Website maintenance is one of those services that can sound responsible without saying much.
A proposal may promise updates, security, backups, monitoring, support, and peace of mind. Those words are reassuring. They are not yet a scope of work.
What gets updated? What is monitored? How quickly does anyone respond? Can the site actually be restored from the backup? Are content changes included? Who owns the accounts if the relationship ends?
A useful maintenance plan answers those questions before something breaks.
The short answer
Website maintenance should cover five responsibilities:
- Availability: keep the domain, certificate, hosting, and website working.
- Security: maintain supported software, control access, and reduce known exposure.
- Recovery: keep usable backups and know how the site will be restored.
- Accuracy: test important functions and keep customer-facing information current.
- Support: define who responds, how requests are handled, and what evidence the owner receives.
The exact work depends on the website. A static marketing site does not need the same care as WordPress, a store, a member portal, or a custom application. The plan should name the technology and responsibilities it actually covers.
“We maintain your website” is a promise. A maintenance plan should turn that promise into tasks, timing, ownership, and limits.
1. Availability: keep the website reachable
The first job is basic but not trivial: the website should remain available at the address customers know.
Routine availability work may include:
- Hosting the website or coordinating with the hosting provider
- Monitoring whether important pages respond
- Renewing or checking the security certificate
- Watching domain and DNS expiration dates
- Confirming the domain still points to the correct service
- Responding to hosting failures or unexpected outages
- Keeping billing and recovery contacts current
These duties may belong to one provider or several. A web company may maintain the site while the business pays the domain registrar directly. A hosting company may keep its servers online without checking whether the contact form works. A certificate may renew automatically until a failed payment or DNS change interrupts it.
Ask who owns each dependency and who receives its warnings.
Monitoring also needs a definition. A provider might check only the homepage every five minutes. That can detect a complete outage but miss a broken booking page, failed form, missing image, or error that affects only mobile visitors.
The plan should identify what is watched, how the alert reaches a person, and what happens next. An uptime alert is not the same as a repair.
No responsible provider can guarantee that a website will never go down. The useful promise is that failures are detected, routed, and handled according to a stated process.
2. Security: reduce the avoidable risk
Maintenance cannot make a website invulnerable. It should reduce known, preventable exposure.
For a content management system such as WordPress, this usually means maintaining the supported versions of the core software, theme, plugins, server environment, and any security tools. Updates should be applied with enough care to catch compatibility problems rather than installed blindly and forgotten.
For a static site, there may be no public database, admin login, or plugin dashboard to patch. That removes a large maintenance surface, but it does not remove every responsibility. The hosting account, deployment system, forms, third-party services, domain, access permissions, and build dependencies still need owners and controls.
Security maintenance may include:
- Applying relevant software updates and security patches
- Removing unsupported or unnecessary components
- Limiting administrator access
- Requiring multi-factor authentication where available
- Removing accounts when staff or vendors leave
- Reviewing unexpected changes or suspicious files
- Keeping credentials out of shared documents and email threads
- Monitoring Search Console or security services for warnings
- Maintaining a documented response path for suspected compromise
The Federal Trade Commission’s small-business cybersecurity guidance recommends regular software updates and backups. CISA’s small-business resources also emphasize software updates, strong authentication, logging, and backups.
Those are operating practices, not products a provider can imply with the word “secure.” Ask what is done, by whom, and on which systems.
If a site handles payments, protected health information, financial records, or another regulated category of data, ordinary website maintenance is not enough by itself. The business needs an environment, vendors, agreements, controls, and professional advice appropriate to that use.
3. Recovery: keep backups that can be used
A backup has value only if it contains what is needed, can be located, and can be restored.
A maintenance plan should explain:
- What is backed up
- How often backups are created
- How long they are retained
- Where they are stored
- Whether the backup is separate from the live system
- Who can start a restore
- How restoration is tested
- What recovery time the provider aims for
The right backup depends on the site.
A static marketing site may be recoverable from its source files and deployment history. A store or member site also needs current database records, uploads, orders, accounts, and configuration. Restoring last week’s brochure page is inconvenient. Restoring last week’s order database could lose real business records.
Do not assume that a hosting company’s backup and a maintenance provider’s backup are separate. They may be the same copy in the same account. Do not assume that a backup includes email, domain settings, analytics, or third-party booking data merely because those services connect to the website.
Ask one direct question: “If the website disappeared today, what exactly would you restore, from where, and who would do it?”
The answer reveals whether recovery is a practiced process or a hopeful feature label.
4. Accuracy: test what customers rely on
A website can be online, patched, and backed up while still failing the business.
Hours become outdated. A staff member leaves. A service changes. A form silently stops sending. A booking calendar shows the wrong availability. Analytics no longer records completed inquiries. A phone number works on desktop but cannot be tapped on a phone.
Routine functional checks should focus on the paths that matter most:
- Contact and estimate forms
- Phone, email, map, and text links
- Booking or reservation flows
- Payment and checkout paths
- Confirmation messages and notifications
- Analytics and important conversion events
- Search Console warnings and indexing changes
- Mobile navigation and primary calls to action
- Important third-party integrations
Google describes Search Console as a way to monitor, maintain, and troubleshoot a site’s presence in Search, including server, indexing, and security issues. It is useful maintenance evidence, but it does not replace testing the customer journey.
The plan should also state whether content changes are included. Technical upkeep may keep a site functional while every photo, price, biography, and service description grows stale.
Define a content request in ordinary language. Is it one changed sentence, one page, 30 minutes of work, or any collection of edits submitted at once? How many requests are included? Do unused requests roll over? How quickly are routine changes handled?
Without those answers, “updates included” can mean software updates to the provider and content updates to the customer. Both interpretations sound reasonable after the fact. Only one belongs in the agreement.
5. Support: define the human response
Maintenance is partly technical work and partly an agreement about attention.
A useful plan explains:
- How to submit a routine request
- Normal support hours
- The target time for acknowledging a request
- The expected time for common changes
- What counts as urgent
- How an outage or security concern is escalated
- What happens when work exceeds the plan
- Whether third-party vendor coordination is included
- Who receives status updates
Be careful with the phrase “24/7 monitoring.” It may mean an automated service checks the site around the clock. It does not necessarily mean an engineer begins repairs at 2:00 a.m.
Separate response time from resolution time. A provider can promise to acknowledge a request within one business day. The time to solve it depends on the cause, access, third-party vendors, and the amount of work.
The owner should also receive enough evidence to know the plan is active. That does not require a 40-page monthly report. A useful update might show:
- Availability incidents and what happened
- Software or security work completed
- Backup or restoration status
- Form and customer-path test results
- Content requests completed and remaining
- Search, analytics, or performance concerns worth discussing
- Decisions or access the provider needs from the business
Silence should not be the only proof that maintenance is working.
Routine care, requests, projects, and emergencies
Many disagreements happen because four different kinds of work are sold under one word.
Routine care
This is the recurring work required to operate the current site: hosting coordination, monitoring, certificates, relevant software updates, backups, form checks, and account hygiene.
Content requests
These are bounded changes within the existing site: replacing a photo, updating hours, editing text, publishing supplied content, or adding a standard page or section.
Project work
This changes the site’s structure or capabilities: a redesign, new ecommerce system, custom calculator, member area, substantial copywriting, new brand, large migration, or integration with business software.
Emergency work
This responds to an outage, compromise, broken checkout, lost access, or another urgent event. The plan should state whether emergency work is included, limited, billed separately, or unavailable outside business hours.
A good provider can draw those boundaries before the request arrives. “Unlimited changes” often becomes disappointing because neither side knows where maintenance ends and a project begins.
What maintenance does not automatically include
Unless the agreement says otherwise, do not assume a maintenance plan includes:
- Unlimited design or development
- New features and integrations
- Search-engine ranking improvements
- Advertising or social media management
- Copywriting, photography, or video production
- Legal, privacy, accessibility, or regulatory certification
- Support for business email, office computers, or every connected service
- Repair of a pre-existing compromise
- Recovery of accounts the business cannot access
- Guaranteed uptime, perfect security, or instant resolution
Some providers offer these services. They should be named and priced rather than hidden inside a broad promise.
Our website account checklist helps identify the domain, hosting, analytics, email, and recovery access that the business should control before maintenance begins.
Twelve questions to ask before buying a plan
Ask the provider to answer these in writing:
- Which website, domain, hosting account, and connected services are covered?
- Which software is updated, and how are updates tested?
- What does monitoring check, how often, and who receives an alert?
- What is backed up, how often, and how long is it retained?
- When was restoration last tested?
- Which forms, bookings, payments, or integrations are tested?
- Are content changes included, and what counts as one request?
- What are the response targets for routine and urgent issues?
- What work is explicitly excluded or billed separately?
- Who controls the domain, hosting, source files, analytics, and billing?
- What reports or evidence will the business receive?
- What happens to the website, accounts, and backups if the plan ends?
Clear answers are more valuable than a longer feature list.
How often should maintenance happen?
Different duties need different rhythms.
Some checks should be continuous or automated, such as basic availability and certificate monitoring. Security updates may need prompt attention when a serious vulnerability is announced, not a fixed appointment next month. Backups may run daily or more often on a changing database, while a static site can be recovered from every approved deployment.
Forms and key customer paths deserve regular tests and another test after a related change. Content accuracy may be reviewed monthly, quarterly, or whenever the business changes its hours, people, prices, services, policies, or location.
The schedule should follow consequence and rate of change. A restaurant menu, event calendar, or online store changes more often than a five-page professional-services site. A site processing transactions needs closer operational attention than a brochure site with a phone number.
Avoid plans that perform every task on the same arbitrary schedule. Good maintenance responds to the system that exists.
Where Superhero Technologies fits
Superhero’s standard care model is built around websites we host or take on through website maintenance and Site Rescue. That lets us define the environment instead of promising to maintain an unknown collection of themes, plugins, accounts, and servers.
Depending on the plan, care can include hosting, monitoring, backups, and a defined number of website requests. The pricing page is the source of truth for current request allowances, fees, and plan requirements.
That model is not right for every site. A large store, member system, custom application, or website that must remain on a specialized platform needs maintenance designed for that environment. The important part is not forcing every website into the same package. It is making responsibility visible.
Maintenance should make the website less mysterious
The owner should know what is being protected, who is watching it, how it can be restored, how routine changes are requested, and what happens when the work becomes larger or urgent.
That is the standard to use when comparing plans.
Do not buy “peace of mind” as an undefined feeling. Buy a clear operating agreement for availability, security, recovery, accuracy, and support. Then make sure the business still controls the accounts and information it would need if that agreement ever ends.