
Photo: Towfiqu barbhuiya
Launch is not the end of a WordPress site. Core, the theme, and plugins keep moving. Comments fill with casino ads. Hosts get probed. A maintenance plan is just a named list of boring jobs, done on a rhythm, so you are not paying an emergency clean-up later.
This is the plan I use for a typical business brochure site. A shop needs more. DIY is allowed if you actually do it.
It pairs with what a WordPress site really costs — care is bucket five.
What “maintenance” is not
- New pages, new Figma, new features (that is a project)
- Writing blog posts for you
- “Unlimited support” for every idea at 11pm
If the retainer mixes care and endless design, nobody knows what they paid for. Split them.

Photo: FlyD
1. Updates (monthly, sometimes weekly)
Three layers: WordPress core, theme / Elementor, plugins. Security releases should not wait for “someday.” Feature updates can wait until a backup exists and someone can click around the homepage.
Good habit:
- Backup first
- Update on staging if you have it, or on a quiet hour
- Check home, contact form, shop checkout if you have one
- Note what changed in a one-line log
“Never update” is how sites get owned. “Update everything at once after two years” is how sites break in one afternoon.
2. Backups (before you need them)
You want files + database, off the same server. Hostinger snapshots help. A plugin like UpdraftPlus to Google Drive / S3 is a second copy. Test a restore once a year. An untested backup is a rumour.
Keep at least a few days of history. One overwrite of a hacked site is a sad story.

Photo: Sasun Bughdaryan
3. Security (boring on purpose)
- HTTPS, strong admin passwords, 2FA if the client will use it
- Few Administrator users; editors should not install plugins
- Firewall plugin (Wordfence, Solid Security, or host WAF)
- Limit login attempts; hide nobody-famous usernames if you can
- Remove unused plugins and themes (they still get scanned)
Brute-force blocks and Application Passwords (for tools like WPVibe) sometimes fight each other. Turn the right Wordfence toggle on; do not disable the whole firewall.
4. Spam comments
Pending queues fill with Russian housing ads, casino copy, and fake “great post.” A plan should:
- Turn on Akismet, or a CAPTCHA, or both
- Close comments on old posts if you do not need them
- Mark junk as spam, then empty spam (do not leave 200 sitting there)
- Not delete real approved comments by accident
This is five minutes a week on a quiet site, or a flood if you leave comments open on every page with no filter.
5. Uptime and leftover chores
- Is the site loading? (UptimeRobot, host monitor)
- Is the contact form still emailing? SMTP keys expire
- PHP version not ancient
- Disk not full of backups of backups
- SSL not expired
A one-page monthly checklist
- Backup confirmed (or run one)
- Update core / plugins / theme; smoke-test the site
- Scan or glance at Wordfence / host security mail
- Empty spam and pending junk
- Click the contact form once
- Note anything broken for the client
Who should do it
You: if you like clicking updates and you have a calendar reminder. The host: some “managed” plans patch core; they still will not design your header. A retainer: if the site makes money or holds customer data and you do not want to think about it.
Typical light retainer: a small monthly fee for the list above, extras billed as projects. That is cheaper than a rebuild after a defacement.
Maintenance is not exciting. That is the point. Photos via Unsplash.

