A website doesn’t stay in the state you left it. The underlying software (the CMS, themes, plugins, and platform libraries) is updated regularly by their developers, often to patch security vulnerabilities that have been discovered since the last release. Without someone managing those updates, a site gradually accumulates risk.

Security issues are the most visible concern, but they’re not the only one. Plugins that haven’t been updated may conflict with newer versions of the CMS. Performance can degrade as the gap between installed and current versions widens. Small problems that would be easy to catch with regular oversight compound into larger ones that are harder to fix.

A care plan addresses this through a structured approach to ongoing management rather than reactive emergency work.

What ongoing maintenance actually covers

Software updates are the most routine part of care plan work. For a WordPress site, this means keeping core, themes, and plugins current, not just accepting every update automatically, but checking compatibility, testing changes where appropriate, and being ready to respond if an update causes an issue. Critical security patches are applied as soon as they’re released; routine updates are handled on a regular schedule.

Monitoring means having visibility into what’s happening with the site rather than finding out about problems when a client or visitor reports them. Uptime monitoring alerts when a site goes down. Security scanning can identify suspicious file changes or known vulnerability signatures before they become active problems.

Backups are covered separately in more detail in Why every website needs a backup plan, but they’re an essential element of any care plan. The key points: backups should run automatically, they should be stored off the live server, and they should be tested periodically to confirm they actually restore correctly.

Reporting ties everything together: a regular summary of what has been done, what was found, and the current state of the site. That record is useful if something goes wrong later, and it makes the ongoing work visible rather than invisible.

The difference a care plan makes when things go wrong

No maintenance approach prevents every problem. Servers have hardware failures. Hosting providers have outages. A plugin update can cause a conflict that wasn’t caught in testing. The question is how quickly you can recover.

When a site is on a care plan with current backups and documented configuration, restoration from a problem is typically measured in hours. When a site has been unmonitored, the same event can mean rebuilding from scratch, digging through old files, recreating settings, re-entering content, or discovering that the most recent restorable state is months out of date.

The GoDaddy DNS outage in 2012 took down millions of sites simultaneously. More recently, vulnerabilities in widely-used WordPress plugins have required immediate patching to protect sites before exploits were circulated. In both cases, the outcome for individual sites depended largely on whether someone was watching and had a restore path ready.

What reactive management typically costs

The calculation for care plans is worth making honestly. The monthly cost of ongoing management is predictable and relatively small compared to the cost of emergency work.

Emergency development work (diagnosing a problem at short notice, restoring a site, or rebuilding content that was lost) typically bills at a higher rate and often takes longer than it would under planned conditions. Beyond that, there’s the business cost of being offline or compromised: lost enquiries, reputational damage with visitors who arrive at a broken or hacked site, and the time spent managing the situation.

A care plan replaces that uncertainty with a consistent, known overhead.

Starting a care plan on a site of unknown state

If you’ve been managing a site reactively, or inherited one without documentation, the current state of the software, security, and configuration may not be clear. Starting a care plan on a site with unresolved issues means maintaining problems rather than preventing them.

A Pre-Care Plan Health Check addresses this by reviewing the site before ongoing work begins. It looks at four areas:

Design and construction

Whether the site's build quality is solid, including theme structure, plugin choices, and how the site is put together under the hood.

Issues and known problems

Any existing errors, broken links, plugin conflicts, or functionality problems that need resolving before maintenance begins.

Performance

Page speed, image handling, script load, and hosting behaviour. Problems here affect both user experience and search visibility.

Security

Software versions, known vulnerabilities, user account hygiene, and any signs of previous compromise.

The findings are delivered as a PDF report with action points, so you have a clear picture of what needs resolving and in what order. From there, a care plan can begin from a documented, understood baseline rather than an unknown one.

The Pre-Care Plan Health Check is a one-off service, priced at £195.

Tired of reactive fixes and surprise costs? See ongoing support options →