WEBSITE MAINTENANCE & SUPPORT

Keep the website you invested in secure, updated, and working

A WordPress site left unmaintained is not a static risk. It is an active one. Outdated plugins are the most common entry point for site compromise, and a compromised site that exposes customer data triggers mandatory reporting obligations under the Australian Privacy Act 1988. Ignited Nepal's maintenance service keeps your site patched, backed up, monitored, and supported every month.

WordPress core, plugin, and theme updates tested on staging before production · Daily off-site backups with 30-day retention · Uptime monitoring with 99.9% SLA alerting · Privacy Act 1988 breach risk reduced through ongoing security monitoring
This is for you if

Maintenance is relevant to every WordPress site, but these three situations make it urgent.

You launched the site, the developer moved on, and updates have been sitting in the WordPress dashboard for months. No one on the team wants to touch them for fear of breaking something. Every pending plugin update is a known vulnerability. Australian businesses on WP Engine, Kinsta, or SiteGround often assume the hosting provider is handling this layer. It is not. Managed hosting handles server infrastructure. The WordPress application, plugins, and theme remain the site owner's responsibility.

The site was flagged by Google Safe Browsing, or the hosting provider suspended the account. Customer-facing pages were replaced with spam content. These incidents are almost always caused by an unpatched plugin vulnerability. For Australian businesses, the consequences extend beyond the technical cleanup: if the breach exposed personal information about customers, the Australian Privacy Act 1988 and the Notifiable Data Breaches scheme may require formal notification to the Office of the Australian Information Commissioner and to affected individuals. A clean site and a maintenance plan reduce the likelihood of this scenario repeating.

The agency or freelancer who built the site in Sydney, Melbourne, or Brisbane delivered the project and the relationship ended. There is no one to call when a plugin breaks a contact form, when the SSL certificate lapses, or when a client reports that the site is down. This is the situation the maintenance retainer is designed for.

What's broken

A site that looks fine on the surface can have serious structural problems underneath.

47 plugin updates pending, each one a potential conflict or security patch

WordPress plugins are the most scanned attack surface on the internet. When a vulnerability is published in a plugin's changelog, automated bots begin scanning for unpatched installations within hours. A long list of pending plugin updates is not a low-priority housekeeping task. It is an active security exposure. Updates also need to be tested: a plugin conflict can break a WooCommerce checkout, a booking form, or a member portal without any warning.

No off-site backup since the site launched

WP Engine, Kinsta, and SiteGround all include hosting-level backups, but those backups are stored within the same platform ecosystem. A compromised site, a billing dispute, or a misconfigured restore can affect access to both the live site and the backup simultaneously. A truly independent off-site backup stored on a separate provider is a different risk category. If the most recent clean backup is the one taken at launch, a restore returns the site to the day it went live.

No uptime monitoring, so downtime is discovered by a client, not the business

Without an independent external monitor, the business finds out about an outage the same way a prospect does: by trying to visit the site. A Melbourne-based e-commerce store with no uptime monitoring could be offline for four hours before the first internal person notices. Uptime monitoring sends an alert within minutes so the team can act before revenue is affected.

SSL certificate expired and not renewed

An expired SSL certificate throws a browser-level security warning before a visitor even loads the homepage. Most visitors leave immediately. Google Search Console will flag the issue. The certificate has a fixed expiry date that is visible months in advance, but without a process for tracking and renewing it, expiries happen regularly at businesses without a maintenance arrangement.

What we engineer

The maintenance plan covers every layer of the site, from the server environment to the content.

WordPress Core, Plugin, and Theme Updates (Tested on Staging)

Every update is applied to a staging environment that mirrors the live site before anything touches production. We run functional checks after each update pass: key pages, forms, checkout flows, and integrations. If an update causes a conflict, it is caught and resolved on staging. Only a clean, tested version of the site is promoted to production. This process applies to all updates including WordPress core releases, which carry the highest potential for theme or plugin compatibility issues.

Security Scanning and Malware Monitoring

Automated file and database scans check for known malware signatures, unauthorised file changes, and injected code. If suspicious activity is detected, an alert is raised immediately. For Australian businesses, maintaining an active security monitoring posture is relevant not just to site integrity but to demonstrating reasonable steps to protect personal information under the Privacy Act. Scan results are included in the monthly report.

Uptime Monitoring with 99.9% SLA Alerting

An external monitor checks the site from multiple locations every minute. Alerts are sent immediately on outage or error response. Response time is tracked alongside availability, so slow sites are identified before they fail completely. For e-commerce and service businesses in Sydney, Melbourne, and Brisbane, downtime during business hours has a direct revenue cost. The monitor ensures the team knows first.

Daily Off-Site Backups with 30-Day Retention

Full backups of the site's files and database are taken daily and stored on infrastructure independent of the hosting provider. Backups are retained for 30 days, enabling point-in-time restores. We test backup restorability periodically, not just backup creation. A backup that cannot be restored is not a backup.

Performance Monitoring and PageSpeed Regression Alerts

Core Web Vitals performance is tracked against an established baseline for the site. If an update, a new image upload, or a theme change causes a measurable regression in PageSpeed scores, an alert is triggered. Performance matters for both user experience and Google Search rankings, and silent regressions after routine maintenance are common without active monitoring.

SSL Certificate Renewal and Spam/Bot Protection

SSL certificates are tracked and renewed proactively before expiry. Firewall and bot protection rules are maintained to filter malicious traffic, reduce server load from automated scanners, and limit spam form submissions that pollute CRM and email systems.

Monthly Maintenance Report and Support Hours Bank

A written report is delivered each month covering updates applied, security scan results, uptime percentage, backup status, and performance metrics. A support hours bank (typically 2 to 5 hours per month) is available for content edits, bug fixes, and minor development requests, so routine changes are handled without a new project proposal each time.

What changes

After the maintenance plan is in place, four things are different.

Before
After
Before WordPress plugins are the most scanned attack surface on the internet. When a vulnerability is published in a plugin's changelog, automated bots begin scanning for unpatched installations within hours. A long list of pending plugin updates is not a low-priority housekeeping task. It is an active security exposure. Updates also need to be tested: a plugin conflict can break a WooCommerce checkout, a booking form, or a member portal without any warning.
After Every plugin, theme, and core installation is current. Known CVEs are patched. The attack surface that bots scan for daily is closed. For Australian businesses holding personal customer data, this directly reduces the likelihood of a notifiable data breach under the Privacy Act 1988.
Before WP Engine, Kinsta, and SiteGround all include hosting-level backups, but those backups are stored within the same platform ecosystem. A compromised site, a billing dispute, or a misconfigured restore can affect access to both the live site and the backup simultaneously. A truly independent off-site backup stored on a separate provider is a different risk category. If the most recent clean backup is the one taken at launch, a restore returns the site to the day it went live.
After A tested, recent, off-site backup means that a compromised site, a botched update, or a hosting incident is recoverable within hours. Without that backup, recovery requires manual reconstruction and may never be fully complete.
Before Without an independent external monitor, the business finds out about an outage the same way a prospect does: by trying to visit the site. A Melbourne-based e-commerce store with no uptime monitoring could be offline for four hours before the first internal person notices. Uptime monitoring sends an alert within minutes so the team can act before revenue is affected.
After The first alert about an outage goes to the maintenance team, not to a customer trying to complete a purchase. The uptime record is documented each month so the business can track reliability over time.
Before An expired SSL certificate throws a browser-level security warning before a visitor even loads the homepage. Most visitors leave immediately. Google Search Console will flag the issue. The certificate has a fixed expiry date that is visible months in advance, but without a process for tracking and renewing it, expiries happen regularly at businesses without a maintenance arrangement.
After Instead of raising a new project with an agency every time a page needs a content update or a bug appears, the support hours bank covers routine requests. Changes are handled within days, not weeks.
How it works

Onboarding to a maintenance plan takes less than a week. The monthly cycle runs without requiring involvement from the site owner.

  1. 01

    Onboarding and Access Setup

    We collect WordPress admin, hosting, and DNS credentials. We review the existing plugin list, theme version, and WordPress core version. We establish a staging environment (or connect to an existing one on WP Engine, Kinsta, or SiteGround), and we configure the uptime monitor, off-site backup system, and security scanner.

  2. 02

    Baseline Update Pass

    Before the ongoing cycle begins, we run a full update pass on staging to bring all plugins, themes, and core to their current versions. We run functional checks, resolve any conflicts, and promote to production only after the staging site is clean. This baseline pass is included in the onboarding. From this point, the site is current and the monthly cycle begins.

  3. 03

    Ongoing Monthly Maintenance Cycle

    Each month: update pass on staging, functional testing, promotion to production, security scan review, backup verification, performance check, and monthly report. The site owner receives the report. No input is required from their side unless support requests are in the queue.

  4. 04

    Support Requests Handled Within the Retainer

    Content edits and bug fixes are submitted by email. Requests within the monthly support hours bank are handled without additional billing. If a request exceeds the bank, a quote is provided before work begins. Urgent issues are escalated and addressed within the same Australian business day.

Common questions

FAQ

Does maintenance cover WooCommerce and its extensions?

WooCommerce and its official extensions are included in the update cycle. WooCommerce updates are handled with particular care because they frequently affect checkout flows, payment gateway integrations, and order management. Each WooCommerce update is tested end-to-end on staging before being promoted to the live store.

Does a compromised WordPress site trigger reporting obligations in Australia?

A WordPress site compromise that exposes personal information about Australian customers is likely to constitute an eligible data breach under the Privacy Act 1988 and the Notifiable Data Breaches scheme. The business would be required to notify the Office of the Australian Information Commissioner and affected individuals. Keeping WordPress patched and actively monitored is the most direct way to reduce this risk.

My site is on WP Engine or Kinsta. Do I still need a maintenance plan?

WP Engine and Kinsta are excellent hosting platforms that handle server-level infrastructure and provide platform-level backups. They do not, however, update WordPress plugins or themes on your behalf, do not provide a support retainer for content changes, and do not send you a monthly report on your site's security posture. The maintenance plan handles the application layer that managed hosting leaves to the site owner.

What happens if an update breaks something on the live site?

We restore from the most recent off-site backup immediately. Because every update is tested on staging before production, this is an uncommon outcome, but it is covered. The incident is documented in the monthly report.

Can you take over maintenance for a site built by another agency?

We can take over maintenance for any WordPress site regardless of who built it. During onboarding we review the existing setup, document what is in place, and establish clean access credentials. If documentation from the previous agency is incomplete, we work from what is accessible and identify any gaps.

Our team

The people behind the work

Not a black box. Real specialists you can call, with their names on the work.

Niraj Raut

Niraj Raut

Founder — Ecommerce SEO
Keshab Joshi

Keshab Joshi

PPC Expert
Hawrry Bhattarai

Hawrry Bhattarai

Google Ads Expert
Arogya Rijal

Arogya Rijal

SaaS SEO Expert
Start here

Start with a site audit, not a commitment

Send us access to your WordPress admin and we will audit the current state of the site: pending updates, backup status, security monitoring, SSL expiry, and uptime record. The audit takes less than 24 hours and is the foundation of every maintenance proposal we produce. There is no obligation to proceed.

Ignited Nepal is a Growth Engineering Company working with businesses in Sydney, Melbourne, Brisbane, and across Australia. We maintain WordPress sites for companies that cannot afford for their website to become a liability.