What are WordPress maintenance services, and does a UK business need them?
WordPress maintenance services are the regular technical upkeep that keeps a WordPress site secure, working and restorable: updates, backups, monitoring, security checks and small fixes. A UK business needs them once the site brings in enquiries, bookings or sales, because a broken or hacked site then costs money every hour it stays down.
WordPress itself is free and open source, but it is also a moving target. Core releases arrive through the year, each plugin has its own release schedule, and PHP versions on your hosting reach end of life. Every one of those changes can interact with the others. Maintenance is the discipline of absorbing that change without your visitors noticing.
You can do it yourself. Plenty of owners do, especially on small sites with few plugins. The trouble is that the tasks are dull until the day they are urgent, and by then it is too late to discover the backups were never set up or the admin email goes to someone who left three years ago.
A care plan moves that responsibility to someone whose job it is. With us it starts at US$120/mo a month, and the work is done during our morning in India, which is before the UK office day begins.
What should a monthly WordPress care plan cover?
A monthly WordPress care plan should cover six areas: updates, backups, security, monitoring, performance and reporting. If a quote does not say how each one is handled, ask, because “maintenance” means very different things to different providers.
- Updates: WordPress core, every plugin, the theme and translations, tested before going live.
- Backups: daily copies of files and database stored off the web server, with a stated retention period.
- Restore tests: proof, at least quarterly, that a backup actually restores.
- Security: malware scanning, login protection, removal of unused admin users and plugins, file-change alerts.
- Monitoring: uptime, SSL certificate expiry, domain renewal reminders and contact form delivery.
- Performance: a monthly look at page speed and Core Web Vitals after updates.
- Reporting: a short note of what was updated, what failed, what was fixed and anything you should decide.
Content editing is sometimes included as a small monthly allowance. Treat it as a bonus rather than the core of the plan; the value of maintenance is in the tasks above.
Looking at the budget side? The website maintenance cost page compares care plans with ad-hoc fixes.
Why plugin and core updates should be tested on staging first
Updates should be tested on a staging copy first because a plugin update that works on thousands of other sites can still break yours, and finding out on staging costs minutes while finding out on live costs customers.
Since WordPress 5.5, administrators can switch on automatic updates plugin by plugin and theme by theme, and the WordPress.org documentation on auto-updates notes that they run twice a day by default and advises having backups so you can roll back. That is useful for small sites with a handful of well-maintained plugins. It is risky for a site with a booking plugin, a page builder, a membership system and custom code, because nobody checks the result before your visitors do.
Our routine is plain. We refresh staging from live, apply all pending updates there, and then check the pages that matter: home, key service pages, forms, checkout or bookings, logged-in areas, and anything with custom code. We look at the PHP error log too, since some breakages are silent.
If staging passes, the same updates go to live early in the UK morning, with a fresh backup taken just before. If something fails, the update is held back on live and we either fix the conflict, wait for the plugin author’s patch, or tell you what the options are.
Daily off-site backups: what “backed up” should really mean
A WordPress site is properly backed up only when a recent copy of both the files and the database is stored somewhere other than the web server, and someone has tested that it restores. Anything less is a hope rather than a backup.
Many owners believe their host backs them up, and many hosts do. But a backup kept on the same server, or with the same provider, can disappear along with the site if the account is suspended, the server fails or an attacker gains access to the control panel. An off-site copy in separate cloud storage, in an account you own, removes that single point of failure.
Frequency matters too. A brochure site that changes once a month can live with daily backups. A shop or booking site that takes orders all day needs the database backed up more often, because restoring yesterday’s copy loses today’s orders. We agree the frequency and retention with you in the quote and write it down.
The restore drill is the part most maintenance plans skip. Every quarter we take a backup, restore it to a staging site, and check that pages load, logins work and recent content is there. If a drill fails, we find out on a quiet Tuesday rather than during an emergency.
How can a team in India maintain a UK WordPress site overnight?
A team in India maintains a UK site overnight simply by working its normal day: India is four and a half hours ahead of the UK in summer and five and a half in winter, so our morning in India happens while most of the UK is asleep. Updates, drills and fixes reported the previous evening can be dealt with before your office opens.
That rhythm suits maintenance well. The best time to update a live site is when it has the fewest visitors, which for a UK audience is the early hours. For a UK-based maintainer that means working unsociable hours; for us it is mid-morning with a cup of tea.
Here is how a typical cycle looks. You notice something odd on the site at 6pm and send a WhatsApp message with a screenshot. We read it that evening or first thing in our morning, investigate on staging, apply a fix, and send you a note. You check it with your morning coffee.
We are honest about the limits. There are three of us, not a 24-hour operations centre. We read WhatsApp seven days a week, but we do not promise a response time unless it is written into your quote, and anything that needs a call is best scheduled for the overlap between your late morning and our afternoon.
Malware clean-up and hacked WordPress site recovery
If your WordPress site has been hacked, the goal is not just to delete the visible malware but to find how the attacker got in, remove every backdoor they left, and close the hole so it does not happen again next week. A clean-up that skips the last two steps is usually followed by reinfection.
The signs vary. Visitors on phones get redirected to scam pages while you see nothing on desktop. Google shows pages of spam product listings under your domain. Your host suspends the account for sending spam. A security plugin reports modified core files. Or a new admin user appears that nobody created.
Our recovery sequence: take a forensic copy of the site as found; put up a holding page if visitors are at risk; compare core files against official copies; inspect plugins, themes and uploads for injected code; check the database for rogue admin users and injected scripts; rotate every password, secret key and API key; update or replace the vulnerable component; and then restore clean pages.
After the site is clean, we request a review in Google Search Console if Google flagged it, submit removals for spam URLs, and tell you in writing what we found and when. Recovery on a site that is not on a plan is quoted as a one-off job, and those written notes become important for the next section.
UK GDPR and the 72-hour duty to report a breach to the ICO
Under UK GDPR, if a personal data breach is likely to put people’s rights and freedoms at risk, the organisation responsible must report it to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. For a website owner, that clock can start the moment a hack involving customer data is discovered.
The ICO’s guide to personal data breaches says a report should describe the nature of the breach, including roughly how many people and records are affected, the likely consequences, and the measures taken or planned. It also says every breach must be documented, including its facts, effects and remedial action, whether or not it is reported, and that people must be told directly when the risk to them is high.
A breach is not only theft. The same guidance treats loss of availability as a breach where it has significant effects, so ransomware or a deleted database can count.
We are not your lawyer and do not decide whether a report is needed; that judgement belongs to you and, if you have one, your data protection adviser. What maintenance can do is make the decision possible within 72 hours, by keeping the records that answer the ICO’s questions. The next section explains which ones.
The logs that make breach reporting possible
The logs that make breach reporting possible are the ones that tell you when an attacker got in, what they touched and whose data sat in the areas they reached. Without them, the honest answer to the ICO’s first questions is “we don’t know”, which helps nobody.
On a WordPress site we keep or enable the following, depending on your hosting:
- Activity log: who logged in, from where, and what they changed: posts, users, plugins, settings.
- Login history: failed and successful logins, so a brute-force run or a stolen password shows up.
- File-change alerts: which files changed and when, which dates the initial compromise.
- Server access and error logs: kept by your host; we note how long they are retained.
- Data map: a short list of where personal data lives on the site: form entries, orders, member profiles, newsletter lists.
- Change notes: our own record of every update and fix, so normal changes can be told apart from malicious ones.
Data minimisation helps too. Contact form plugins often store every submission forever in the database. If those messages already reach your inbox, we can switch storage off or set automatic deletion, which means less data at risk if the worst happens.
Logs themselves can contain personal data, so we keep them only as long as your quote specifies and restrict who can read them.
WordPress security hardening that belongs in a UK care plan
Security hardening in a care plan means reducing the ways in: fewer plugins, fewer admin users, stronger logins and up-to-date software. Most WordPress compromises start with an outdated plugin or a reused password, not an exotic attack.
We start by removing what is not used. Inactive plugins and themes still sit on the server and can still be exploited, so they go. Admin accounts are reviewed each quarter and anyone who no longer needs access is downgraded or removed. Two-factor authentication is switched on for every administrator, and login attempts are rate-limited.
WordPress’s own Site Health screen, under Tools, flags some of the basics: an outdated PHP version, background updates that are not working, and debug settings that expose errors to visitors. We check it monthly alongside our own scans. PHP version matters for security as well as speed; WordPress.org currently recommends PHP 8.3 or greater.
Beyond that: file editing from the dashboard disabled, sensible file permissions, HTTPS everywhere, security headers, and a web application firewall where your hosting offers one. None of this makes a site unhackable, and nobody honest will claim it does. It makes a successful attack much less likely and much easier to spot.
How to choose WordPress maintenance services in the UK
Choose WordPress maintenance services in the UK by asking how the work is done, not only what is on the list. Every provider says “updates and backups”; the useful differences are in staging, restore testing, records and who you actually talk to.
Ask these five questions of any provider, including us. Do you test updates on staging before live? Where are backups stored, and when did you last restore one? What happens if my site is hacked: is clean-up included, and what will you tell me in writing? Who has admin access, and do you use your own named accounts? What is in the monthly report?
Then look at the contract. You want the price, what it includes, how extra work is quoted, and how to leave. Your hosting and domain should stay in your name. A plan that requires moving your site to the provider’s own hosting makes leaving harder; that may be fine, but go in with open eyes.
For a wider comparison of freelancers and agencies across all kinds of web work, read web design agency vs freelancer. For our own terms, see the terms page.
Red flags in a WordPress maintenance contract
The biggest red flag in a maintenance contract is vagueness: a monthly fee for “maintenance” with no description of how updates are tested, where backups go or what happens after a hack. Vague plans tend to cover the easy tasks and exclude the difficult ones.
- Updates run automatically on live with nobody checking afterwards.
- Backups stored only on the same server as the site.
- No restore has ever been tested, or the provider cannot say when.
- Malware clean-up excluded or charged at an undefined rate.
- Your hosting or domain must be moved into the provider’s account.
- Shared admin logins instead of named accounts per person.
- Reports that list plugin names but never mention failures or decisions.
- Promises that the site can never be hacked, or that rankings are guaranteed.
None of these automatically means a provider is poor; some are trade-offs on cheap plans. But you should know about each one before you sign, and ask for the answers in writing.
How much do WordPress maintenance services cost in the UK?
WordPress maintenance services in the UK are priced very differently from one provider to the next, so compare what each plan does rather than the monthly figure alone. A cheap plan that auto-updates live and stores backups on the same server is doing much less work than one with staging and restore drills.
With us, care plans start at US$120/mo a month. Four things move the price: the number and complexity of plugins, whether the site takes payments, bookings or member logins (each adds test cases to every update), how much content editing you want included, and how often the database needs backing up.
Sites we build get two months of care free after launch, which covers the period when most early fixes and tweaks happen. After that you choose whether to continue on a plan or pay for fixes as they arise.
Hacked-site recovery for a site not already on a plan is quoted as a separate job, because the effort depends on how deep the infection goes. Hosting, premium plugin licences and security service subscriptions are paid directly by you, so you always see those costs separately from our fee.
Working with a WordPress maintenance team in India from the UK
Working with us from the UK runs on WhatsApp, email and occasional video calls. Our afternoon overlaps your late morning and early afternoon for live conversations, and our morning covers your early hours for maintenance work.
Invoices come from India in USD, usually monthly for a care plan. You pay from a GBP business account by Wise, bank wire or PayPal. How that is treated for your tax is for your accountant; we do not advise on it.
Ownership never moves. Your hosting, domain, WordPress admin account and any plugin licences stay in your name. We use our own named user accounts and a separate hosting login where your host supports it, so you can remove us at any time and nothing else changes.
Week one
You add our admin user and hosting access. We take a full off-site backup, set up staging, review every plugin and theme, switch on activity logging and two-factor login, and send a written health report with anything urgent flagged.
Week two
The first round of updates is done on staging and pushed live early in the UK morning. We run a first restore drill, set up uptime and form monitoring, and agree the monthly report format with you.
Paperwork
Plan contents, backup retention and any response commitments sit in your written quote. Refund terms are on our refund policy page.
Maintenance protects search visibility mostly by preventing damage: a plugin update that adds heavy scripts, a theme change that breaks headings, or a setting flipped to discourage search engines can undo months of work. Checking for those after each update is part of the job.
Each month we look at page speed on mobile, check Core Web Vitals in Google Search Console, confirm the XML sitemap and robots settings are still correct, and scan for broken links and missing pages after content changes. If an update slows the site, we find which component did it.
Search Console also reports security issues and manual actions, which is often where a hack shows up first. We make sure the property is verified in your name and that alerts reach an inbox someone reads.
AI assistants and AI Overviews draw on pages that load reliably and state facts clearly. A site that is often down, slow or partly broken is less likely to be crawled and quoted. Maintenance will not grow traffic on its own and nobody can guarantee rankings, but it keeps the foundation steady. For active growth, monthly SEO starts at US$150/mo; see local SEO services or the technical SEO audit.
Worked example: a hypothetical Harrogate guest house hacked on a Friday evening
This scenario is made up to show how the pieces fit together; it is not a client story. Say a six-room guest house in Harrogate runs a WordPress site with a booking enquiry form and a newsletter sign-up, on one of our care plans.
Friday, 7pm UK: the owner searches for the guest house on her phone and sees spam listings for knock-off trainers under her domain. She sends a screenshot on WhatsApp.
Friday night into Saturday morning (our morning in India): we take a copy of the site as found, check the activity log and file-change alerts, and see that an outdated gallery plugin was exploited on Wednesday. Injected pages were created, but the log shows no admin logins from unknown locations and the form entries table was not touched. We remove the injected files and pages, update the plugin, rotate passwords and keys, and restore from Tuesday’s backup for the affected files.
Saturday, 8am UK: the owner receives a written summary: how the attacker got in, when, what was changed, what personal data the site holds and what the logs show about access to it. With that, she and her adviser can decide whether the incident needs reporting to the ICO well within 72 hours, rather than guessing.
The following week: spam URLs are submitted for removal in Search Console, form storage is set to delete entries after 90 days, and the gallery plugin is replaced with a lighter, maintained one.
WordPress maintenance services UK checklist before you sign up
Before you sign up for any WordPress maintenance service in the UK, make sure you can tick every item below. If a provider cannot answer one, ask them to put the answer in writing.
- Updates are tested on staging before they reach the live site.
- Backups are daily (or more often for shops) and stored off the web server.
- A restore has been tested recently, and drills are scheduled.
- Hacked-site clean-up is included or has a clear quoting process.
- An activity log, login history and change notes are kept.
- Everyone with admin access has a named account with two-factor login.
- Hosting, domain and licences stay in your name.
- You receive a monthly report that mentions failures, not just successes.
- You know who to message and when they work.
If you want us to look at your site first, send the address through our contact page or on WhatsApp and we will reply with what we would change in the first month.