Website maintenance is the ongoing work of keeping your site secure, fast, backed up and functioning: updates, monitoring, backups, security patches, broken link fixes and speed checks. It matters more than it sounds, because 11,334 new vulnerabilities were reported across the WordPress ecosystem in 2025, a 42 percent increase on the previous year, and 91 percent of them came from plugins.
Most owners think of maintenance as a tidying job that can wait. It is closer to insurance with a deductible you pay in leads. This article covers what maintenance actually includes, the published security data that explains the urgency, a realistic schedule, and how to tell a genuine maintenance plan from a monthly invoice for nothing.
Key takeaways
- 11,334 new WordPress ecosystem vulnerabilities were reported in 2025, up 42 percent year on year
- 91 percent came from plugins, 9 percent from themes, and only 6 from WordPress core itself
- 46 percent were not fixed in time for public disclosure, so the flaw became public before the patch existed
- For heavily targeted flaws the weighted median time to first exploit is 5 hours, which is faster than most businesses check their email
- The expensive failures are silent: a broken form, a dead payment step, an expired certificate
- Maintenance is not a design service. If your plan produces no report, you have no way to know it happened
What website maintenance actually covers
Strip out the marketing language and there are six real jobs.
Updates. Core software, plugins and themes, applied in a way that does not break the site. This is where most of the risk lives and most of the skill is required.
Backups. Taken automatically, stored somewhere other than the server they came from, and restored at least once so you know they work. An untested backup is a hope, not a plan.
Security. Firewall rules, login protection, malware scanning, and file integrity monitoring. The point is to detect a compromise in hours rather than the week a customer mentions it.
Uptime and function monitoring. Not just is the site up, but does the contact form still deliver, does the phone link still dial, does checkout still complete.
Performance. Image sizes, caching, database cleanup, and removing the plugins nobody uses. Slow accumulates quietly.
Content and link hygiene. Broken links, outdated pricing, staff who left two years ago, and the seasonal page from last summer that still ranks.
The numbers that make this urgent
New vulnerabilities reported across the WordPress ecosystem in 2025, a 42 percent increase on the year before.
Patchstack, State of WordPress Security in 2026Came from plugins, against 9 percent from themes and just 6 in WordPress core. The risk is what you added, not what you installed.
Patchstack, State of WordPress Security in 2026Weighted median time to first exploit for heavily targeted vulnerabilities. Roughly half of high impact flaws are exploited within 24 hours.
Patchstack, State of WordPress Security in 2026The 91 percent figure is the useful one, because it tells you where to act. Every plugin is a supplier you have taken on, and you inherit their security practices whether or not you ever read their code. The practical implication is unglamorous: install fewer plugins, delete the ones you stopped using, and update the rest quickly.
The five hour figure explains why "we update quarterly" is not a maintenance plan. Patchstack also found that 46 percent of vulnerabilities were not fixed in time for public disclosure, meaning the flaw was public knowledge before a patch existed. During that window the only defence is monitoring and a firewall, which is precisely the part most businesses skip.
What actually breaks, and how you find out
Sites rarely fail loudly. They fail in ways nobody reports, which is what makes the cost hard to see.
| What breaks | How most owners find out | What it costs while unnoticed |
|---|---|---|
| Contact form stops delivering email | A customer eventually calls to ask why nobody replied | Every enquiry in the gap, plus the ones who told a friend you ignore people |
| SSL certificate expires | Browsers show a full page security warning to every visitor | Effectively all traffic, immediately, until it is renewed |
| A plugin update breaks the layout | Nobody, because it broke on mobile only | The majority of your visits, since Google indexes the mobile version |
| Site is compromised and injected with spam | A Search Console warning, or a customer seeing pharmacy links | Rankings, trust, and days of cleanup at emergency rates |
| Speed decays as images and plugins pile up | Never, because the decline is gradual | Conversions, quietly. Deloitte and Google measured a 21.6 percent lift in lead form submissions from a 0.1 second gain |
| Backups silently stopped running | The day you need one | Everything |
A realistic maintenance schedule
This is what proportionate looks like for a small business site. A store taking payments needs more; a five page brochure site can sit at the lighter end.
| How often | What happens |
|---|---|
| Continuously | Uptime monitoring, malware scanning, firewall rules, automated backups |
| Weekly | Apply plugin, theme and core updates on a staging copy, then push live. Check the site still works afterwards. |
| Monthly | Submit a real test enquiry through every form. Check speed. Review Search Console for new errors. Delete unused plugins. |
| Quarterly | Restore a backup somewhere safe to prove it works. Full broken link scan. Review Core Web Vitals against the 2.5 second, 200 millisecond and 0.1 thresholds. |
| Annually | Audit every plugin for whether it is still maintained and still needed. Refresh outdated content, pricing and staff pages. Review hosting. |
Note the weekly item says staging, not live. Updating a live site and hoping is the single most common way maintenance itself causes an outage.
The five step monthly routine
Test every form yourself
Submit a real enquiry from a phone. Confirm it arrives in the inbox someone actually reads, not a spam folder.
Output: proof leads arriveUpdate on staging, then live
Apply core, plugin and theme updates on a copy first. Load three key pages. Only then push to the live site.
Output: patched, not brokenVerify the backup
Check the latest backup exists, is recent, and lives off the server. Once a quarter, actually restore it somewhere.
Output: a recovery you trustCheck speed and Search Console
Run a speed test on mobile data. Open Search Console and read anything new under coverage and page experience.
Output: problems found earlyRemove what you stopped using
Deactivate and delete unused plugins and themes. An inactive plugin still carries its vulnerabilities.
Output: smaller attack surfaceDoing it yourself or paying someone
Handle it in house if
- Someone on your team is genuinely comfortable with staging and rollbacks
- Your site is simple, with few plugins and no payments
- That person has protected time for it, not just good intentions
- You have a written checklist so it survives that person leaving
- You can tolerate a day of downtime without losing serious money
Pay for it if
- Your site takes payments or bookings
- Enquiries from the site are a meaningful share of your revenue
- Nobody in house would notice a broken form for a week
- You run more than a handful of plugins, which is most sites
- You would rather buy the outcome than learn the job
Neither answer is wrong. What is wrong is the third option most businesses actually pick, which is assuming someone is handling it when nobody is.
What maintenance does for your search visibility
Maintenance is not an SEO tactic, but neglect is reliably an SEO problem. A compromised site can be flagged in Search Console and lose visibility fast. Broken pages and dead internal links waste crawl effort and strand content. Speed decay pushes Core Web Vitals past the thresholds Google measures on real visitors: 2.5 seconds for Largest Contentful Paint, 200 milliseconds for Interaction to Next Paint, and 0.1 for Cumulative Layout Shift, assessed at the 75th percentile.
There is a blunter version of this. Everything you invest in search visibility sits on top of a site that has to keep working. When the foundation fails, the investment above it fails with it, and you generally find out from a drop in enquiries rather than a warning.
What a real maintenance plan includes
Ask for these five things in writing before you pay anyone monthly.
A stated update cadence, including whether updates are tested on staging first. "As needed" means no cadence.
Backup frequency, storage location and retention. Off site, and kept long enough that you can go back past a problem you noticed late.
A monthly report you can actually read. What was updated, what broke, what was fixed, current speed. If nothing is ever reported, nothing is verifiable.
A response time for emergencies, and what counts as one. A site down on a Saturday needs a defined answer, not goodwill.
What is excluded. Most plans cover upkeep, not new pages or redesigns. That is reasonable, but it should be written down rather than discovered in an argument.
Two red flags: a plan that includes no reporting at all, and a plan sold as maintenance that is really a hosting bill with a nicer name. If you want a second opinion on your current arrangement, our free website review covers speed, indexing and function, and you can take the findings anywhere. If you would rather hand it over, that is what our website maintenance services do.
Frequently asked questions about website maintenance
What does website maintenance actually include?
Six jobs: applying core, plugin and theme updates safely; taking and verifying off site backups; security monitoring and malware scanning; checking that forms, links and payments still work; keeping speed from decaying; and fixing outdated or broken content. Anything sold as maintenance that does not include the first four is really hosting.
How often should a business website be updated?
Security and plugin updates should be applied weekly at minimum, tested on a staging copy first. Patchstack found the weighted median time to first exploit for heavily targeted vulnerabilities is 5 hours, and roughly half of high impact flaws are exploited within 24 hours, so a quarterly update cycle leaves months of exposure.
Is WordPress itself insecure?
The core software is not the problem. Of 11,334 vulnerabilities reported across the WordPress ecosystem in 2025, 91 percent came from plugins and 9 percent from themes, while WordPress core accounted for just 6, all low priority. The risk comes from what gets added to a site, which means plugin discipline is the single most effective security habit available to you.
How much should website maintenance cost?
It depends on the size and risk of the site, so treat any fixed number you read online with suspicion. What matters more than the price is what you get for it: a stated update cadence, off site backups with a retention period, security monitoring, and a monthly report. Compare those five things across quotes rather than comparing headline prices.
Can I just do the updates myself?
Yes, if you are comfortable working on a staging copy and rolling back when an update breaks something. The risk is not clicking update, it is what happens when a plugin conflict takes the site down on a Friday afternoon. If your site takes payments or generates a meaningful share of your revenue, the cost of getting that wrong usually exceeds the cost of paying someone.
What happens if I never maintain my website?
Usually nothing visible for a while, then several things at once. Sites accumulate unpatched vulnerabilities, forms quietly stop delivering, speed decays, links break, and eventually something is compromised or an update forced by a PHP change breaks the whole layout. The bill arrives as emergency work at emergency rates, plus whatever the leads you never received were worth.
Does website maintenance affect SEO?
Neglect does. A compromised site can be flagged and lose visibility quickly, broken links and error pages waste crawl effort, and speed decay pushes Core Web Vitals past Google's thresholds of 2.5 seconds, 200 milliseconds and 0.1, which are measured on real visitors at the 75th percentile. Maintenance will not win you rankings, but its absence will cost you them.
How do I know my backups actually work?
Restore one. That is the only test that counts. Check that backups run automatically, are stored somewhere other than the server they came from, and are kept long enough to go back past a problem you noticed late. Then restore a copy to a staging environment at least quarterly, because backups fail silently and only announce it on the day you need them.
What is the difference between hosting and maintenance?
Hosting is the server your site sits on. Maintenance is the work done to the site itself: updates, backups, security, monitoring and fixes. Some hosts bundle a little of the second into the first, which is useful but rarely complete. If your only arrangement is hosting, assume nobody is applying your plugin updates.
My site works fine. Do I really need this?
A site that works fine today is exactly the situation maintenance protects. The failures that cost most are the silent ones: a form that stopped delivering, a backup that stopped running, an unpatched plugin. None of them announce themselves, and all of them are cheap to prevent and expensive to discover late. Submit a test enquiry through your own form this week and see.
About this article. Written by the team at FOG Digital Marketing, a San Antonio agency working with local service businesses and ecommerce brands across South Texas. Our office is at 2822 N Loop 1604 W Suite 109, San Antonio, TX 78248, and you can reach us on (726) 224-4920.
Sources cited. Patchstack, State of WordPress Security in 2026, covering 11,334 vulnerabilities reported during 2025. Google and web.dev, Core Web Vitals thresholds and 75th percentile assessment. Deloitte with Google, Milliseconds Make Millions.
Not sure anyone is actually maintaining your site?
We will check your updates, backups, speed and forms, and tell you plainly what is being looked after and what is not.
