A screen with a program open on it — MYOS | Software Project

The site goes live, the invoice gets paid, and for a fortnight everything’s brilliant. Then an email arrives offering a monthly care plan, and you’re left wondering whether that’s a real need or a subscription bolted onto a finished job.

Nobody explains this bit until you’re being asked to pay for it. So here’s what genuinely needs doing after launch, how often, and a straight answer on care plans. Fair warning: I sell care packages. I’ll tell you where they earn their keep and when you’re better off doing it yourself.

TL;DR

  • A live website is software on a public server, and patching is the one job you can’t skip. The gap between a security fix being published and yours being applied is the window bots look in.
  • Backups are what everybody assumes and nobody tests. One you’ve never restored is a rumour.
  • A fair plan: updates applied and checked, off-site backups that have been restored, uptime, SSL and PHP watched, a form test, a human who answers. Padding: undefined “monitoring” and reports nobody reads.
  • Plenty of businesses can self-manage, and I’ll say so when that’s you. Mine is two weeks of free support after completion, then care packages if you want one.

What actually needs doing after launch

Search website maintenance cost and you’ll get a spread of UK figures with nothing behind them. Start with the work instead.

Frequency is where these lists go wrong. Security fixes don’t arrive on a schedule to suit you, and the moment a flaw is published the clock is running on every site still on the old version. Read it as a rhythm, not a calendar.

  • Core, plugin and theme updates. Monthly is realistic, with security releases done the day you see them.
  • A full backup of files and database, stored off the server it came from and reaching back a few weeks.
  • SSL renewal. Usually automatic, which is why nobody checks it. A lapsed certificate puts a full-page warning in front of visitors.
  • Uptime checking, so you hear it from a monitor at 3am rather than a customer at half nine.
  • A real test submission through the contact form to the real inbox. Not a look at the settings page.
  • Broken links and missing images, which multiply every time somebody renames a page.
  • The PHP version your hosting runs on. It goes end of life on a published schedule and your host will move you eventually.

None of it is difficult, and that’s worth knowing before anyone quotes you. It isn’t hard work, it’s relentless work, and it loses to everything else in your week around month four.

Security patching is the one you can’t skip

Nobody is sat at a keyboard picking on a joiner in Houghton. A flaw in a popular plugin gets published along with the version it was fixed in, and scanners then crawl huge ranges of the web looking for that plugin at that version. Your site isn’t chosen. It’s matched.

What follows is rarely dramatic. No skull on the homepage. You get hidden pages selling something dodgy, injected links, or a redirect that only fires for people arriving from Google, so it looks fine to you and broken to everyone who matters.

The gap between a fix being published and that fix reaching your site is the whole game. That’s why this one is non-negotiable.

A backup you’ve never restored is a rumour

Everybody has backups. Almost nobody has put one back.

The failures are dull and consistent. A plugin backing up the files but not the database, where every page and setting lives. Copies saved onto the same server they’re protecting. A scheduled job that stopped in March, unnoticed, because nothing emails you when a backup doesn’t happen.

Fixing that takes one afternoon, once. Restore a copy somewhere private, log in, click about. Better to find out on a quiet Tuesday than on the morning your site has gone. How far the copies reach back matters too, because seven days sounds plenty until a problem has sat there a fortnight.

The contact form is the one that costs you quietly

A broken site gets reported to you within the hour. A broken form never gets reported at all.

Most forms hand the message to the hosting server to send, and the rules on who’s allowed to send mail for your domain tighten every year. If those records don’t line up, Gmail and Outlook increasingly reject the message rather than filing it in spam. Nothing looks wrong. The form still says thanks. The enquiry never lands, and you decide the website isn’t working.

Then the human version. The address belongs to somebody who left, or points at an inbox nobody has opened since the shop got busy. Send yourself a test enquiry once a month from your phone, and reply to it. I’ve written before about sites that look fine and still get no enquiries, and a form eating messages is on that list.

So do you actually need a care plan?

Depends what’s inside it. A fair plan does the work above and can show you it happened. Updates applied, then the site looked at afterwards, because an update that breaks your layout on a phone is worse than no update. Backups pulled off the server and restored occasionally. Uptime, SSL and PHP watched. A form test. And a human who picks up when something breaks.

Padding has recognisable shapes. “Monitoring” with no definition of what’s watched or what happens when it trips. A monthly PDF nobody reads to the end. SEO as a line item with no work described behind it. Hosting rebadged at a markup and called maintenance.

Ask for the list in writing. What gets done, how often, what happens when something breaks that isn’t on it, and what that costs.

Mine’s on the table before you buy anything: two weeks of free support after the site’s completed, then care packages if you want one. Inside those two weeks, anything broken is mine to sort. After that it’s your call, with no contract holding you anywhere. You own the site and you hold the logins. What a build includes and costs is on my web design page; the process is on my FAQ page.

Ask whoever’s selling you a care plan one question: when did you last restore a backup of a client’s site, and how long did it take? Vague answer, and you’ve found out what you’d be paying for. The assumption that everything’s fine.

When you can genuinely do this yourself

Plenty of businesses can, and I’d rather say so than take the money.

It works when a few things line up. Somebody logs in monthly and doesn’t resent it. The site is a brochure or a small shop, rather than something holding customer accounts and card details. And your host takes its own backups, which you’ve checked rather than assumed.

The job is short. Log in, run the updates, load the homepage and the two or three pages that matter, then submit the contact form.

The honest reason plans exist is that most people do this for two months and then life gets in the way. If that’ll be you, a plan costs less than the alternative. Keep at it and keep your money. And if what you want is somebody in the background for the odd strange day rather than a monthly commitment, that’s closer to day-to-day tech support.

What happens if you do nothing at all

This is what people are really asking. Quite often nothing happens, for a year, sometimes longer. That’s why the advice is easy to ignore, and why everyone who got away with it is sure they were right.

Then it goes, at the worst possible time. A plugin flaw gets found, your site starts serving somebody else’s spam, and the host suspends the account. Or nothing gets hacked at all: your host retires an old PHP version on a schedule published months back, the site goes white because a plugin from 2019 can’t run on it, and it’s Saturday.

The cost is hardly ever the repair. It’s the days offline, the visibility that drains away while a warning sits under your listing, and the customer who saw a browser security screen and went to whoever was next. That last one you never hear about.

FAQs

What happens if I never update my website?

For a while, usually nothing, which is what makes it a bad bet rather than an obvious mistake. The odds shift over time: flaws in old plugin versions get published and scanned for, and your host will eventually retire the PHP version you’re on. The usual ending isn’t a dramatic hack. It’s a site quietly serving spam pages.

How often do backups need running?

Match it to how much work you’d be willing to redo. A brochure site that changes twice a year is fine on weekly. A shop taking orders wants daily. What matters more than the interval is that copies live off the server they came from, reach back far enough, and that somebody has restored one.

Is hosting included in what I paid?

Depends what you bought. Ask bluntly. On my own published pricing, the standard build lists UK hosting in what’s included, and both bands list weekly backups. Whoever built yours, get it in writing: included for how long, and what happens after? No end date is what turns awkward in year two.

Can I do the maintenance myself?

Yes, on a normal WordPress brochure site, and a fair few people should. Log in monthly, run the updates, check the site still looks right, and pull a backup off the server every few months. Two things catch DIY out. Drift, where three good months become six missed ones, and knowing what to do the day an update breaks something.

What does it cost to fix a hacked site?

There’s no honest single figure, and anybody quoting one before looking is guessing. It’s driven by how long the site was compromised, whether a clean backup exists from before it happened, and whether the way in gets closed. Clean up without closing the door and it’s back within a fortnight. Clean backup and a known cause is a short job. Neither, and it’s detective work.

You can run all this yourself. If you’ve read the list and thought “aye, that’s an hour a month”, crack on and don’t buy anything. If you’d rather someone looked at what’s running on your site, when it was last updated and whether those backups exist, that’s the sort of thing I do for businesses around Sunderland and the North East. Drop me a line and I’ll tell you plainly whether a care plan is worth it.

footer shape