WordPress support

WordPress maintenance services run by developers, not scripts

Core, plugin and theme updates are tested on a staging copy before they reach your live site. Backups are restored to prove they work, and you get a plain report every month.

  • Updates tested on staging
  • Backups we actually restore
  • Written report each month
What is included
  • Tested updates
  • Backups and restore tests
  • Uptime and security monitoring
  • Malware cleanup and hardening
  • Performance checks
  • Small-change hours
Get a free quote Reply within one business day. NDA on request.
The problem

What neglected WordPress sites have in common

Nobody plans to neglect a WordPress site. The agency that built it moved on, automatic updates were switched off after one broke the checkout, and now the dashboard shows twenty-three pending updates that nobody dares to run. Meanwhile the backup plugin has been emailing a failure notice to an address no one reads.

Maintenance is the dull, regular work that prevents the expensive emergency. We take over that routine for company sites, stores, LMS platforms and membership sites, including ones we did not build. A developer reads the changelogs, applies updates on staging, checks the pages that matter and then releases. Monitoring runs around the clock, and our developers respond during working hours. Plans are scoped after a review of your site, because a brochure site and a busy store do not need the same care.

  • Updates are overdue and risky

    The last update broke a layout, so they stopped. Core, PHP and a dozen plugins are now several releases behind, and each month makes the jump bigger.

  • Backups nobody has restored

    Copies are stored on the same server as the site, or the job has been failing silently. The first real test will be the day you need it.

  • The site was hacked once already

    Spam pages appeared in search results or visitors were redirected elsewhere. A cleanup plugin removed some files, but the way in was never found.

  • Small changes wait for weeks

    A banner swap, a new form field or a broken link needs a developer, and there is no one on call. Minor requests pile up until they become a project.

What we do

What a care plan covers

A plan combines preventive work on a fixed schedule with developer time for the things that come up. The exact mix is set after we have reviewed your site.

Tested updates

WordPress core, plugins, themes and PHP versions updated on staging first, with checks of checkout, login, forms and key templates before the same changes go live.

Backups and restore tests

Scheduled off-site backups of files and database, retained on an agreed cycle, and restored to a test environment periodically to confirm they are complete.

Uptime and security monitoring

Automated checks around the clock for downtime, changed core files, new admin accounts, blocklist status and expiring SSL certificates, with alerts routed to our team.

Malware cleanup and hardening

Infected files and database entries removed, the entry point traced and closed, credentials rotated, then login protection and file permissions tightened.

Performance checks

Core Web Vitals, slow queries, autoloaded options, cache behavior and database growth reviewed regularly, so gradual slowdowns are caught before visitors complain.

Small-change hours

A block of developer time each month for content fixes, layout tweaks, new form fields and plugin settings, requested by email or your usual channel.

Typical projects

Who hands us their maintenance

01

A company site with no developer

Marketing owns the content but nobody owns the software. We keep it current and secure, and handle the occasional change request without a new contract each time.

02

A store or LMS that cannot be down

Updates are rehearsed against checkout, enrollment and payment paths on staging, released in quiet hours and watched afterwards, with a rollback ready.

03

An inherited or neglected site

We start with an audit, clear the backlog of updates in safe stages, remove dead plugins and document what the site depends on before routine care begins.

04

Agencies needing a technical back office

Design and marketing agencies pass us the upkeep of client sites under NDA, with reports written so they can be forwarded to the end client.

In depth

How we keep a WordPress site healthy

The onboarding review sets the plan

We begin every engagement by reading the site, not by installing a dashboard. Which plugins are active, which are abandoned, where custom code lives, what PHP version the host runs, how backups are taken, who has administrator access. We look for edits made directly to plugin or parent theme files, since those are what make updates dangerous. The review ends with a short written list: risks to fix now, things to watch, and the amount of monthly attention the site needs. Your plan is scoped from that list.

How an update cycle runs

Staging is refreshed from production so tests reflect the current site. We read the changelog of each pending update and separate security fixes, which go out quickly, from major releases, which get more testing. Updates are applied with WP-CLI in small groups, never all at once, so a fault can be traced to one plugin. Then we check the paths that earn or protect revenue: place a test order, log in as a member, submit the main form, open the templates with the most traffic. Only after that does production receive the same set, and the previous versions are kept so rolling back is a known step.

Backups are only as good as the last restore

A backup that has never been restored is a hope. We keep copies off the web server, cover both database and uploads, and match frequency to how often the data changes. A store that takes orders every hour needs a different schedule from a site edited weekly. On a regular cycle we restore one to a blank environment and confirm the site boots, recent content is present and media loads. The result goes in your report.

Security work is mostly prevention

Monitoring watches for file changes in core directories, unexpected administrator accounts, failed-login spikes and vulnerability disclosures that match your plugin list. When a serious disclosure lands we patch outside the normal cycle. If a site is already infected, cleaning files is half the job. We find how the attacker got in, whether through an outdated plugin, a stolen password or a writable upload folder, then close that door and rotate keys and passwords. If the damage comes from years of patchwork, a rebuild or a move to a cleaner environment may be the honest advice.

What the monthly report tells you

One page, in plain language: updates applied, anything held back and why, backup and restore status, uptime, security events, speed measurements against last month, hours used on changes and our recommendations. If we think a plugin should be replaced, the hosting is holding you back or the site needs a dedicated performance optimization project, it is written there with reasons.

Process

Taking over a site, step by step

  1. 1

    Site review

    You give us access and we audit plugins, theme, hosting, backups and user accounts. The findings and a proposed scope come back in writing.

  2. 2

    Stabilize

    Urgent risks are handled first: a working off-site backup, critical security updates, and removal of unused plugins and accounts.

  3. 3

    Staging and monitoring setup

    A staging copy, uptime checks, file-change alerts and backup schedules are put in place, and we agree how you will send requests.

  4. 4

    Monthly cycle

    Updates are tested and released, backups verified, performance measured and your small changes completed within the hours in the plan.

  5. 5

    Report and review

    You receive the monthly report. Every so often we revisit the plan and adjust it if the site, traffic or team has changed.

Deliverables

What you receive every month

  • Updates applied only after testing on staging
  • Off-site backups with documented restore tests
  • Alerts for downtime and suspicious changes
  • Developer hours for small changes each month
  • A plain-language report with our recommendations
FAQ

Support plan questions answered

What does a WordPress maintenance plan cost?
It depends on the site. The number of plugins, whether there is a store or LMS, how much traffic it gets and how many change hours you want all affect the work involved. We review the site first and then propose a plan, so you are not paying for a tier that does not fit.
Do you maintain sites that another company built?
Yes. We do not need to have built a site to look after it. The onboarding review tells us what we are taking on. If we find direct edits to plugin files or premium plugins without a valid license, we raise them at the start and agree how to resolve them.
Is support available at night and on weekends?
Monitoring runs around the clock, so downtime and security alerts are raised at any hour. Our developers respond during working hours by default. If your site needs emergency cover outside those hours, raise it during the review and we will tell you plainly what we can offer.
What happens if an update breaks something?
It should break on staging, where nobody sees it. We then hold that update, report the conflict to the plugin author or patch around it, and release the others. If a problem appears only on production, we roll back to the previous version and investigate from there.
Our site has been hacked. Can you help now?
Yes. Send us the URL and what you have noticed. We take a copy of the current state for analysis, clean files and database, find and close the entry point, reset credentials and request removal from blocklists. Ongoing monitoring afterwards is strongly advised, since reinfection is common when only the symptoms were removed.
What counts as a small change, and what is a separate project?
Small changes are tasks a developer can finish within the plan's hours: text and image edits, a form field, a plugin setting, a minor layout fix. New features, redesigns and integrations are quoted separately. For steady development work, some clients hire a WordPress developer alongside the plan.
What access do you need to our site and hosting?
An administrator account, hosting or SFTP access and a view of DNS, so we can run backups, staging and monitoring. We ask for individual accounts instead of shared logins, which lets you revoke access at any time, and we sign an NDA on request.
Related

From the blog

All articles
Start a project

Ask for a review of your WordPress site

Send the URL and tell us what worries you most. We reply within one business day, take a look at the site and propose a plan that fits it, with a free quote.

  • Free consultation and quote
  • NDA on request
  • You own the source code
  • Reply within one business day
Add budget and timeline optional, helps us quote faster

This form is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.