Service

Website maintenance that prevents the emergency rather than billing for it

Almost every website emergency I get called into was preventable and cheap to prevent: an expired domain, an unpatched plugin, a backup nobody had ever restored. Maintenance is not a subscription for reassurance — it is the specific set of checks that stop those three things from happening to you.

Starting from
$45
Timeline
ongoing monthly
Proof
3 live sites
Aftercare
30 days

What website maintenance actually means

Website maintenance is the recurring set of checks that keep a site working, secure and online: applying updates, taking backups that have actually been restored at least once, patching known vulnerabilities, watching for the domain renewal nobody diarised, and making the small changes a business needs every month.

It is worth saying what it is not. It is not a subscription for reassurance, and it is not insurance against every possible failure. It is a specific list of things that go wrong predictably, done on a schedule, because almost every website emergency I have been called into was preventable and cheap to prevent.

Who this is for

  • Businesses whose site takes payments or generates the enquiries the business runs on
  • WordPress sites, where unpatched plugins are the most common route to a compromise
  • Companies with nobody internally who owns the website
  • Businesses that have been burned once by an expired domain, a lapsed certificate or a lost site
  • Anyone who would lose real money if the site were down for two days

Who it is not for

Saying this out loud costs me some enquiries and saves both of us the ones that would have gone wrong. If you are on this list, I will tell you in the first reply rather than after a deposit.

  • Static brochure sites with no forms, no payments and no CMS, where there is genuinely little to maintain
  • Businesses with a competent internal developer already doing this work
  • Anyone wanting a retainer that quietly funds continuous new development. That is development, and it should be priced as development
  • Sites I have audited and found to be in a state where maintenance would be papering over a rebuild

The problems it solves

Domain or certificate expires and the site vanishes
Renewal and expiry monitoring with alerts that reach a human before the deadline, not after.
Compromised through an unpatched plugin
Updates applied on staging first, then live, on a monthly cycle rather than when someone remembers.
Backups that have never been restored
Quarterly test restores to a scratch environment. An untested backup is a belief.
Nobody notices the site is down
Uptime monitoring with alerting, so you hear it from me rather than from a customer.
Small changes never get made
A monthly allowance for small content and layout work, so minor updates stop accumulating into a project.
Silent SEO decay
Search Console coverage and traffic checked monthly, so a noindex left in production is caught in weeks rather than quarters.

What you get

  • Core, plugin and dependency updates applied on staging first, then live
  • Offsite backups taken on a schedule and test-restored quarterly, because an untested backup is a hope
  • Security patching, plus header and SSL certificate checks
  • Uptime and certificate-expiry monitoring, with alerts that reach a human
  • Domain and hosting renewal watch — the single most common cause of a site going dark
  • A monthly allowance of small content and layout changes, with anything larger quoted separately
  • Search Console and analytics checked monthly for coverage errors and traffic anomalies
  • A short written monthly report: what changed, what was found, what needs a decision

What is included in the starting price

Everything below is in the $45 figure. Nothing here is quoted as an extra once the build is underway, which is the point of publishing it.

  • Core, plugin, theme and dependency updates, applied on staging then live
  • Offsite backups on a schedule, with a quarterly test restore
  • Security patching, plus header and SSL certificate checks
  • Uptime and certificate-expiry monitoring with human-reachable alerts
  • Domain and hosting renewal watch
  • A monthly allowance of small content and layout changes
  • Monthly Search Console and analytics review for coverage errors and traffic anomalies
  • A short written monthly report: what changed, what was found, what needs a decision

What costs extra, and why

A quote that omits these is not cheaper — it is less honest. Each one is real work that someone has to do, and pretending otherwise is how a fixed price becomes a negotiation in week two.

New features or pages
Quoted separately so the retainer does not become an argument about what counts as small.
Emergency out-of-hours response
Available on higher plans with a stated response time rather than the word "fast".
Recovery from an existing compromise
A separate piece of work. Cleaning an infected site is not routine maintenance.
Content production
Writing and publishing ongoing content is a different service with different value.
SEO retainer
Maintenance protects what you have. Growing rankings against real competition is separate work.

How the work runs

  1. Onboard. Access, an inventory of what the site runs on, and a first full backup taken before anything is touched.
  2. Baseline. Current versions, current vulnerabilities, current speed and current indexation, recorded so drift is visible later.
  3. Monthly cycle. Updates on staging, verify, deploy, back up, monitor. The same sequence every month, which is what makes it boring and reliable.
  4. Quarterly restore test. A backup is restored to a scratch environment and checked. Any month this is skipped, you do not really have backups.
  5. Report. What was done, what was found, and what needs your decision. No decision needed most months, which is the point.

Day by day

ongoing monthly from the day scope is signed off. Published as a schedule rather than a promise of speed — you should be able to tell on day three whether a build is on track.

WhenWhat happens
Onboarding Access collected, an inventory of what the site actually runs on, and a full backup before anything is touched.
Baseline Current versions, known vulnerabilities, speed and indexation recorded, so later drift is visible rather than argued about.
Monthly cycle Update on staging, verify, deploy, back up, monitor. The same sequence every month, which is what makes it reliable.
Quarterly A backup restored to a scratch environment and checked. Skipped quarters mean you do not really have backups.
Reporting A short written summary each month: done, found, and anything that needs your decision. Most months, nothing does.

The technology

Deliberately boring, and that is the feature. A stack another developer can pick up is worth more to you than one that impresses other developers.

Backups
Offsite and versioned, never only on the same server as the site itself
Monitoring
Uptime checks, certificate expiry, and domain renewal dates tracked outside the registrar
Staging
A separate noindexed environment where updates are proven before they touch production
Updates
Applied deliberately on a schedule rather than automatically at three in the morning
Reporting
Search Console, uptime history and a written summary you can keep for your own records

What it integrates with

  • Google Search Console, monitored for coverage and manual actions
  • Uptime monitoring with alerts by email and message
  • Your hosting control panel and registrar, for renewal and certificate visibility
  • Offsite backup storage separate from the hosting account
  • Analytics, watched for the traffic anomaly that signals a technical fault

What I need from you

Short list, and the first item matters most. Projects do not usually slip because the code was hard — they slip because a decision waited a week.

  • Access: hosting, CMS admin, registrar and DNS
  • A named person who can approve a change or a decision within a few days
  • Notice before you or anyone else makes significant changes, so a fault can be attributed
  • Honesty about what other people have access to the site, because that is often the answer when something breaks
  • A decision on how quickly you actually need a response, since that is what separates the plans

Content and photography

The most valuable content work in maintenance is unglamorous: keeping the pages that already earn their traffic accurate. Prices that changed, services no longer offered, staff who left, an address that moved. Each one costs trust and, where the details are in structured data, consistency signals too.

A short quarterly review of your top ten pages against what the business currently does takes an hour and is worth more than most content plans. It is included in the monthly review here, and it is the item clients are most often surprised to find useful.

Performance standards

Targets, not aspirations — measured before handover on a throttled mobile connection rather than on a fast laptop.

MetricTarget
Largest Contentful PaintUnder 2.5s on a mid-range Android over 4G, measured in the field rather than on my laptop
Interaction to Next PaintUnder 200ms — which mostly means shipping less JavaScript rather than reordering it
Cumulative Layout ShiftUnder 0.1: every image carries width and height, fonts have metric-matched fallbacks
Total page weightBudgeted before the build, not discovered after it

Accessibility standards

StandardWCAG 2.2 AA as the build target, tested rather than asserted
KeyboardEvery interactive element reachable and operable without a mouse, with visible focus
ContrastText at 4.5:1, interface elements and icons at 3:1, checked with a contrast tool not by eye
MotionAnything animating over five seconds gets a pause control — WCAG 2.2.2 is a Level A requirement
FormsReal labels, errors described in text next to the field, no colour-only signalling
Why it matters commerciallyThe European Accessibility Act has applied to consumer e-commerce since June 2025, and the obligation sits with the business selling, not the agency that built it

This site is built to the same standard it sells, and the accessibility statement lists what is conformant and what is not — which is the part most statements leave out.

Security practices

TransportHTTPS enforced in a single redirect hop, HSTS enabled
HeadersCSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy and COOP set
DatabasePrepared statements everywhere. Not "mostly" — everywhere
InputValidated server-side, because client-side validation is a convenience and not a control
SecretsEnvironment variables, never in the repository, never in a JavaScript bundle
EmailSPF, DKIM and DMARC aligned so your order confirmations reach inboxes

The SEO included in every build

Not an upsell. A site that launches unindexed is a shop with the shutters down, and the work below is cheap during a build and expensive afterwards because the fixes are structural.

RenderingContent present in the HTML without JavaScript execution, so every crawler and answer engine can read it
IndexationOne canonical per page, generated XML sitemap, robots.txt that does not block what it should not
Structured dataA linked JSON-LD graph — Organization, WebSite, page type and the commercial type that fits
AI crawlersAccess verified per user-agent before launch, because a host can 403 GPTBot before robots.txt is read
Search ConsoleVerified and the sitemap submitted at launch, so the site goes live indexed rather than as a blank shell

Ownership and handover

You own everything: the domain registered to you, hosting in your account, code in a repository you control, and the payment provider account in your business name. Credentials are handed over as they are created rather than at the end.

A supplier who resists this is protecting recurring revenue rather than your interests. If you want the reasoning in full, including how to check your current site, there is a guide on it.

Aftercare and what happens after launch

Thirty days of snag fixes are included. A snag is something that does not work as scoped — not a new feature, and the difference is written down before launch rather than argued about after it.

You also get written handover documentation aimed at whoever maintains the site next, which may well not be me. That is deliberate: the test of a good handover is whether another developer could take over without calling me, and on my projects they can.

Ongoing maintenance

Optional, monthly, cancellable. Nothing here is required to keep what you paid for.

RetainerFromCovers
Maintenance $50/month Software, plugin and dependency updates; Automated backups with restore tested quarterly; Uptime monitoring with alerting
SEO retainer $80/month Monthly technical crawl and fix cycle; Search Console monitoring and issue resolution; Content briefs based on your real query data

Payment terms

Working hoursMon–Fri, 09:00–18:00 PKT (UTC+5). That overlaps 05:00–14:00 UK time and 00:00–09:00 US Eastern.
Response timeWithin one business day, always. If I will be unreachable for longer, you know before it happens.
MeetingsGoogle Meet or Zoom, scheduled in your timezone. I will take an early or late call to reach you — that is my problem to solve, not yours.
LanguageAll work, documentation and communication in English.
Payment40% deposit, 60% on completion. Bank transfer or Wise. Invoices issued for your records.
CurrencyQuoted in USD by default. GBP, CAD or EUR on request.

How this compares to the alternatives

Including the routes that do not involve me, because a comparison that only flatters the author is not a comparison.

RouteCostWhat you trade
Do nothingFree until it is notThe cost arrives all at once, usually at the worst time
Host-provided auto-updatesIncludedUpdates applied without staging or verification, and backups nobody has tested
This retainerStarting from $45/monthA fixed monthly fee, in exchange for the emergency not happening
Call a developer when it breaksEmergency ratesDowntime while you find someone, and no backup they can trust

What could go wrong, and how it is handled

An update breaks something
Why updates go to staging first. If it breaks there, it never reaches your customers.
The site is already compromised at onboarding
Found during the initial audit. Cleaning it is quoted separately before the retainer starts.
Someone else changes the site without telling anyone
The most common cause of an unexplained fault. Access is inventoried at onboarding for exactly this reason.
The plan does not cover what you assumed
The allowance and the response time are written down. Ambiguity here is what turns retainers into disputes.

Live builds you can open

Every project below is live right now. Nothing here is a mockup, a concept piece or a template screenshot, and the build fails if any of these URLs stops responding.

Service Website

24 Hours London

Developed and deployed a responsive client website with a full SEO setup.

24hrs.london ↗
Full-Stack E-commerce

Cheapest Proxies

Full-stack proxy e-commerce app with Stripe checkout and automated order + email handling via PHPMailer - built and deployed end to end.

cheapest-proxies.com ↗
Service Website

Removal Services London

Responsive website for a London-based removals and moving-services company.

removal-services.london ↗

Case studies

What the brief was, what I built and the decisions worth explaining. No invented traffic figures — every number on this site is one I can evidence.

What to measure after launch

A site with no measurement is a site nobody can improve. These are the numbers worth watching, in the order they matter.

  1. Uptime percentage over the month, with any incident explained
  2. Time to restore, measured on the quarterly test rather than estimated
  3. Number of updates applied and vulnerabilities closed
  4. Search Console coverage errors, which should trend to zero and stay there
  5. Core Web Vitals field data, watched for regression after content changes
  6. How many small changes were requested against the allowance, which tells you whether the plan fits

Common mistakes in this kind of project

Every one of these has been found on a real site, several of them on this one before it was rebuilt.

Automatic updates with no staging and no backup
Works until the morning it does not, and then there is nothing to roll back to.
Backups stored on the same server as the site
A server failure or a compromise takes the backups with it.
Never testing a restore
The most common discovery during a real incident, and the worst possible moment for it.
Domain renewal on a personal card that expired
A genuinely common cause of a business site going dark, and entirely preventable.
Treating maintenance as optional for a site that generates revenue
The saving is small and the exposure is the whole revenue stream.

Glossary

Terms that come up in quotes and get nodded at rather than asked about.

Staging
A copy of the site where changes are proven before they reach visitors.
Offsite backup
A backup stored somewhere other than the server it came from.
Test restore
Actually restoring a backup to verify it works. The step that makes backups real.
Patch
An update that closes a known security hole, as distinct from one adding features.
Uptime monitoring
An external service checking the site regularly and alerting when it fails.
Manual action
A penalty applied by a human reviewer at Google, visible in Search Console.

Guides on this subject

Free, ungated, and written from client work. If reading one convinces you I know what I am doing, the enquiry follows on its own.

Questions people ask before hiring

Do I really need a website maintenance plan?
If the site takes payments or generates enquiries, the honest answer is yes — not for the updates, but for the backups and the renewal watch. If it is a three-page brochure site you would not miss for a week, a maintenance plan is optional and I will say so.
What is included in the monthly fee?
Updates, backups, security patching, monitoring, a monthly allowance of small changes and a written report. Anything that is genuinely a new feature is quoted separately, so the retainer does not quietly turn into an argument about what counts as small.
Can you maintain a site somebody else built?
Yes, and that is most of this work. It starts with an audit, because I will not take responsibility for a codebase I have not read. If the audit turns up something serious, you get told before the retainer starts rather than after.
What happens if my site goes down?
Monitoring alerts me, usually before you notice. Response time depends on the plan, and the plan says a number rather than the word "fast". Restoring from the most recent verified backup is the fallback if the cause is not immediately obvious.

Every other question I get asked → · or just ask me directly

Website maintenance by location

Same fixed scope and the same $45 starting price, priced in the local currency with that country's tax and data-protection terms set out in full.

All 735 locations across 39 countries →

Other services

Need website maintenance?

Send the brief and you get a reply within one business day — either questions, or a scoping call. If your project is not something I should take on, I will say so then.

Response
Replies within 1 business day
Hours
Mon–Fri, 09:00–18:00 PKT — overlaps 05:00–14:00 UK, 00:00–09:00 US Eastern
Booking
Booking projects from October 2026
WhatsApp — opens a chat with +92 346 5348466 in a new tab