WEBSITE MAINTENANCE & SUPPORT

Keep the website you invested in secure, updated, and working

An unpatched WordPress site is not a maintenance problem. It is a liability. A plugin vulnerability exploited by an automated bot can expose customer data, trigger CCPA or GDPR notification obligations, and take the site offline without warning. Ignited Nepal provides ongoing maintenance: updates tested before they reach production, daily off-site backups, continuous monitoring, and a support retainer so there is always someone available when the site needs attention.

WordPress core, plugin, and theme updates tested on staging before production · Daily off-site backups with 30-day retention · Uptime monitoring with 99.9% SLA alerting · CCPA and GDPR breach risk reduced through active security monitoring
This is for you if

Maintenance is relevant to every WordPress site, but these three situations make it urgent.

The project was delivered, the agency relationship ended, and the site has been running without updates since the launch sprint. The WordPress dashboard has dozens of pending plugin updates. The development team that built the site is on other projects. No one has time to apply updates and no one wants to break a live revenue-generating site. In the meantime, every pending update is either a security patch or a compatibility fix that is not being applied.

Search Console flagged the site as dangerous, the hosting provider suspended the account, or a team member noticed the site was serving spam to organic search visitors. WordPress compromises are almost always caused by an unpatched plugin or theme vulnerability. For US businesses that collect personal data, a site compromise may constitute a data breach triggering notification obligations under CCPA (for California consumers) and potentially GDPR (for users in the EU), in addition to state-level breach notification laws. Post-cleanup monitoring is not optional for businesses in this situation.

The original developer is a contractor or a small agency that finished the project and has no retainer in place. There is no staging environment, no documented update process, and no one accountable for the site between projects. Every change request requires sourcing a developer, briefing them on the setup, and hoping they do not introduce new issues. A maintenance retainer replaces this pattern with a permanent, accountable support relationship.

What's broken

A site that looks fine on the surface can have serious structural problems underneath.

47 plugin updates pending, each one a potential conflict or security patch

WordPress plugin vulnerabilities are catalogued in the National Vulnerability Database and in plugin-specific changelogs. When a vulnerability is published, automated scanning tools begin probing for unpatched installations within hours. For US businesses running WooCommerce stores, membership platforms, or lead generation funnels, a plugin-based compromise can expose customer payment data, email addresses, and purchase history. Pending updates that sit unaddressed are an open invitation.

No off-site backup since the site launched

WP Engine, Kinsta, and Pagely provide excellent hosting-level backups, but those backups are stored within the same platform. A compromised site may corrupt or delete backup data on the same infrastructure. A genuinely independent off-site backup stored on a separate provider is a materially different safeguard. If the most recent clean backup pre-dates any customer data collection, a restore following a breach could raise additional compliance questions about what data was lost.

No uptime monitoring, so downtime is discovered by a client, not the business

Without an external monitor, the first person to know the site is down is often a customer, a prospect following up on an ad, or a sales rep who tried to pull up the site during a call. For US businesses running paid search campaigns, every hour of undetected downtime is wasted ad spend pointing to a non-functioning destination. An uptime monitor sends an alert within minutes so the team can act before the outage compounds.

SSL certificate expired and not renewed

An expired SSL certificate triggers a full-page browser warning before the visitor sees any content. Visitors who arrived from a paid ad, an email campaign, or an organic search result all encounter the same wall. The certificate has a predictable expiry date that is visible months in advance. Without a process for tracking and renewing it, expiries happen at businesses of every size.

What we engineer

The maintenance plan covers every layer of the site, from the server environment to the content.

WordPress Core, Plugin, and Theme Updates (Tested on Staging)

All updates are applied to a staging environment before reaching production. We run functional tests after each update pass: forms, checkout flows, integrations, and key landing pages. Conflicts are resolved on staging. Only a verified, tested version of the site is promoted to production. For US businesses on WP Engine, Kinsta, or Pagely, we work within the platform's staging tooling. For sites on other hosts, we establish a staging environment during onboarding.

Security Scanning and Malware Monitoring

Automated scans check the site's files and database for known malware signatures, unauthorised file modifications, and code injections. For US businesses subject to CCPA, GDPR, or state-level privacy laws, maintaining active security monitoring is a material component of reasonable security practices. Scan results are included in the monthly report, providing a documented record of the security posture.

Uptime Monitoring with 99.9% SLA Alerting

An external monitor checks the site from multiple US-region locations every minute. Alerts are sent immediately on outage or error response. Response time is tracked alongside availability. For businesses running paid search campaigns, the monitor ensures that downtime is not silently consuming ad budget. Uptime records are included in the monthly report.

Daily Off-Site Backups with 30-Day Retention

Full backups of the site's files and database are taken daily and stored on infrastructure independent of the hosting provider. Backups are retained for 30 days. Restorability is tested periodically. For a US business experiencing a breach or a ransomware event, the ability to restore from a clean, recent, independent backup is the difference between a recoverable incident and a full rebuild.

Performance Monitoring and PageSpeed Regression Alerts

A performance baseline is established during onboarding. Core Web Vitals and PageSpeed scores are tracked continuously. If a plugin update, a new media upload, or a configuration change causes a measurable performance regression, an alert is triggered. For US businesses where Google Ads Quality Score and organic search rankings are tied to page experience signals, undetected performance regressions have a direct cost.

SSL Certificate Renewal and Spam/Bot Protection

SSL certificates are tracked and renewed proactively before expiry. Firewall and bot protection rules are maintained to filter malicious traffic, reduce automated form spam, and limit server load from scanning bots that target known WordPress endpoints.

Monthly Maintenance Report and Support Hours Bank

A written report is delivered each month summarising all maintenance activity: updates applied, security scan results, uptime percentage, backup status, and performance metrics. A support hours bank (typically 2 to 5 hours per month) covers content edits, bug fixes, copy changes, and minor development requests, providing a standing resource for routine site changes without a new scope of work each time.

What changes

After the maintenance plan is in place, four things are different.

Before
After
Before WordPress plugin vulnerabilities are catalogued in the National Vulnerability Database and in plugin-specific changelogs. When a vulnerability is published, automated scanning tools begin probing for unpatched installations within hours. For US businesses running WooCommerce stores, membership platforms, or lead generation funnels, a plugin-based compromise can expose customer payment data, email addresses, and purchase history. Pending updates that sit unaddressed are an open invitation.
After Every plugin, theme, and WordPress core installation is current. Known CVEs are patched. The attack surface that automated bots probe for daily is significantly reduced. For US businesses holding personal data on California residents, EU users, or customers in states with active privacy legislation, this directly reduces the likelihood of a notifiable breach event.
Before WP Engine, Kinsta, and Pagely provide excellent hosting-level backups, but those backups are stored within the same platform. A compromised site may corrupt or delete backup data on the same infrastructure. A genuinely independent off-site backup stored on a separate provider is a materially different safeguard. If the most recent clean backup pre-dates any customer data collection, a restore following a breach could raise additional compliance questions about what data was lost.
After A clean, tested, recent off-site backup means that any incident is recoverable. A breach, a ransomware event, a botched plugin update, or a hosting failure can be resolved without losing months of content, customer data, or site configuration. Recovery is measured in hours. The alternative is measured in weeks, and is never complete.
Before Without an external monitor, the first person to know the site is down is often a customer, a prospect following up on an ad, or a sales rep who tried to pull up the site during a call. For US businesses running paid search campaigns, every hour of undetected downtime is wasted ad spend pointing to a non-functioning destination. An uptime monitor sends an alert within minutes so the team can act before the outage compounds.
After The first alert about an outage goes to the maintenance team. Paid ad campaigns are not sending traffic to an offline page. Prospective customers are not bouncing from a 503 error. The uptime record is documented so the business has visibility into site reliability over time.
Before An expired SSL certificate triggers a full-page browser warning before the visitor sees any content. Visitors who arrived from a paid ad, an email campaign, or an organic search result all encounter the same wall. The certificate has a predictable expiry date that is visible months in advance. Without a process for tracking and renewing it, expiries happen at businesses of every size.
After Routine content updates, bug reports, and minor development requests go to a support contact who knows the site. They are handled within days, within the existing retainer, without a new project proposal.
How it works

Onboarding to a maintenance plan takes less than a week. The monthly cycle runs without requiring involvement from the site owner.

  1. 01

    Onboarding and Access Setup

    We collect WordPress admin, hosting, and DNS credentials. For sites on WP Engine, Kinsta, or Pagely, we set up access within the platform's user management system. We document the current plugin inventory, theme version, and WordPress core version. We establish a staging environment, configure the uptime monitor, connect the backup system, and activate the security scanner.

  2. 02

    Baseline Update Pass

    We run a full update pass on staging to bring all plugins, themes, and WordPress core to their current versions. Functional tests are run. Conflicts are resolved. The live site is updated only after staging is clean and tested. The baseline pass establishes the starting point for the monthly maintenance cycle. Any pre-existing security issues identified during the baseline are flagged separately.

  3. 03

    Ongoing Monthly Maintenance Cycle

    Each month: update pass on staging, functional testing, production promotion, security scan review, backup verification, performance check, and monthly report delivery. The site owner receives the report. Nothing is required of them unless support requests are pending.

  4. 04

    Support Requests Handled Within the Retainer

    Content edits and bug fixes are submitted by email or a shared project management tool. Requests within the monthly support hours bank are handled without additional billing. If a request requires more time than the bank covers, a quote is provided before work begins. Urgent issues are escalated and addressed within the same US business day across Eastern, Central, Mountain, and Pacific time zones.

Common questions

FAQ

Can a WordPress site compromise trigger CCPA or GDPR notification requirements?

A WordPress compromise that results in unauthorised access to personal information about California residents may constitute a data breach under the California Consumer Privacy Act, requiring notification to affected individuals. If the site collects data from EU residents, the General Data Protection Regulation imposes separate notification obligations, including reporting to a supervisory authority within 72 hours of becoming aware of the breach. Many US states also have independent breach notification statutes. Keeping WordPress patched and actively monitored is the most direct technical control available to reduce this risk.

Does maintenance cover WooCommerce stores and subscription plugins?

WooCommerce and its extensions are included in the update cycle. WooCommerce updates are handled with particular care because they affect checkout flows, payment gateway integrations, and subscription billing logic. Every WooCommerce update is tested end-to-end on staging before production, including a test transaction where applicable.

My site is already on WP Engine or Kinsta. Do I still need a maintenance plan?

WP Engine and Kinsta manage server infrastructure, provide platform-level backups, and offer excellent hosting-level security. They do not update WordPress plugins or themes on your behalf, do not maintain a support retainer for content changes, and do not deliver a monthly report on your application-layer security posture. The maintenance plan covers the WordPress application layer that managed hosting platforms leave to the site owner.

What is the response time for urgent issues?

Urgent issues, defined as site outages, confirmed malware, or broken checkout flows, are escalated immediately upon detection. Response is within four business hours during US business hours, with same-day resolution as the target for critical incidents. The on-call response protocol is defined during onboarding.

How do support hours work across months with heavy traffic or seasonal campaigns?

Additional support hours can be purchased in advance of high-activity periods such as product launches or seasonal campaigns. For businesses with consistently higher support volume, a higher-tier plan with more monthly hours is a better fit than repeatedly purchasing add-ons. Unused hours in low-activity months do not roll over but reflect the intended baseline of the plan.

Our team

The people behind the work

Not a black box. Real specialists you can call, with their names on the work.

Niraj Raut

Niraj Raut

Founder — Ecommerce SEO
Keshab Joshi

Keshab Joshi

PPC Expert
Hawrry Bhattarai

Hawrry Bhattarai

Google Ads Expert
Arogya Rijal

Arogya Rijal

SaaS SEO Expert
Start here

Start with a site audit, not a commitment

Send us access to your WordPress admin and we will audit the current state of the site: pending updates, backup status, security monitoring configuration, SSL expiry, uptime history, and performance baseline. The audit is completed within 24 hours and forms the basis of every maintenance proposal we deliver. There is no obligation to proceed.

Ignited Nepal is a Growth Engineering Company. We maintain WordPress sites for US businesses that need an accountable technical partner, not a support ticket queue.