WEBSITE MAINTENANCE & SUPPORT

Keep the website you invested in secure, updated, and working

Most WordPress sites are quietly falling apart. Plugins go months without updates. Backups have never been tested. Uptime is a guess. Ignited Nepal runs ongoing maintenance so that a WordPress security issue, a plugin conflict, or a server outage in the middle of the night does not become a business crisis.

WordPress core, plugin, and theme updates tested on staging before production · Daily off-site backups with 30-day retention · Uptime monitoring with 99.9% SLA alerting · Monthly maintenance report delivered to your inbox
This is for you if

Maintenance is relevant to every WordPress site, but these three situations make it urgent.

You launched the site, then the team moved on to the next priority. The WordPress dashboard shows a column of pending updates but no one has touched them. Every unpatched plugin is a known vulnerability that automated bots scan for daily. In Nepal, where many sites sit on shared hosting with no security layer, an outdated plugin is often all an attacker needs.

A client searched your business name and found a spam page indexed on your domain. Or the hosting provider suspended the account for sending spam email. A malware infection on a WordPress site is almost always the result of an unpatched vulnerability. After a cleanup, the underlying issue needs to be closed permanently, and ongoing monitoring needs to be in place so it does not happen again.

The developer who built the site did good work and then moved to another project. There is no retainer, no documentation, no one to call when something breaks. Updates have not been applied because no one wants to risk breaking the site. Support requests go unanswered for weeks. This is the most common situation for growing Nepali businesses, and it is an easy problem to solve with the right maintenance partner in place.

What's broken

A site that looks fine on the surface can have serious structural problems underneath.

47 plugin updates pending, each one a potential conflict or security patch

WordPress plugins are the most common attack surface on the internet. Plugin authors release updates to patch known vulnerabilities, and within hours of a vulnerability being published, bots begin scanning for unpatched sites. A dashboard full of pending updates is not a cosmetic issue. It is an active risk. Updates also need to be tested before they are applied to production because a plugin conflict can break a page, a form, or an entire checkout flow without warning.

No off-site backup since the site launched

Hosting providers are not backup providers. A server crash, a ransomware attack, or an accidental file deletion can wipe a site and any backup stored on the same server. In Nepal, where power instability and shared hosting environments are common, the risk of data loss without an independent backup system is real. If the last backup is the one the developer made before handing the project over, a restore would take the site back to launch day.

No uptime monitoring, so downtime is discovered by a client, not the business

Without an external monitor checking the site every minute, the business learns about downtime the same way a prospective client does: by trying to visit the site and finding it unreachable. Nepal's power infrastructure and the prevalence of budget shared hosting mean unplanned downtime is not rare. An uptime monitor sends an alert within minutes of an outage so the problem can be addressed before it damages trust.

SSL certificate expired and not renewed

An expired SSL certificate throws a security warning in the browser before a visitor even sees the homepage. Most users will leave immediately. Search engines treat SSL as a ranking signal. The certificate expiry is a predictable, calendar-driven event that should never be allowed to lapse, but without someone responsible for watching it, it routinely does.

What we engineer

The maintenance plan covers every layer of the site, from the server environment to the content.

WordPress Core, Plugin, and Theme Updates (Tested on Staging)

Every update, whether to WordPress core, an installed plugin, or the active theme, is applied first to a staging copy of the site. The staging environment mirrors the live site. We run functional checks after each update pass before promoting changes to production. If an update causes a conflict, it is caught and resolved before visitors ever see it.

Security Scanning and Malware Monitoring

Automated scans check the site's files and database for known malware signatures, unauthorised file modifications, and injected code. Alerts are triggered immediately if suspicious changes are detected. The scan results feed into the monthly report so the site owner has a complete record of security activity.

Uptime Monitoring with 99.9% SLA Alerting

An external monitor checks the site from multiple locations at one-minute intervals. If the site goes offline or returns an error response, an alert is sent immediately. The monitor tracks response time as well as availability, so performance degradation is visible before it becomes a full outage. This is particularly important for sites hosted in Nepal or on shared infrastructure where power and network reliability can vary.

Daily Off-Site Backups with 30-Day Retention

A full backup of the site's files and database is taken daily and stored on infrastructure separate from the hosting server. Backups are retained for 30 days, giving the ability to restore to any point within the past month. Backups are tested periodically to confirm they are restorable and complete, not just present.

Performance Monitoring and PageSpeed Regression Alerts

A plugin update, a new image, or a change to the theme can silently degrade site speed. Performance is monitored continuously. If a PageSpeed score drops below the established baseline, an alert is triggered. Speed matters both for user experience and for search rankings, and regressions are caught before they compound.

SSL Certificate Renewal and Spam/Bot Protection

SSL certificates are tracked and renewed before they expire. Firewall rules and bot protection are maintained to block known malicious traffic, reduce server load from automated scanners, and keep spam form submissions at a manageable level.

Monthly Maintenance Report and Support Hours Bank

A written report is delivered each month summarising updates applied, security scan results, uptime percentage, backup status, and performance trends. In addition, a bank of support hours (typically 2 to 5 hours per month) covers content edits, bug fixes, copy updates, and minor development requests, so there is always someone available for routine changes without a new project proposal each time.

What changes

After the maintenance plan is in place, four things are different.

Before
After
Before WordPress plugins are the most common attack surface on the internet. Plugin authors release updates to patch known vulnerabilities, and within hours of a vulnerability being published, bots begin scanning for unpatched sites. A dashboard full of pending updates is not a cosmetic issue. It is an active risk. Updates also need to be tested before they are applied to production because a plugin conflict can break a page, a form, or an entire checkout flow without warning.
After Every plugin, theme, and core installation is current. Known CVEs are patched. The attack surface that bots target daily is closed. The site is not guaranteed to be unhackable, but it is no longer low-hanging fruit.
Before Hosting providers are not backup providers. A server crash, a ransomware attack, or an accidental file deletion can wipe a site and any backup stored on the same server. In Nepal, where power instability and shared hosting environments are common, the risk of data loss without an independent backup system is real. If the last backup is the one the developer made before handing the project over, a restore would take the site back to launch day.
After When something goes wrong, whether it is a botched update, a server failure, or a security incident, there is a clean, tested, recent backup ready to restore from. Recovery is measured in hours. The alternative, a manual rebuild from screenshots and memory, takes weeks and is never complete.
Before Without an external monitor checking the site every minute, the business learns about downtime the same way a prospective client does: by trying to visit the site and finding it unreachable. Nepal's power infrastructure and the prevalence of budget shared hosting mean unplanned downtime is not rare. An uptime monitor sends an alert within minutes of an outage so the problem can be addressed before it damages trust.
After The first alert about an outage goes to the maintenance team, not to a prospective client trying to visit the site. Problems are addressed before they affect business, and the uptime record is documented in the monthly report.
Before An expired SSL certificate throws a security warning in the browser before a visitor even sees the homepage. Most users will leave immediately. Search engines treat SSL as a ranking signal. The certificate expiry is a predictable, calendar-driven event that should never be allowed to lapse, but without someone responsible for watching it, it routinely does.
After Instead of chasing a developer who has moved on or filing a new project request every time a page needs updating, there is a support hours bank and a direct contact. Routine changes are handled promptly within the existing arrangement.
How it works

Onboarding to a maintenance plan takes less than a week. The monthly cycle runs without requiring involvement from the site owner.

  1. 01

    Onboarding and Access Setup

    We collect access credentials for the WordPress admin, the hosting account, and any DNS or domain registrar accounts. We document the current plugin list, theme, and WordPress version. We establish a staging environment if one does not already exist, and we configure the uptime monitor, backup system, and security scanner.

  2. 02

    Baseline Update Pass

    Before the ongoing cycle begins, we run a full update pass to bring everything current. This is done on staging first. Any conflicts identified are resolved. Once the staging site passes functional testing, the updates are applied to production. The site enters the maintenance cycle from a clean, fully patched baseline.

  3. 03

    Ongoing Monthly Maintenance Cycle

    Each month we run the update cycle (staging, test, promote to production), review security scan results, verify backup integrity, check performance metrics, and compile the monthly report. Routine tasks run in the background. The site owner receives the report and nothing else is required of them unless they have support requests.

  4. 04

    Support Requests Handled Within the Retainer

    Content edits, bug fixes, and minor development requests come in by email. Requests within the monthly support hours bank are handled without additional billing. If a request requires more time than the bank covers, a quote is provided before work begins. Anything urgent is escalated and addressed within the same business day.

Common questions

FAQ

What if my site was built by a developer who no longer works with us?

We can take over maintenance for any WordPress site regardless of who built it. We review the existing setup during onboarding, document what is in place, and establish clean access before the previous developer's access is revoked. If the handover documentation is incomplete or missing entirely, we work from what we can access and flag anything that requires clarification.

Do you update plugins even if the site is on a page builder like Elementor or WPBakery?

Page builder plugins require careful handling because updates frequently cause visual or functional regressions. We update page builder plugins on staging and run a page-level review before promoting to production. If a page builder update breaks a layout, we resolve it before the live site is touched.

What happens if an update breaks something on the live site?

We restore from the most recent backup immediately. Because updates are tested on staging first, this scenario is rare, but it is covered. The monthly report will document what happened and what was done to resolve it.

How many support hours are included each month?

The standard plan includes 2 to 5 hours of support per month depending on the tier selected. Support hours cover content edits, minor bug fixes, copy changes, image swaps, and small development tasks. Hours do not roll over but unused hours in a given month reflect a lighter request load, which is the intended baseline.

Is maintenance necessary if my site is on managed WordPress hosting?

Managed WordPress hosting (such as premium shared hosting common in Nepal) handles server-level patching and infrastructure, but it does not update WordPress plugins or themes, does not provide off-site application-layer backups by default, and does not include a support retainer for content changes. The WordPress application layer remains the site owner's responsibility regardless of hosting tier.

Our team

The people behind the work

Not a black box. Real specialists you can call, with their names on the work.

Niraj Raut

Niraj Raut

Founder — Ecommerce SEO
Keshab Joshi

Keshab Joshi

PPC Expert
Hawrry Bhattarai

Hawrry Bhattarai

Google Ads Expert
Arogya Rijal

Arogya Rijal

SaaS SEO Expert
Start here

Start with a site audit, not a commitment

Send us access to your WordPress admin and we will tell you exactly what the current state of your site is: how many updates are pending, when the last backup was taken, whether security monitoring is active, and what the uptime record looks like. The audit is the first step in any maintenance proposal. There is no obligation to proceed.

Ignited Nepal is a Growth Engineering Company based in Kathmandu. We maintain WordPress sites for Nepali businesses that cannot afford to lose their website.