Maintenance Plan and Onboarding Audit
We begin every engagement with a written audit of your current WordPress installation. We document your WordPress core version, PHP version, full plugin list with version and update status, active theme and child theme, hosting configuration, existing backup schedule, and any security issues we find on day one. The audit becomes the baseline for all future maintenance reports and gives you a complete record of your site's state at the point we took it over.
Staging Environment
We set up a staging environment on your hosting platform (WP Engine, Kinsta, or SiteGround UK) or provision one separately if your current host does not support it. All core, plugin, and theme updates are applied to staging first and tested for compatibility, visual breakage, and functionality before being applied to the live site. Updates are never applied to live without a passed staging test.
Core, Plugin, and Theme Updates
We apply WordPress core, plugin, and theme updates on a documented schedule. Minor and security updates are applied promptly. Major version updates are tested more thoroughly on staging before live deployment. We document every update applied, the version moved from and to, and any issues found during staging testing.
Security Monitoring
We configure a security scanner appropriate to your site (Wordfence, Sucuri, or equivalent) and monitor it actively. We check for malware, file integrity changes, known vulnerability matches against your plugin versions, login brute force attempts, and blacklist status. Security alerts are reviewed by a human, not just logged. If a genuine incident is detected, we notify you with a written summary and a recommended response plan within the same business day.
Uptime Monitoring
We configure uptime monitoring that checks your site every minute from multiple UK and European locations. If your site goes down, we receive an immediate alert. For clients on our standard and higher plans, we begin investigating without waiting for you to contact us. You receive a written incident report for any outage that lasts more than five minutes, covering when it started, what caused it, and when it was resolved.
Off-Site Backups
We configure automated daily backups stored off-site, separate from your hosting environment. Backups are retained for a minimum of 30 days. We verify backup integrity on a monthly basis and document the verification result in your monthly report. If a restore is required, we have a tested, documented process for executing it cleanly.
SSL Management
We monitor your SSL certificate expiry and renew it before it lapses. An expired SSL certificate produces browser security warnings that damage visitor trust and can cause search engines to flag your site. SSL management is included in every maintenance plan at no additional cost.
Spam and Bot Protection
We configure and maintain spam filtering for your contact forms and comment sections, and apply bot protection rules at the server or plugin level to reduce junk submissions and reduce server load from automated crawlers. Spam and bot activity is summarised in your monthly report.
Monthly Report
We deliver a written monthly report covering every update applied, security scan results, uptime statistics, backup verification status, SSL certificate status, spam and bot summary, and any support hours used from your bank that month. The report is formatted for a non-technical reader and includes a plain-language summary of anything that requires your attention or a decision.
Support Hours Bank
Every maintenance plan includes a bank of support hours each month (between 2 and 5 hours depending on your plan). Support hours cover content changes, small fixes, plugin investigations, and minor development work. Unused hours do not roll over, but you always know how many hours you have available and what has been used. There are no surprise invoices for routine requests that fall within your bank.