What should a WordPress maintenance plan include?

What should a WordPress maintenance plan actually cover? Updates, tested backups, monitoring, reporting, incidents and what is usually left out.

Open a support ticket

A WordPress website is not finished the day it goes live. WordPress itself, plugins, themes and the server underneath keep changing, and every change carries a small risk.

A maintenance plan is the routine that manages that risk. It decides who updates what, how often, how changes are checked and what happens when something goes wrong.

The difficulty is that "maintenance" can mean very different things. For one provider it means clicking "update all" once a month. For another it means tested updates, verified backups, monitoring and a clear response when the website stops working. Both can be called a maintenance plan.

If you are comparing offers, renewing a contract or simply trying to understand what your website needs, it helps to know what a good plan normally includes and what it usually does not.

This guide explains the main parts of a WordPress maintenance plan, what each one protects, what is often left out and which questions to ask before you choose a provider.

What is a WordPress maintenance plan?

A maintenance plan is a set of recurring activities that keep a website working, secure and recoverable over time.

It is different from a one-off repair. A repair starts when something is already broken. Maintenance happens on a schedule, so that fewer things break and, when they do, the damage is smaller and easier to undo.

A good plan usually covers four areas:

  • updates: keeping WordPress, plugins, themes and PHP current
  • recovery: making sure a working copy of the website can be restored
  • monitoring: noticing problems before customers do
  • communication: telling you what was done and what needs attention

The exact mix depends on the website. A small brochure site and a busy online store do not need the same level of care, but both need the four areas in some form.

Why does it matter?

Most WordPress problems do not appear out of nowhere. They usually follow a change: an update, a new plugin, a server change or an expired component.

Without a routine, two things tend to happen:

  • updates are postponed for months, then applied all at once, which makes it hard to tell which one caused a problem
  • nobody checks whether the backups actually work until the day they are needed

A maintenance plan does not guarantee that nothing will ever go wrong. What it does is make problems less likely, easier to diagnose and quicker to recover from.

Which updates should be included?

Updates are the most visible part of maintenance, but "updates included" can hide very different approaches.

WordPress core

WordPress releases minor versions, mostly security and bug fixes, and major versions with new features. Minor updates are usually applied automatically by WordPress itself. Major updates deserve more care, because they can affect older plugins or custom code.

Plugins

Plugins are where most compatibility problems start. A plan should explain how plugin updates are handled: all at once or one at a time, automatically or manually, tested first or applied directly on the live website.

Security updates should be applied quickly. Other updates can follow a regular cadence. The guide on how often to update WordPress plugins explains this in more detail.

Themes

Theme updates can overwrite changes made directly to the theme files. A good plan checks whether the website uses a child theme and whether any customization could be lost.

PHP

PHP is the programming language WordPress runs on. Hosting providers retire old PHP versions over time, and running an unsupported version is a security risk.

PHP changes are often forgotten because they happen at the hosting level, not inside WordPress. A maintenance plan should at least monitor which PHP version the website uses and plan upgrades before the hosting provider forces them.

How are updates checked?

This is the question that separates a careful plan from a basic one.

Ask whether updates are:

  • tested on a staging copy before being applied to the live website
  • applied one at a time or in groups
  • followed by a check of the most important functions, such as forms, login and checkout
  • reversible, with a recent backup taken just before

For websites that sell, take bookings or manage members, testing updates first is usually worth the extra effort. The guide on testing WordPress updates on a staging site explains when and how.

What should the backup part cover?

"Daily backups" sounds reassuring, but a backup is only useful if it can be restored.

A good plan should explain:

  • what is backed up: files, database or both
  • how often: daily, more often, or in real time for busy stores
  • where backups are stored: ideally away from the same server as the website
  • how long they are kept: a few days or several weeks
  • who can restore them and how long a restore normally takes
  • whether restores are tested, not just whether backups are created

For an online store, the frequency matters more. A daily backup restored at 6 pm could lose a whole day of orders. That is why stores often need more frequent or continuous backups, and a careful plan for how to restore without losing recent data.

Testing a restore, even occasionally, is what turns a backup from a hope into a safety net.

What does security monitoring involve?

Security in a maintenance plan is usually about prevention and early detection, not about guaranteeing that a website can never be attacked.

It may include:

  • applying security updates quickly
  • scanning files for known malware or unexpected changes
  • watching for new administrator accounts
  • limiting login attempts or protecting the login page
  • a firewall or security service in front of the website
  • checking whether Google or other services have flagged the website

Ask what happens when a scan finds something. Some plans only send an alert. Others include an investigation. Malware cleanup is often a separate service, so it is worth knowing in advance.

Why is uptime monitoring useful?

Uptime monitoring checks, at regular intervals, whether the website responds. If it does not, someone receives an alert.

Without it, the first person to notice a broken website is often a customer, sometimes hours later.

Useful questions:

  • how often is the website checked?
  • who receives the alert: you, the provider or both?
  • does monitoring check only the home page, or also important pages like checkout or login?
  • what happens after the alert?

Monitoring on its own does not fix anything. It only shortens the time between a problem starting and someone knowing about it.

Should performance checks be part of it?

Websites tend to slow down over time. Plugins add scripts, images get heavier, the database fills with old data and caches stop working as expected.

A maintenance plan can include periodic checks such as:

  • page loading times on key pages
  • database cleanup of old revisions, expired temporary data and leftover tables
  • checking that caching works correctly
  • spotting plugins that have become heavy or unnecessary

Deep performance optimization is usually a separate project. Regular checks help you notice when that project becomes necessary.

What kind of reporting should you expect?

Reports are how you know the work is actually happening.

A useful report is short and readable. It may include:

  • which updates were applied and which were postponed, with the reason
  • backup status and the date of the last successful backup
  • any downtime and how long it lasted
  • security findings
  • recommendations, such as replacing an abandoned plugin or upgrading PHP

A report that only says "all good" every month tells you very little. A report that explains what was skipped and why is far more useful.

What happens when something goes wrong?

This part is often vague, and it is the one that matters most on a bad day.

A plan should explain:

  • how you report an incident: ticket, email, phone
  • whether incidents caused by maintenance work are fixed as part of the plan
  • whether other incidents, such as a hack or a hosting failure, are included or handled separately
  • what the provider does first: restore a backup, roll back an update or investigate

Do not expect a plan to cover every possible emergency without limits. But you should know, before you need it, what is included and what will be treated as extra work.

Who has access to the website?

Maintenance requires access: the WordPress dashboard, the hosting panel, sometimes the server, DNS or a CDN.

It is worth agreeing:

  • that the provider uses its own named accounts, not a shared admin login
  • that passwords are never exchanged by email
  • that access is removed when the contract ends
  • who else has administrator access, such as former developers or agencies

Old accounts that nobody uses are a common security weakness. A maintenance plan is a good moment to clean them up.

What is usually not included?

Many disagreements come from different expectations about what "maintenance" covers.

Items that are often outside a standard maintenance plan:

  • new features, pages or design changes
  • building or rewriting custom code
  • content updates, such as editing pages or uploading products
  • full redesigns or migrations to a new hosting provider
  • major version upgrades that require development work
  • malware cleanup after a hack, in some plans
  • fixing problems caused by changes made by someone else

None of this is a problem in itself, as long as it is clear. This is often where an hours-based support plan or individual tickets fit alongside maintenance. The guide on maintenance plans versus on-demand support compares the two.

Common mistakes when choosing a plan

  • choosing only on price, without checking what is actually done
  • assuming backups work because they exist
  • accepting automatic "update everything" with no testing for a store or membership website
  • having no clear answer to "what happens if an update breaks the site?"
  • leaving PHP and hosting out of the picture
  • not knowing who has access to the website

Which questions should you ask a provider?

Before signing, ask:

  1. Which updates do you apply, how often and how are they tested?
  2. Do you use a staging copy before updating the live website?
  3. What is backed up, how often, where is it stored and how long is it kept?
  4. Have you tested restoring a backup of this website?
  5. How is the website monitored, and who receives the alerts?
  6. What happens if an update breaks something?
  7. Which incidents are included and which are billed separately?
  8. What do your reports contain?
  9. How do you manage access and passwords?
  10. What happens to backups and access if we stop working together?

The answers do not need to be perfect. They need to be clear.

What does good maintenance look like?

In practice, good maintenance is quiet. Updates happen regularly and rarely cause surprises. Backups exist, are stored safely and have been restored at least once. Problems are noticed early. You receive a short report and you know who to contact when something is wrong.

How D4Hub can help

D4Hub can help you set up maintenance that fits your website, or review what you already have.

Depending on your needs, D4Hub can:

  • review your current maintenance and point out gaps
  • check WordPress, plugin, theme and PHP versions
  • verify that backups exist and can actually be restored
  • set up uptime monitoring
  • apply and test updates, with a staging copy where it makes sense
  • identify abandoned or risky plugins
  • clean up old administrator accounts and access
  • provide continuous maintenance through MAP, or hours-based support through a support plan
  • handle one-off requests through a ticket when something comes up

You can ask for support at any stage, whether you are comparing offers or already have a plan and want a second opinion.

Open a support ticket

For hands-on users: a maintenance self-assessment

You do not need to change anything to complete this checklist. It is a way to see what your website currently has and what is missing. If you do decide to change something, take a backup first.

Check versions

From the WordPress dashboard, open Tools > Site Health > Info and note the WordPress version and the PHP version under the Server section.

If you use WP-CLI, the same information is available with:

wp core version
wp --info
wp plugin list --update=available
wp theme list --update=available

Write down how many plugins and themes have updates waiting.

Check backups

Answer these questions honestly:

  1. When was the last successful backup?
  2. Does it include both files and the database?
  3. Is it stored somewhere other than the website's own server?
  4. When was a backup last restored, even as a test?
  5. Who knows how to restore it?

If you cannot answer question 4, your backups are untested.

Check monitoring

  1. Would you know within minutes if the website stopped responding?
  2. Who would receive the alert?
  3. Is anything checking the checkout, login or forms, not just the home page?

Check access

In Users, filter by the Administrator role and list every account. For each one, ask whether that person still needs access. Do not delete accounts until you know whether they own content or are used by an integration.

Score the result

Give yourself one point for each item you can confirm:

  1. Updates applied in the last month
  2. PHP version still supported by your hosting provider
  3. Backups stored off the server
  4. A restore tested in the last year
  5. Uptime monitoring active
  6. Every administrator account known and needed
  7. A clear contact for incidents

If you score below five, your website would benefit from a more structured maintenance routine.

FAQFrequently asked questions

It needs maintenance, but not necessarily a heavy plan. Even a simple website runs plugins and a theme that need updates, and it can be hacked or go offline.

For a small website, regular updates, reliable backups and basic monitoring are often enough.

No. Automatic updates help with keeping software current, but they do not test the result, verify backups, monitor the website or respond to incidents.

It depends on how often the website changes. A website edited once a month needs fewer backups than an online store that receives orders every hour. The key question is how much data you could afford to lose.

Not usually. Many hosting providers maintain the server and may offer backups, but they do not normally test plugin updates or check that your checkout still works. Ask your hosting provider exactly what they cover.

Maintenance is scheduled care to keep the website working. Support is help when you need something done or fixed. Many websites benefit from both.

Yes, with some preparation. Make sure you have a recent backup, a list of all accounts and access, and know where the domain, hosting and DNS are managed before the change.

Related resources

Related services and technologies