Skip to main content

Care plan 4 sections Also: legacy modernisation

Website Support
and Maintenance

01

What website support and maintenance covers

Website support and maintenance is the work that keeps a live site safe and working once the build is over. It covers security updates, tested backups, checks that forms and payments still run, and the small changes a business needs month to month. A website is not a thing you finish. It sits on other people's software, and that software keeps moving underneath it.

Where this sits

This page is about looking after a site that already exists. If you need a new one, start at small business web design.

If the system is old enough that maintaining it no longer helps, that is legacy software modernisation.

Paying somebody to look after it, or doing it yourself

Every site needs the same work. The only question is who does it and whether it actually gets done.

General to this kind of project rather than to any one product. No prices, because none are ours to publish.
What to weigh What a support arrangement gives you What it does not cover
Updates They get applied on a schedule by somebody whose job it is. An update can still break something. Being looked after means it gets noticed.
Backups Backups are taken and, more importantly, tested by restoring them. A backup is not a plan. Somebody still has to decide what is worth restoring.
When it breaks There is a named route to somebody who knows the site. It does not make the site never break. Nothing does.
Security Known problems get patched before they are found by somebody else. It cannot protect you from a weak password or a shared login.
Doing it yourself It is entirely possible, and cheaper, if somebody genuinely has the time. The usual failure is not skill. It is that it quietly stops happening.
What it is not Routine care keeps the site healthy and current. New features and redesigns are separate work, and should be quoted as such.

What actually goes wrong when nobody looks after it

None of these are dramatic. They are slow, they are quiet, and they are the reason most rescue jobs arrive.

The software behind it goes out of date

A site runs on a stack of other people's code. Each part gets security fixes. Skip them long enough and the known holes stay open.

We apply updates in a test copy first, check the site still works, then put them live.

The version of PHP it runs on stops being supported

Hosts retire old versions. A site left behind either breaks on the day it is moved, or sits on a version nobody patches.

We track the end of support dates and move the code up before the host forces it.

There is a backup, but nobody has ever restored one

A backup that has never been tested is a hope, not a plan. Plenty of them turn out to be empty or unreadable.

We check that a backup actually restores, rather than only that the job ran.

A payment or delivery connection quietly stops working

Other companies change their systems. A link to a card processor or a courier can fail without anyone on your side being told.

We watch the connections that carry orders and money, and fix them when the other end changes.

Nobody knows who holds the domain or the hosting

The person who set it up has left. The renewal notice goes to an inbox no one reads. The site disappears on renewal day.

We write down where every part lives and who controls it, and we hand you that list.

A site that is stable and rarely changes needs less of this than a shop taking orders every day. The right amount of care is not the same for every site.

02

Websites and applications need different care

Most website maintenance sold in the UK is a WordPress care plan. That is a real service and it suits a lot of sites. It does not cover a custom application, because there are no plugins to update.

What needs updating

WordPress itself, the theme and every plugin. Each has its own author and its own release schedule.

The framework and the libraries it uses. There is no plugin list, so somebody has to read the code.

What breaks a change

Two plugins that disagree, or a theme that was edited directly instead of through a child theme.

A business rule that quietly stops matching how the company now works, which no update will flag.

How you test it

Update in a copy, click through the pages that matter, then repeat it on the live site.

Run the automated tests, then check the paths that carry money or data by hand.

Who can pick it up

Many people. The platform is common and most agencies know it.

Someone who can read the language and the framework. That is a smaller pool, and it is worth knowing that before you need one.

We build in Laravel and PHP and we work in WordPress, so we can look after either. If your site is on a platform we do not work in, we will tell you rather than learn it at your cost.

03

Taking on a site somebody else built

Plenty of this work starts with a site we have never seen, built by somebody who is no longer around. That is normal, and it is a job we take on.

We start by reading the site and its hosting rather than guessing at them. That means the code, what it runs on, what has been changed by hand, whether backups exist and whether anything is already broken. It is a review, not a sales call.

You get the result in plain writing. What the site runs on, what state it is in, anything we think is a genuine risk, and what we would do first. If two of those things are urgent and the rest can wait, the summary says so.

The answer you might not want

Sometimes a site has drifted so far behind that maintaining it costs more than replacing it, and keeps costing. We will say that plainly when we find it. Charging a monthly fee to hold together something that needs rebuilding does you no favours.

Handover matters as much as the work. You should know where the site is hosted, who owns the domain, where the code lives and who receives the renewal notices. We write that list down and give it to you. A surprising number of businesses do not have it, and it is the thing that hurts most when someone leaves.

If the system is business software rather than a website, the same thinking applies through bespoke software development and API integration services.

04

Common questions

How much does website maintenance cost?
It depends on what the site is and how much of it we look after. A small brochure site with a handful of pages is not the same job as a shop taking orders, or an application with logins and its own database. The other question is how much change you want included each month. We look at the site first, agree what is covered and what is not, then price that. You are agreeing to a defined scope rather than an open hourly rate.
How often does a website need maintenance?
Security updates should be applied as they are released, not saved up. Most other checks suit a monthly rhythm. That covers backups, broken links, forms still sending and any warning the site is producing. Some things are yearly, like the version of PHP the site runs on and the renewal dates for the domain and certificate. A site left completely alone for a year is usually a bigger job to rescue than it would have been to maintain.
What happens if I do not maintain my website?
Usually nothing, right up until it matters. The common outcomes are a security hole left open long enough for someone to find it, a form that stopped sending and lost you enquiries nobody counted, or a host retiring the software version your site needs. The expensive version is a site that has drifted so far behind that updating it safely is a rebuild. Small regular work is cheaper than the recovery.
Can you take on a website you did not build?
Yes, and a good share of this work is exactly that. We start by reading the code and the hosting rather than guessing. That tells us what it runs on, what state it is in and what has been changed by hand. You get that back as a plain written summary, including anything we think is a real risk. If we believe the honest answer is that it needs replacing rather than maintaining, we will say so.
Do you maintain bespoke applications as well as WordPress sites?
Yes, and they are different jobs. A WordPress care plan is mostly about core, theme and plugin updates. A bespoke application has its own code, its own database and its own connections to other systems, so there are no plugin updates to apply. It needs someone who can read the code, follow the framework as it changes and test that the business rules still behave. We build in Laravel and PHP, so we maintain them too.
Is hosting part of it?
It can be, but it does not have to be. Some clients want us to hold the hosting so there is one place to go when something breaks. Others already have a host they are happy with, or an internal team who own it. We work either way. What matters more is that somebody has written down where the site lives, who controls the domain and who receives the renewal notices. That list is often the thing missing.
What is the difference between support and maintenance?
Maintenance is the planned work that keeps a site healthy. Updates, backups, checks and the small fixes nobody asked for. Support is what happens when you need something: a page changed, a fault reported, a question answered. Most businesses want both, which is why they are usually sold together. It is worth agreeing which of the two you actually need, because a site that is stable and rarely changes needs far less of the second.

Every question we get asked, in one place

Next step

Tell us what your site is running on

Send us the address and whatever you know about who built it. We will look at it and tell you what it actually needs.

  • Pontefract, West Yorkshire
  • Building for businesses across the UK
  • Reply within 1 working day