Website Maintenance: What You're Really Paying For
“Can’t I just leave it once it’s built?”
It’s a fair question. You’ve paid for a website, it looks great, everything works. Why does someone need to keep doing things to it every month?
The honest answer is that a WordPress website is not a printed brochure. It’s running software, connected to the internet, constantly exposed to automated bots and security scanners, built on a platform that releases updates every few weeks. The moment you stop maintaining it, it starts deteriorating - slowly at first, then faster.
Here’s what website maintenance actually involves, why each part matters, and what the consequences of skipping it look like in practice.
What Does Website Maintenance Actually Include?
Website maintenance covers WordPress core, plugin, and theme updates (tested before applying), daily off-site backups, malware scanning, uptime monitoring, speed checks, and SSL certificate monitoring. These are not optional extras on a WordPress site - they are the difference between a site that remains secure and functional, and one that silently accumulates vulnerabilities until something goes wrong. A single hack cleanup typically costs R2,000 to R5,000, more than a year of professional maintenance. JWD’s maintenance service at R450 per hour covers the full checklist - you pay only for the time the work actually takes.
People hear “maintenance” and imagine someone refreshing the page every month to make sure it still looks right. The real work is less visible than that, but far more consequential.
WordPress core updates: WordPress releases updates regularly. Some are minor fixes, some are security patches, some are significant version updates that change how WordPress works under the hood. Each update is tested against your specific site setup before being applied - because applying a major update without testing is how sites break.
Plugin updates: The average WordPress site runs 15 to 25 plugins. Every plugin is maintained by a third party. Every plugin release notes section contains updates ranging from new features to critical security fixes. Keeping all plugins current, in the right order, while watching for conflicts, is an ongoing task that never ends.
Theme updates: Your Divi, Elementor, or other theme updates independently of WordPress core. Theme updates can sometimes change styling behaviour or break custom CSS. These need to be applied and checked visually.
Off-site backups: Daily backups of your WordPress files and database, stored off the server. Not “WordPress’s built-in backup” or “the hosting company’s server snapshot” - dedicated, downloadable backups you can restore from if needed.
Security scanning: Automated scanning for known malware signatures in your site files. If something is injected, you want to know immediately, not when Google flags your site.
Uptime monitoring: An external monitoring service that pings your site every few minutes and alerts your maintenance provider if the site goes down. The goal is for your maintenance provider to know about downtime before you do - and ideally before your customers notice.
Speed checks: Monitoring whether your site’s page load times drift upward over time. A plugin adding tracking scripts, a new image uploaded at original resolution, a backup plugin slowing down the database - these things accumulate and degrade performance without anyone noticing.
Why Can’t You Just “Set It and Forget It”?
The “set it and forget it” instinct makes sense for things that don’t change. But WordPress is not static software. The platform evolves. Plugins evolve. The hosting environment evolves. Security threats evolve.
The threat landscape for WordPress specifically is active. WordPress powers a significant portion of the web, which makes it the most targeted CMS. Automated bots scan the internet continuously, looking for:
- Sites running known vulnerable plugin versions
- Default login URLs and weak credentials
- Exposed configuration files
- Outdated PHP versions with known exploits
These bots are not targeting you specifically. They’re scanning millions of sites simultaneously. If your site has an unpatched vulnerability, it will be found and exploited - the question is only when.
The plugin conflict risk is equally real but less dramatic. A plugin that worked fine in version 3.2 may conflict with another plugin in version 3.3. A WordPress core update may change a function that a plugin relied on. Without someone checking the site after each update, these conflicts can result in broken layouts, broken contact forms, or broken checkouts - none of which are immediately obvious to the site owner.
What Are the Real Risks of Skipping Maintenance?
These aren’t hypothetical. They’re the conversations we have with clients who come to us after something has already gone wrong.
Hacked sites: The most common outcome of a neglected WordPress site. Hackers inject malicious code that redirects your visitors to scam sites, serves malware, or sends spam using your domain. Often the site owner has no idea for weeks or months. The cleanup is expensive (forensic scan, malware removal, reputation repair with Google) and could have been prevented.
Google blacklisting: When Google detects malware on a site, it shows a “Dangerous site” warning in Chrome and removes or demotes the site in search results. Recovering from a Google blacklist requires submitting a review request and waiting - during which your organic traffic is substantially gone.
Broken layouts and functionality: A plugin update gone wrong, applied without testing, can break your homepage layout, your contact form, your online store checkout, or your bookings system. If no one discovers this quickly, you lose business while visitors hit errors.
Slow performance and ranking drops: Unmaintained sites accumulate bloat. Old revisions pile up in the database. Caching configurations stop working correctly after updates. Images uploaded without compression. The site gets slower month by month, and because it’s gradual, no one notices until rankings and conversions have already dropped.
SSL certificate expiry: SSL certificates expire, usually annually. An expired SSL shows visitors a security warning in their browser. On a maintained site, certificate renewal is automated and monitored. On an ignored site, it expires and your visitors see “Your connection is not private” - and leave.
Hosting plan not renewed: Sounds obvious, but it happens. An email goes to a defunct address, the credit card expires, and the hosting lapses. The site goes down. Getting it back up after a lapse can involve data recovery or rebuilding from whatever backup exists (which, if the site was unmaintained, may be months old).
What Does JWD’s Maintenance Service Cover at R450 per Hour?
Our website maintenance service at R450 per hour covers the practical checklist:
- WordPress core, plugin, and theme updates (applied with pre-update backup and post-update check)
- Daily off-site backups stored externally
- Malware scanning
- Uptime monitoring with alerts
- Speed monitoring
- SSL certificate monitoring
- A monthly report so you can see what was done
This is not a “tick the box” service where we click update and walk away. It’s active oversight: checking that the site still looks and works correctly after every update cycle, catching issues before they become problems.
For clients using our maintenance service, we also handle the inevitable minor issues that come up - a plugin that needs a compatibility fix, a widget that shifted after an update, an image that needs re-uploading. You pay only for the time the work takes, so small fixes cost far less than a full hour.
How Does Maintenance Compare to the Cost of Not Doing It?
A hack cleanup for a WordPress site typically costs R2,000 to R5,000 or more, depending on the severity. That’s without accounting for the lost traffic, the lost customer trust, the potential POPIA implications if customer data was exposed, and the time spent.
A professionally rebuilt site after a severe infection with no clean backup available can easily cost as much as the original build.
Regular maintenance at R450 per hour - even just a few hours per quarter - costs far less than a single serious incident. Maintenance is insurance with the additional benefit of keeping your site performing well throughout the year.
For more detail on what maintenance involves over time, read our complete website maintenance guide.
Want your site kept fast, secure and up to date? See our website maintenance options or request a quote.
Frequently Asked Questions
Can I do my own WordPress maintenance instead of paying for a plan?
Yes, if you have the technical knowledge and the discipline to do it consistently. The problem most business owners face is not capability - it’s time. Maintenance needs to happen on a regular schedule, not when you remember or when something breaks. If you know WordPress, understand plugin conflicts, maintain off-site backups, and check your site after every update, DIY maintenance is viable. If any of those steps seem uncertain, it’s worth paying someone else to own it.
What happens to my backups if I stop the maintenance plan?
Your most recent backups from the active maintenance period remain as files - they don’t disappear. However, ongoing backup creation stops when the plan ends. At that point, your most recent clean backup ages by one day every day you’re without a plan. After a few months, a backup that’s several months old may not accurately reflect your current site - you’d lose recent content, product additions, or form submissions if you needed to restore from it. The recommendation is always to download and keep a local copy of your most recent backup when transitioning away from a maintenance plan.