Maintenance is more than clicking Update once a month. A good provider should know what is being changed, have a recovery route if an update fails and be clear about what the recurring fee does and does not include.
Keep WordPress, plugins and themes sensibly current
Updates often contain security fixes and compatibility changes. They should be reviewed and applied on a sensible schedule rather than ignored indefinitely. On higher-risk sites, major changes may need staging or additional testing before they reach the live site.
Have a backup that can actually be restored
A backup is only useful if it includes what is needed to recover the site and is not stored solely inside the same failed environment. The provider should know the backup frequency, retention and restore process.
Check the website after routine updates
Look at the important pages, forms, checkout/booking flow and obvious frontend errors after updates. Automated tools are helpful, but a business-critical function can fail while the homepage still appears perfectly normal.
Monitor security, uptime and server compatibility
Maintenance should include sensible security hygiene, uptime monitoring and awareness of PHP/server compatibility. It is not possible to promise a WordPress site will never be hacked, but leaving known vulnerabilities and unsupported server software unattended is avoidable risk.
Be clear about content changes and development
Routine maintenance and content work are not the same service. At Smarter Search, hosted WordPress maintenance covers the standard technical care; changes such as new text, images, pages, products or bespoke functionality are charged separately at £30/hour with a 30-minute minimum.
Let the client own important licences where practical
Premium plugins and themes may have annual licence fees. We generally prefer clients to pay those licences directly where practical, so the business keeps clear ownership and avoids unnecessary mark-up. There are cases where we manage licences for a client, but the arrangement should be transparent.
You should be able to ask what was done
If a provider cannot explain what your maintenance fee covers, when updates were last handled or what happens after a failed update, that is a reasonable concern. You do not necessarily need a monthly PDF report, but you should not be paying indefinitely for an undefined service.
What maintenance cannot guarantee
No responsible provider can promise that a public WordPress site will never be hacked, never go offline or never encounter a plugin conflict. The value of maintenance is reducing avoidable risk, detecting problems sooner and having a tested recovery route. Be cautious of absolute security guarantees or claims that a particular plugin makes a site “unhackable”.
Maintenance should fit the site
A small brochure site and a WooCommerce store should not be maintained identically. A shop may need more frequent backups, checkout testing and careful handling of live orders. A membership site may need login/subscription checks. A custom plugin may need developer involvement before major updates. The maintenance scope should follow the business risk, not simply the number of plugins installed.