Service
Website maintenance that prevents the emergency rather than billing for it
Almost every website emergency I get called into was preventable and cheap to prevent: an expired domain, an unpatched plugin, a backup nobody had ever restored. Maintenance is not a subscription for reassurance — it is the specific set of checks that stop those three things from happening to you.
- Starting from
- $45
- Timeline
- ongoing monthly
- Proof
- 3 live sites
- Aftercare
- 30 days
What website maintenance actually means
Website maintenance is the recurring set of checks that keep a site working, secure and online: applying updates, taking backups that have actually been restored at least once, patching known vulnerabilities, watching for the domain renewal nobody diarised, and making the small changes a business needs every month.
It is worth saying what it is not. It is not a subscription for reassurance, and it is not insurance against every possible failure. It is a specific list of things that go wrong predictably, done on a schedule, because almost every website emergency I have been called into was preventable and cheap to prevent.
Who this is for
- Businesses whose site takes payments or generates the enquiries the business runs on
- WordPress sites, where unpatched plugins are the most common route to a compromise
- Companies with nobody internally who owns the website
- Businesses that have been burned once by an expired domain, a lapsed certificate or a lost site
- Anyone who would lose real money if the site were down for two days
Who it is not for
Saying this out loud costs me some enquiries and saves both of us the ones that would have gone wrong. If you are on this list, I will tell you in the first reply rather than after a deposit.
- Static brochure sites with no forms, no payments and no CMS, where there is genuinely little to maintain
- Businesses with a competent internal developer already doing this work
- Anyone wanting a retainer that quietly funds continuous new development. That is development, and it should be priced as development
- Sites I have audited and found to be in a state where maintenance would be papering over a rebuild
The problems it solves
- Domain or certificate expires and the site vanishes
- Renewal and expiry monitoring with alerts that reach a human before the deadline, not after.
- Compromised through an unpatched plugin
- Updates applied on staging first, then live, on a monthly cycle rather than when someone remembers.
- Backups that have never been restored
- Quarterly test restores to a scratch environment. An untested backup is a belief.
- Nobody notices the site is down
- Uptime monitoring with alerting, so you hear it from me rather than from a customer.
- Small changes never get made
- A monthly allowance for small content and layout work, so minor updates stop accumulating into a project.
- Silent SEO decay
- Search Console coverage and traffic checked monthly, so a noindex left in production is caught in weeks rather than quarters.
What you get
- Core, plugin and dependency updates applied on staging first, then live
- Offsite backups taken on a schedule and test-restored quarterly, because an untested backup is a hope
- Security patching, plus header and SSL certificate checks
- Uptime and certificate-expiry monitoring, with alerts that reach a human
- Domain and hosting renewal watch — the single most common cause of a site going dark
- A monthly allowance of small content and layout changes, with anything larger quoted separately
- Search Console and analytics checked monthly for coverage errors and traffic anomalies
- A short written monthly report: what changed, what was found, what needs a decision
What is included in the starting price
Everything below is in the $45 figure. Nothing here is quoted as an extra once the build is underway, which is the point of publishing it.
- Core, plugin, theme and dependency updates, applied on staging then live
- Offsite backups on a schedule, with a quarterly test restore
- Security patching, plus header and SSL certificate checks
- Uptime and certificate-expiry monitoring with human-reachable alerts
- Domain and hosting renewal watch
- A monthly allowance of small content and layout changes
- Monthly Search Console and analytics review for coverage errors and traffic anomalies
- A short written monthly report: what changed, what was found, what needs a decision
What costs extra, and why
A quote that omits these is not cheaper — it is less honest. Each one is real work that someone has to do, and pretending otherwise is how a fixed price becomes a negotiation in week two.
- New features or pages
- Quoted separately so the retainer does not become an argument about what counts as small.
- Emergency out-of-hours response
- Available on higher plans with a stated response time rather than the word "fast".
- Recovery from an existing compromise
- A separate piece of work. Cleaning an infected site is not routine maintenance.
- Content production
- Writing and publishing ongoing content is a different service with different value.
- SEO retainer
- Maintenance protects what you have. Growing rankings against real competition is separate work.
How the work runs
- Onboard. Access, an inventory of what the site runs on, and a first full backup taken before anything is touched.
- Baseline. Current versions, current vulnerabilities, current speed and current indexation, recorded so drift is visible later.
- Monthly cycle. Updates on staging, verify, deploy, back up, monitor. The same sequence every month, which is what makes it boring and reliable.
- Quarterly restore test. A backup is restored to a scratch environment and checked. Any month this is skipped, you do not really have backups.
- Report. What was done, what was found, and what needs your decision. No decision needed most months, which is the point.
Day by day
ongoing monthly from the day scope is signed off. Published as a schedule rather than a promise of speed — you should be able to tell on day three whether a build is on track.
| When | What happens |
|---|---|
| Onboarding | Access collected, an inventory of what the site actually runs on, and a full backup before anything is touched. |
| Baseline | Current versions, known vulnerabilities, speed and indexation recorded, so later drift is visible rather than argued about. |
| Monthly cycle | Update on staging, verify, deploy, back up, monitor. The same sequence every month, which is what makes it reliable. |
| Quarterly | A backup restored to a scratch environment and checked. Skipped quarters mean you do not really have backups. |
| Reporting | A short written summary each month: done, found, and anything that needs your decision. Most months, nothing does. |
The technology
Deliberately boring, and that is the feature. A stack another developer can pick up is worth more to you than one that impresses other developers.
- Backups
- Offsite and versioned, never only on the same server as the site itself
- Monitoring
- Uptime checks, certificate expiry, and domain renewal dates tracked outside the registrar
- Staging
- A separate noindexed environment where updates are proven before they touch production
- Updates
- Applied deliberately on a schedule rather than automatically at three in the morning
- Reporting
- Search Console, uptime history and a written summary you can keep for your own records
What it integrates with
- Google Search Console, monitored for coverage and manual actions
- Uptime monitoring with alerts by email and message
- Your hosting control panel and registrar, for renewal and certificate visibility
- Offsite backup storage separate from the hosting account
- Analytics, watched for the traffic anomaly that signals a technical fault
What I need from you
Short list, and the first item matters most. Projects do not usually slip because the code was hard — they slip because a decision waited a week.
- Access: hosting, CMS admin, registrar and DNS
- A named person who can approve a change or a decision within a few days
- Notice before you or anyone else makes significant changes, so a fault can be attributed
- Honesty about what other people have access to the site, because that is often the answer when something breaks
- A decision on how quickly you actually need a response, since that is what separates the plans
Content and photography
The most valuable content work in maintenance is unglamorous: keeping the pages that already earn their traffic accurate. Prices that changed, services no longer offered, staff who left, an address that moved. Each one costs trust and, where the details are in structured data, consistency signals too.
A short quarterly review of your top ten pages against what the business currently does takes an hour and is worth more than most content plans. It is included in the monthly review here, and it is the item clients are most often surprised to find useful.
Performance standards
Targets, not aspirations — measured before handover on a throttled mobile connection rather than on a fast laptop.
| Metric | Target |
|---|---|
| Largest Contentful Paint | Under 2.5s on a mid-range Android over 4G, measured in the field rather than on my laptop |
| Interaction to Next Paint | Under 200ms — which mostly means shipping less JavaScript rather than reordering it |
| Cumulative Layout Shift | Under 0.1: every image carries width and height, fonts have metric-matched fallbacks |
| Total page weight | Budgeted before the build, not discovered after it |
Accessibility standards
| Standard | WCAG 2.2 AA as the build target, tested rather than asserted |
|---|---|
| Keyboard | Every interactive element reachable and operable without a mouse, with visible focus |
| Contrast | Text at 4.5:1, interface elements and icons at 3:1, checked with a contrast tool not by eye |
| Motion | Anything animating over five seconds gets a pause control — WCAG 2.2.2 is a Level A requirement |
| Forms | Real labels, errors described in text next to the field, no colour-only signalling |
| Why it matters commercially | The European Accessibility Act has applied to consumer e-commerce since June 2025, and the obligation sits with the business selling, not the agency that built it |
This site is built to the same standard it sells, and the accessibility statement lists what is conformant and what is not — which is the part most statements leave out.
Security practices
| Transport | HTTPS enforced in a single redirect hop, HSTS enabled |
|---|---|
| Headers | CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and COOP set |
| Database | Prepared statements everywhere. Not "mostly" — everywhere |
| Input | Validated server-side, because client-side validation is a convenience and not a control |
| Secrets | Environment variables, never in the repository, never in a JavaScript bundle |
| SPF, DKIM and DMARC aligned so your order confirmations reach inboxes |
The SEO included in every build
Not an upsell. A site that launches unindexed is a shop with the shutters down, and the work below is cheap during a build and expensive afterwards because the fixes are structural.
| Rendering | Content present in the HTML without JavaScript execution, so every crawler and answer engine can read it |
|---|---|
| Indexation | One canonical per page, generated XML sitemap, robots.txt that does not block what it should not |
| Structured data | A linked JSON-LD graph — Organization, WebSite, page type and the commercial type that fits |
| AI crawlers | Access verified per user-agent before launch, because a host can 403 GPTBot before robots.txt is read |
| Search Console | Verified and the sitemap submitted at launch, so the site goes live indexed rather than as a blank shell |
Ownership and handover
You own everything: the domain registered to you, hosting in your account, code in a repository you control, and the payment provider account in your business name. Credentials are handed over as they are created rather than at the end.
A supplier who resists this is protecting recurring revenue rather than your interests. If you want the reasoning in full, including how to check your current site, there is a guide on it.
Aftercare and what happens after launch
Thirty days of snag fixes are included. A snag is something that does not work as scoped — not a new feature, and the difference is written down before launch rather than argued about after it.
You also get written handover documentation aimed at whoever maintains the site next, which may well not be me. That is deliberate: the test of a good handover is whether another developer could take over without calling me, and on my projects they can.
Ongoing maintenance
Optional, monthly, cancellable. Nothing here is required to keep what you paid for.
| Retainer | From | Covers |
|---|---|---|
| Maintenance | $50/month | Software, plugin and dependency updates; Automated backups with restore tested quarterly; Uptime monitoring with alerting |
| SEO retainer | $80/month | Monthly technical crawl and fix cycle; Search Console monitoring and issue resolution; Content briefs based on your real query data |
Payment terms
| Working hours | Mon–Fri, 09:00–18:00 PKT (UTC+5). That overlaps 05:00–14:00 UK time and 00:00–09:00 US Eastern. |
|---|---|
| Response time | Within one business day, always. If I will be unreachable for longer, you know before it happens. |
| Meetings | Google Meet or Zoom, scheduled in your timezone. I will take an early or late call to reach you — that is my problem to solve, not yours. |
| Language | All work, documentation and communication in English. |
| Payment | 40% deposit, 60% on completion. Bank transfer or Wise. Invoices issued for your records. |
| Currency | Quoted in USD by default. GBP, CAD or EUR on request. |
How this compares to the alternatives
Including the routes that do not involve me, because a comparison that only flatters the author is not a comparison.
| Route | Cost | What you trade |
|---|---|---|
| Do nothing | Free until it is not | The cost arrives all at once, usually at the worst time |
| Host-provided auto-updates | Included | Updates applied without staging or verification, and backups nobody has tested |
| This retainer | Starting from $45/month | A fixed monthly fee, in exchange for the emergency not happening |
| Call a developer when it breaks | Emergency rates | Downtime while you find someone, and no backup they can trust |
What could go wrong, and how it is handled
- An update breaks something
- Why updates go to staging first. If it breaks there, it never reaches your customers.
- The site is already compromised at onboarding
- Found during the initial audit. Cleaning it is quoted separately before the retainer starts.
- Someone else changes the site without telling anyone
- The most common cause of an unexplained fault. Access is inventoried at onboarding for exactly this reason.
- The plan does not cover what you assumed
- The allowance and the response time are written down. Ambiguity here is what turns retainers into disputes.
Live builds you can open
Every project below is live right now. Nothing here is a mockup, a concept piece or a template screenshot, and the build fails if any of these URLs stops responding.
24 Hours London
Developed and deployed a responsive client website with a full SEO setup.
24hrs.london ↗Cheapest Proxies
Full-stack proxy e-commerce app with Stripe checkout and automated order + email handling via PHPMailer - built and deployed end to end.
cheapest-proxies.com ↗Removal Services London
Responsive website for a London-based removals and moving-services company.
removal-services.london ↗Case studies
What the brief was, what I built and the decisions worth explaining. No invented traffic figures — every number on this site is one I can evidence.
What to measure after launch
A site with no measurement is a site nobody can improve. These are the numbers worth watching, in the order they matter.
- Uptime percentage over the month, with any incident explained
- Time to restore, measured on the quarterly test rather than estimated
- Number of updates applied and vulnerabilities closed
- Search Console coverage errors, which should trend to zero and stay there
- Core Web Vitals field data, watched for regression after content changes
- How many small changes were requested against the allowance, which tells you whether the plan fits
Common mistakes in this kind of project
Every one of these has been found on a real site, several of them on this one before it was rebuilt.
- Automatic updates with no staging and no backup
- Works until the morning it does not, and then there is nothing to roll back to.
- Backups stored on the same server as the site
- A server failure or a compromise takes the backups with it.
- Never testing a restore
- The most common discovery during a real incident, and the worst possible moment for it.
- Domain renewal on a personal card that expired
- A genuinely common cause of a business site going dark, and entirely preventable.
- Treating maintenance as optional for a site that generates revenue
- The saving is small and the exposure is the whole revenue stream.
Glossary
Terms that come up in quotes and get nodded at rather than asked about.
- Staging
- A copy of the site where changes are proven before they reach visitors.
- Offsite backup
- A backup stored somewhere other than the server it came from.
- Test restore
- Actually restoring a backup to verify it works. The step that makes backups real.
- Patch
- An update that closes a known security hole, as distinct from one adding features.
- Uptime monitoring
- An external service checking the site regularly and alerting when it fails.
- Manual action
- A penalty applied by a human reviewer at Google, visible in Search Console.
Guides on this subject
Free, ungated, and written from client work. If reading one convinces you I know what I am doing, the enquiry follows on its own.
Questions people ask before hiring
- Do I really need a website maintenance plan?
- If the site takes payments or generates enquiries, the honest answer is yes — not for the updates, but for the backups and the renewal watch. If it is a three-page brochure site you would not miss for a week, a maintenance plan is optional and I will say so.
- What is included in the monthly fee?
- Updates, backups, security patching, monitoring, a monthly allowance of small changes and a written report. Anything that is genuinely a new feature is quoted separately, so the retainer does not quietly turn into an argument about what counts as small.
- Can you maintain a site somebody else built?
- Yes, and that is most of this work. It starts with an audit, because I will not take responsibility for a codebase I have not read. If the audit turns up something serious, you get told before the retainer starts rather than after.
- What happens if my site goes down?
- Monitoring alerts me, usually before you notice. Response time depends on the plan, and the plan says a number rather than the word "fast". Restoring from the most recent verified backup is the fallback if the cause is not immediately obvious.
Every other question I get asked → · or just ask me directly
Website maintenance by location
Same fixed scope and the same $45 starting price, priced in the local currency with that country's tax and data-protection terms set out in full.
- Website maintenance Enfield
- Website maintenance Drogheda
- Website maintenance Ottawa
- Website maintenance Philadelphia
- Website maintenance Parramatta
- Website maintenance Abu Dhabi
- Website maintenance Dammam
- Website maintenance Rawalpindi
- Website maintenance Delhi
- Website maintenance Woodlands
- Website maintenance Cape Town
- Website maintenance Dusseldorf
- Website maintenance Rotterdam
- Website maintenance Toulouse
Other services
Need website maintenance?
Send the brief and you get a reply within one business day — either questions, or a scoping call. If your project is not something I should take on, I will say so then.
- Response
- Replies within 1 business day
- Hours
- Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern
- Booking
- Booking projects from October 2026