A website feels unusually complete on launch day. Every page has been checked, the forms have been tested and the old temporary text has finally disappeared. It is tempting to regard the job as finished.
The site is finished in the same sense that a new shop is finished on opening morning. It is ready to work. It is not exempt from maintenance, change or the occasional unexpected problem.
This is not an argument for constantly redesigning a website to create work for web designers. It is an argument for sensible website maintenance: treating a business asset as an asset and keeping it secure, accurate, measurable and appropriate to the people using it.
The software around the content keeps changing
A WordPress site is made from several moving parts. WordPress itself changes. Themes and plugins release security fixes and new versions. PHP and database software evolve on the server. Browsers and phones change how pages are rendered.
Doing nothing is therefore a decision to let the gap widen between the site's current state and the environment in which it runs.
WordPress's official guidance recommends keeping the software on the latest version and backing up before updates so the site can be restored if a problem occurs. Minor and security updates may be applied automatically, but themes, plugins and larger releases still need oversight.
Updates should not be installed with blind optimism. A care process checks what will change, creates a recoverable backup, applies updates and confirms that important parts of the site still work. A dashboard showing green ticks is useful; a completed enquiry reaching the inbox is better evidence.
Backups only matter if they can be restored
“The host does backups” is a promising beginning, not a complete recovery plan.
A useful backup arrangement answers several questions:
- How often are files and the database backed up?
- How many versions are retained?
- Is a copy kept separately from the live hosting account?
- Can one page or file be recovered, or only the whole site?
- Who knows how to restore it?
- Has restoration ever been tested?
Ireland's National Cyber Security Centre baseline guidance includes understanding the schedule, frequency and type of backup appropriate to business requirements. The principle is proportionate: a site that changes once a month has different recovery needs from a shop taking orders throughout the day.
A backup that exists but cannot be found, decrypted or restored when needed is a rather ceremonial form of reassurance.
Security is a routine, not a product badge
Security plugins, managed hosting and protective services can reduce risk. None creates a permanent “secure” state.
Ongoing work includes removing unused accounts and software, using strong authentication, checking administrator access, applying supported updates, monitoring suspicious changes and responding when a vulnerability is announced. WordPress's hardening guidance describes security as risk reduction rather than an absolute guarantee.
The human side matters too. A perfectly patched website can still be compromised through a reused password, a convincing phishing message or an administrator account given to somebody who no longer needs it.
Good maintenance therefore includes access housekeeping as well as software updates. People should have the permissions required for their job and no more.
The business can make its own website inaccurate
Sometimes the technology is healthy while the content is quietly becoming wrong.
Prices change. Staff move. Services are renamed. Opening hours alter. A business begins working with a new kind of client but its homepage still speaks to the old audience. An embedded booking service is retired, yet the button remains.
These errors affect trust because visitors reasonably assume the website represents the current business. Stanford's web-credibility guidance found that recently updated or reviewed content contributes to credibility, while errors and broken links damage it.
A regular content review need not become an endless rewrite. Check the pages that influence decisions most: homepage, services, prices, contact details, team information, legal notices and frequently visited articles. Add a visible “last reviewed” date where currency matters.
Performance drifts as sites accumulate things
Websites often become slower gradually. A new analytics script is added, then a chat widget, several large photographs and a plugin used for one campaign that nobody later removes.
Google's current Core Web Vitals measure loading, responsiveness and visual stability. The recommended thresholds include a Largest Contentful Paint within 2.5 seconds, Interaction to Next Paint of 200 milliseconds or less and a Cumulative Layout Shift score of 0.1 or less, assessed at the 75th percentile.
Those figures are useful indicators, not the entire user experience. The practical concern is simple: can real visitors, particularly on phones and ordinary connections, reach and use the important content without irritation?
Routine care should monitor trends rather than chase a perfect laboratory score. A sudden regression after installing a plugin matters more than a decorative badge declaring 100 on one test run.
User journeys change with the business
The first version of a website is built from the best available understanding of customers. Once it is live, the business begins collecting better evidence.
People may repeatedly ask a question the site was supposed to answer. Visitors may arrive on a service page and return to Google because the next step is unclear. The most valuable clients may be interested in a service that was given very little prominence.
Small improvements can respond to this evidence: rewrite a heading, move a relevant testimonial, simplify a form, clarify a price or add an article answering a genuine sales question. This is usually healthier than leaving the site untouched for four years and then commissioning a crisis redesign.
A refresh is not necessarily a rebuild
Design ages, but not every change requires demolition.
A yearly review might find that the visual system remains sound while photographs, spacing and a few components need attention. A larger refresh may update typography, colour use and page templates without replacing the content platform. A rebuild becomes appropriate when the structure, technology or business position no longer provides a useful foundation.
The decision should be diagnostic. “It looks old to me” deserves investigation, as does “our competitors have animation”. Neither is a strategy by itself.
What a sensible care plan should contain
Care plans vary, so the name alone tells you little. A useful agreement should state the actual work and boundaries. Depending on the site, that may include:
- Managed hosting and uptime monitoring.
- Scheduled backups and a restoration process.
- WordPress, theme and plugin updates.
- Security monitoring and response arrangements.
- Checks of forms and important visitor journeys.
- Performance and broken-link monitoring.
- A defined allowance for content changes.
- Periodic design and UX review.
- Clear response times and an emergency contact route.
- Reporting in language the owner can understand.
It should also say what is not included. Malware recovery, major new functionality, copywriting, ecommerce support and third-party subscription fees may require separate scope. Ambiguity is not a benefit merely because it fits on a shorter sales page.
Hosting, maintenance and improvement are different jobs
These services are often bundled, which can make the boundaries difficult to see. Hosting supplies the environment in which the website runs. Technical maintenance looks after software, backups, security and routine checks. Content and design improvement keep the site aligned with the business and its visitors.
A good host may provide excellent server backups and malware controls without checking whether your contact form still reaches the right person. A maintenance provider may update plugins reliably without rewriting an outdated service page. A designer may improve the user journey without taking responsibility for emergency recovery at two in the morning.
None of those arrangements is inherently wrong. Problems arise when everybody assumes somebody else is watching. The agreement should identify which layer is covered, who receives alerts and who is authorised to act when something fails.
For a modest business site, one person or company may sensibly coordinate all three. The important point is not the number of suppliers; it is continuity of responsibility.
A practical maintenance rhythm
Different sites need different frequencies, but a modest service-business site might use the following rhythm.
Weekly or automated
Monitor availability, security alerts, backups and form delivery. Automation is useful here because nobody should have to remember to check whether the site disappeared overnight.
Monthly
Review and apply updates, check representative pages and forms, inspect performance changes, remove obvious spam and make routine content amendments.
Quarterly
Review analytics and search performance, broken links, user journeys, administrator access and the accuracy of core service information. Decide whether any repeated client question deserves a new page or article.
Annually
Consider the site's visual freshness, positioning, content structure, technical stack and relationship to the current business plan. This may lead to a light refresh, a larger improvement project or the reassuring conclusion that the site still does its job.
A simple responsibility map prevents neglect
For each recurring task, write down an owner and a fallback. Who renews the domain? Who receives uptime and security alerts? Who approves updates, checks the enquiry form, reviews analytics and notices when a key member of staff has left the About page?
The list can be short, but “the website company probably does it” is not an owner. If a supplier is responsible, the task should appear in the agreement. If the business is responsible, it should belong to a named person rather than an unattended shared inbox.
Also record where access is kept and how it can be recovered. The domain registrar, hosting account, WordPress administrators, analytics property and paid licences should remain identifiable even when staff or suppliers change. That modest piece of administration can save an astonishing amount of detective work during an urgent problem.
What should it cost?
The price depends on risk, complexity and the amount of human time included. Basic updates and monitoring for a small brochure site cost less than active care for ecommerce, bookings or membership data.
When comparing plans, look beyond the update count. Ask whether backups are tested, whether somebody checks the front end after changes, whether content time is included and what happens during an incident.
My own website pricing starts at €150 per month on a 12-month commitment and combines the website with hosting, monthly security and plugin updates, ongoing content changes, incremental design work and a yearly refresh or redesign. That model suits businesses that prefer continued attention to a handover followed by a separate maintenance decision.
It will not suit everybody. Some owners have the skills and time to manage their site responsibly; others may prefer a one-off build and a lighter technical plan. The important thing is that somebody has accepted each responsibility.
The point is continuity, not constant interference
A maintained website should not feel permanently under construction. Most of the work is quiet: preventing avoidable failures, noticing drift and making useful changes before small problems become expensive ones.
The website remains recognisable. It simply continues to match the business, the technology and the expectations of the people using it.
If you are unsure what your current site actually needs, see my services or contact me for a practical conversation. A responsible review may conclude that the site needs a rebuild, a handful of repairs or merely a better care routine.
Sources and further reading
- Updating WordPress — WordPress.org
- Hardening WordPress — WordPress Developer Resources
- Cyber Security Baseline Standards — National Cyber Security Centre Ireland
- Stanford Guidelines for Web Credibility
- Web Vitals — web.dev
Important note
This article provides general information and professional commentary. It is not advice tailored to your particular business, website or circumstances, and it should not be treated as legal, financial, privacy, accessibility, cybersecurity or other specialist advice. Any opinions are my own professional judgement based on the information available when the article was researched.
Products, prices, services, software and official guidance can change. External links are provided for reference; I do not control third-party websites and cannot guarantee their continuing availability, accuracy or content. A link does not imply endorsement of everything published by that source.
Check current official information before making an important decision. Test technical changes safely, keep a verified backup, and obtain appropriately qualified advice where the consequences warrant it. Any sponsorship, free product, affiliate link or other commercial relationship relevant to the article will be clearly disclosed.




