and a test on a staging copy
- Checking the PHP version at your host, since old PHP versions no longer receive security fixes
- Backups of files and database, stored off the web server, with regular restore tests
- Uptime monitoring, so an outage is not first reported by a customer
- Security monitoring: known vulnerabilities in installed plugins, changed files, unknown admin accounts
- Cleanup: removing unused plugins and old user accounts
- Performance: caching, image sizes, database bloat
Signs your WordPress site has been hacked
Attacks on WordPress are mostly automated. A successful attack is often not visible right away, because attackers want to use the site for spam, redirects or hidden links. Typical signs:
- Visitors, especially from Google or on mobile, are redirected to other sites
- Spam pages appear in Google results under your domain
- Google or the browser shows a warning about your site
- There are administrator accounts nobody created
- Your host reports unusual email sending or suspends the account
What a maintenance contract should cover
A maintenance contract mainly creates clarity about who is responsible for what. Make sure it states the scope of updates and how they are tested, how backups are made and restored, response times for outages and security incidents, who handles hosting, domain, content and plugin licences — and that all credentials, licences and data belong to you and are handed over in full when the contract ends.
Maintenance and GDPR
Many plugins load fonts, maps, videos or tracking scripts from servers outside the EU, or send form data to external services. During maintenance we check which plugins send what data where and whether your privacy policy still matches the site. Because a maintenance provider has access to personal data such as form submissions, a data processing agreement is usually part of the arrangement — we settle that at the start.
When switching makes more sense than the next repair
If WordPress is enough for your project, we say so. But when the theme only runs with workarounds, key plugins are no longer maintained, the site stays slow despite optimisation or every update breaks something, maintenance becomes endless repair work. In that case we calculate with you what maintenance will cost over the next few years compared with a rebuild — for example with Next.js and a headless CMS. The decision is yours; you should just make it with full information.
How we start: the audit first
Before taking over maintenance we look at the site closely: WordPress and PHP versions, installed plugins and whether they are still maintained, theme, hosting, existing backups, user accounts and obvious security issues. The result is a clear list of what should be done now, what can wait and what we recommend — and a concrete quote for ongoing support that fits your site.