A website is not finished.
It's maintained.

Platform and plugin updates, security patching, backups, broken-link checks and the content changes you never get round to, done on a schedule and tested before they go live.

MonthlyUpdate cycle
StagingTested before live
30-dayBackup retention

Update queue · a typical week

Staging tests passed
CORE
Platform & core updatesSecurity releases applied first, out of hours
security releaseLive
PLUG
Plugins & extensionsChangelogs read, safe releases applied
weekly cycleLive
PLUG
Forms & integrationsMinor releases, no visual change expected
bundledStaging
DEP
PHP & dependenciesCompatibility scanned before any upgrade
plannedNeeds review
SEC
Vulnerability watchlistFeeds checked daily against your versions
daily scanClear
Maintained by ACSBackups nightly, off-site

Nothing goes wrong for months.
Then everything does at once.

Websites decay quietly. Plugins fall behind, PHP moves on, certificates expire, and the first sign of trouble is usually a white screen or a Google warning.

An unmaintained website

  • Plugins two years behindEvery out-of-date extension is a published, well-documented way in. Most hacked sites are hacked through one.
  • Updates clicked in a panicSomeone hits “update all” on the live site with no backup, and the layout breaks on a Friday afternoon.
  • An unsupported PHP versionThe host forces an upgrade, the theme wasn't written for it, and the site goes white overnight.
  • Content nobody has time to changeLast year's offer, an old phone number, staff who left, and a blog that stopped in 2023.
  • Rebuilt every four yearsDeferred maintenance becomes a five-figure rebuild, because catching up costs more than keeping up.

A website on a care plan

  • Updates on a monthly cycleCore, theme, plugins and dependencies reviewed every month, security releases applied within 24 hours.
  • Tested before it's liveChanges go to a staging copy first, with key journeys tested; forms, checkout and logins.
  • A restore point before every changeFull file and database backup taken first, so any update can be reversed in minutes, not days.
  • Content changes includedA block of hours each month for the banners, offers, products and posts you'd otherwise never get to.
  • It ages slowly, not suddenlySmall, continuous work instead of a rebuild.

The jobs a website needs
every single month.

Technical upkeep and practical content work, in one plan, on one bill, whether we built the site or inherited it.

Core & platform updates

WordPress, Joomla, Magento or your framework kept current - major versions planned, tested and scheduled rather than sprung on you.

Plugin & extension updates

Every add-on reviewed weekly. We read the changelogs, apply what's safe, hold what isn't, and remove what you no longer use.

Dependency & PHP upgrades

PHP, database and library versions tracked against end-of-life dates, with compatibility scanned and fixed before your host forces the change.

Security patching & scanning

Vulnerability feeds watched daily, malware scans, firewall rules and hardened admin access. Critical patches applied within 24 hours.

Backups & rollback

Nightly off-server backups plus a restore point taken immediately before every update, retained 30 days and periodically test-restored.

Speed & Core Web Vitals

Page-speed tracked month to month, with caching, image and database optimisation when the numbers start drifting.

Broken links & 404s

Automated crawls catch dead links, missing images and orphaned pages, with redirects put in place so nothing is lost.

Content & product updates

Banners, seasonal offers, adverts, blog posts, staff pages and e-commerce catalogue changes - added, edited or removed on request.

Monthly reporting

One page in plain English: what was updated, what was blocked and why, uptime, page speed, backups verified and hours used.

Maintenance is a rhythm,
not a reaction.

Four cycles running in the background. You don’t have to remember any of them.

Daily
Watch
  • Uptime and response checks
  • Malware & vulnerability scans
  • Off-server backup verified
  • Security releases assessed
Monthly
Update
  • Core, theme & plugin updates
  • Applied on staging, then live
  • Key journeys re-tested
  • Spam & database cleanup
Monthly
Review
  • Page-speed & Core Web Vitals
  • Broken links and 404 report
  • Content & product changes
  • Plain-English report issued
Quarterly
Plan
  • PHP & dependency roadmap
  • Major version upgrades scheduled
  • Restore tested from backup
  • Plugin audit and remove the unused ones

Security releases are the exception to the schedule, anything critical is applied within 24 hours, out of hours where needed.

Skipping updates is
a decision with a date on it.

Roughly what happens to a business website left alone, based on the sites we get called in to rescue.

Months 1-3: nothing looks wrong

A handful of plugin updates sit pending. The site looks fine, so nobody acts, and small compatibility gaps start opening between components.

Low

Months 4-6: speed and SEO slip

Page weight creeps up, caching drifts out of date, Core Web Vitals drop and rankings soften. Contact forms quietly stop delivering.

Moderate

Months 7-12: real exposure

Published vulnerabilities now apply to your version. Bots find the site automatically, this is the window where most compromises happen.

High

Year 2+: rebuild territory

Updating in one jump breaks the theme. PHP is unsupported, the host forces a change, and the honest quote is a rebuild.

Critical

We maintain the site you have,
not just the ones we built.

Inherited a site from another agency, or from a developer who’s moved on? We’ll audit it first and tell you honestly what shape it’s in.

Content platforms

Core, theme and plugin lifecycle managed on the major CMS platforms.

  • WordPress
  • Static & headless

E-commerce

Catalogue, checkout and payment extensions kept current and tested end to end.

  • WooCommerce
  • Magento
  • OpenCart
  • Payment gateways

Server & dependencies

The layer underneath, tracked against end-of-life dates rather than left to chance.

  • PHP 8.x
  • MySQL / MariaDB
  • Node & npm packages
  • Cpanel \ WHM
  • SSL & TLS

Nobody clicks
“update all” on a live site.

Every change follows the same four steps, every time, whether it’s one plugin or a platform upgrade.

01Stage 1 of 4
Step 01 · Review

Read the changelogs first

Every pending update is checked against what it actually changes: security fix, feature release or breaking change. Anything known to conflict with your theme is held back, not gambled on.

  • Vulnerability feeds
  • Changelogs read
  • Risky releases held
Step 02 · Backup

Take a restore point

Files and database are backed up off-server immediately before anything is touched. If an update misbehaves, we roll back in minutes, not spend an afternoon working out what changed.

  • Full file + database
  • Stored off-server
  • Rollback in minutes
Step 03 · Stage & test

Apply on a copy, then check it by hand

Updates go to a staging clone first. We walk the journeys that earn you money: contact forms, checkout, logins, search and look at the pages, rather than trusting a green tick.

  • Staging clone
  • Forms & checkout tested
  • Visual check
Step 04 · Deploy & report

Go live out of hours, then write it down

Changes are pushed to the live site outside business hours and re-checked. At month end you get one page telling you what was updated, what was held and why, and what we recommend next.

  • Out-of-hours deploy
  • Post-deploy checks
Keep scrolling

Common questions

Before you hand it over.

Yes, many of the sites we maintain came from somewhere else. We start with an audit of the platform, plugins, dependencies and backups, and give you a written picture of its condition before quoting a plan.

Updates are applied to a staging copy and tested before they touch the live site, and a restore point is taken immediately beforehand. If something slips through, we roll back and fix it as part of either a maintenance plan or a one-off job.

No. Security releases go on immediately; major feature releases are held until they’ve settled and been tested against your theme.

Text and image edits, new pages, blog posts, seasonal banners, promotional offers, adverts, staff changes, and adding, editing or removing products. Anything larger, e.g. a new section or a redesign, is quoted separately so you always know before it’s done.

No, though it makes staging and rollbacks quicker. If you’re elsewhere we’ll need suitable access and a host that allows backups; if the current host makes safe maintenance impossible, we’ll tell you.

You do. Domain, hosting, CMS all stay in your name, and you keep admin access throughout. If you ever leave, everything goes with you.

Maintenance plans run monthly with a 30-day notice period, or annually if you’d prefer to fix the cost. No minimum term beyond that.

Usually not. We’ll quote a one-off catch-up to get everything current and stable, then the ongoing plan keeps it there. Catching up is almost always cheaper than rebuilding, we’ll say so plainly if it isn’t.

Need a quote on Website Maintenance Services?

Get in touch and we can provide the best solution for your needs.

ACS at work