Maintenance

What a WordPress maintenance plan should actually include

Maintenance plans are the least glamorous thing an agency sells and the easiest to sell badly, because the value is invisible when it works. Here is what a plan should actually contain, and how to tell whether the one you are being offered is care or just a recurring invoice.

1. Updates applied on staging first

This is the single biggest difference between a real plan and a cheap one. Core, theme and plugin updates should go to a staging copy, get checked against your key pages and critical flows, and only then reach production.

For a store that means somebody actually completes a test checkout. For a lead-gen site it means the forms get submitted. “We update your plugins” without staging is clicking Update All on a Friday and hoping — which is how most of the incidents we get called about happened.

2. Backups that have been tested by restoring them

Almost every plan promises backups. Very few test them. A backup plugin reporting success every night proves the job ran, not that the archive is complete or restorable.

Ask this question: “When did you last restore one of my backups, and how long did it take?” The answer tells you immediately whether the backup is a safety net or a line item.

You want offsite storage, versioned snapshots going back far enough to survive a problem you did not notice for a week, and a documented recovery process.

3. Monitoring that alerts them, not you

Uptime checks every minute from multiple locations, with the alert going to the people who can fix it. If you find out your site is down because a customer emailed you, you are not being monitored.

Good plans also track performance over time, so a gradual slide is visible while it is still small, and file integrity, so unexpected changes surface quickly.

4. Security patching outside the normal cycle

Regular updates run on a schedule. Critical vulnerabilities do not wait for it. A plan should commit to applying serious security patches out of cycle, which means somebody is watching vulnerability databases for the specific plugins you run.

5. A named human with an agreed response time

Not a ticket queue that returns a reference number. Someone who knows your site and can answer “is this normal?” quickly. Most of what clients need is a short honest answer, and needing to file a formal request for that is friction with no purpose.

6. Reporting that produces decisions

An automated list of plugins updated is not a report. A useful one says what changed, what is degrading, what is at risk, and what should be considered next quarter. If the report never leads to a decision, it is not doing anything.

What should not be in a plan

Just as important, and where disputes come from. New feature work, redesigns and substantial development should be quoted separately. When they get quietly absorbed, one of two things happens: the plan becomes unprofitable and quality drops, or “maintenance” expands until nobody knows what is covered.

Get the boundary in writing. A good agency will have already written it down.

Red flags

  • No staging environment. Then updates are being applied straight to production.
  • Backups that have never been restored. Ask for the date. Hesitation is the answer.
  • Hosting locked in their account. Leaving should not require a migration.
  • No named contact. “Our team” means nobody in particular knows your site.
  • Unlimited everything. Either heavily caveated in the small print or unsustainable. Neither is good for you.

Is it worth it?

Compare the annual cost against one incident: a day of downtime, an emergency malware cleanup, or a broken checkout on your busiest weekend. For most businesses whose site earns money, the plan costs less than the single incident it prevents.

For a small brochure site updated twice a year, it may genuinely not be worth it — and an agency that tells you so is one worth keeping.