Most websites are built as a project and then left alone. The launch budget gets approved, the site goes live, and maintenance becomes something that happens when something breaks.
That approach works for a while. Then a plugin stops getting updates, a form quietly stops sending emails, or a security advisory comes out for a module nobody remembers installing. By the time anyone notices, the fix is bigger and more urgent than it needed to be.
This post is a checklist you can use to judge a maintenance plan, whether you run it in-house or pay someone else to.
Every week
Security updates
This is the core of maintenance. Your CMS, its modules or plugins, your frontend dependencies and your server software all receive security fixes. A good plan watches the official advisories for everything your site uses and applies critical fixes within days, not at the end of the month.
The important detail is testing. Updates should be applied on a staging copy of the site first, checked, and then deployed. Updating production directly saves an hour and occasionally costs a day.
Uptime and error monitoring
Someone should know your site is down before your customers tell you. Uptime monitoring is cheap and simple. Error monitoring is more useful: it catches the checkout that fails for one payment method, or the page that throws an error only for logged-in users.
Backups
Backups should run automatically, be stored somewhere other than the server they back up, and cover both the database and uploaded files. A backup you have never restored is a guess. Test a restore occasionally.
Every month
Non-security updates
Minor releases of your CMS and modules bring bug fixes and small improvements. Applying them regularly keeps each update small. Skipping them for a year turns a routine task into a project, and it makes the next major version upgrade much harder.
Form and integration checks
Contact forms, newsletter signups, CRM integrations and payment flows break silently more often than anything else, usually because a third-party service changed something. Submit each important form and check that the result arrives where it should.
Performance check
Look at your Core Web Vitals in Search Console and run your key pages through PageSpeed Insights. Performance tends to decay slowly as content editors add large images and marketing adds new scripts. Catching it monthly means small fixes rather than a rescue project.
A short report
You should receive a plain summary of what was updated, what was found and what needs a decision from you. If a provider cannot tell you what they did last month, assume they did very little.
Every year
Platform and hosting review
Check how long your CMS version, PHP version and hosting stack will remain supported. End-of-life dates are announced well in advance, and an upgrade planned a year ahead costs a fraction of one done in a hurry.
Access review
Remove accounts for people who left the organization, contractors who finished their work and test users nobody needs. Make sure admin accounts use strong passwords and, where possible, two-factor authentication.
Dependency cleanup
Remove modules, plugins and scripts that are no longer used. Every piece of code you remove is code that cannot break, slow the site down or be exploited.
Accessibility and content check
Spot-check key pages with an accessibility checker and a keyboard. Look for broken links, outdated pages and old promotions that are still live.
What it costs to skip maintenance
The cost of skipping maintenance rarely shows up as a single bill. It shows up as:
- An emergency fix after a security issue, done at short notice and at a higher rate.
- A major upgrade that becomes a rebuild because the site fell too many versions behind.
- Leads lost to a contact form that stopped working weeks ago.
- Search visibility lost slowly to a site that got heavier every month.
- Hours of staff time spent working around problems nobody had time to fix.
None of these are certain on any given month. Over a few years, at least one of them is very likely.
Questions to ask a maintenance provider
When you compare plans, these questions separate real maintenance from a monthly invoice:
- How quickly do you apply critical security updates, and how do you find out about them?
- Do you test updates on staging before they reach production?
- Where are backups stored, and when did you last test a restore?
- What monitoring do you run, and who gets alerted?
- What does the monthly report include?
- How many hours of changes or improvements are included, and what happens to unused hours?
- What is your response time for urgent issues, and is it written down?
A good provider will answer all of these without hesitation. If the answers are vague, the maintenance probably is too.
We offer maintenance plans for Drupal, React and Gatsby sites. Get in touch and we will review your site and suggest what it actually needs.