What is WordPress maintenance, and who is it for?
WordPress maintenance is ongoing work that keeps a live site up to date, backed up and secure. I offer it as a maintenance plan: I test updates first, take regular backups, stay on top of security checks and fix any problems the updates cause. That way, you can focus on your business.
This service is for businesses that rely on their corporate website or WooCommerce store for customers and orders but don’t want to deal with updates. Your site doesn’t have to be one I built. I also maintain sites that someone else set up.
There’s no fixed package. The fee depends on how your site is built and what the maintenance covers. I confirm the exact scope and fee after I’ve taken a technical look at your site and we’ve talked it over in writing.
What does WordPress maintenance cover?
- Tested updates: Themes, plugins and major WordPress releases. First a backup, then a test copy, and only then the live site.
- Backups and restore tests: Regular backups, a copy stored off the server and a check that the site can really be restored from a backup.
- Security checks: Tracking security updates and known vulnerabilities, spotting abandoned plugins and reviewing admin accounts.
- PHP version tracking: Planning the upgrade before your server’s PHP version runs out of support, and testing your theme and plugins for compatibility first.
- Downtime monitoring: I get an automatic alert when your site can’t be reached.
- Small content edits (optional): Tasks like changing a phone number, a bit of text or an image can be added to the plan.
- Maintenance report: What was updated, the state of your backups, anything that caught my attention and my recommendations.
Why does putting off website maintenance cost more?
Skipped updates pile up. Small steps that should happen regularly turn into one big, risky jump. WordPress 7.0 dropped support for PHP 7.2 and 7.3. Sites still on those PHP versions are stuck on WordPress 6.9 and don’t get new WordPress releases automatically. Yet WordPress officially supports only its latest version.
Most of the risk comes from plugins. According to Patchstack’s 2026 report, 11,334 new security vulnerabilities were recorded in the WordPress ecosystem in 2025. Of those, 91% were in plugins, and only 6 were found in WordPress itself.
If your site gets hacked, Google may add a “This site may be hacked” warning next to it in search results. The cleanup is a separate job from maintenance, and a much harder one. Some problems are quieter. A contact form that stops working after an update can cost you customers until someone notices.
How I handle maintenance
Before maintenance starts: an initial check
The first thing I do is go through your whole site. I note which theme and plugins are installed and which ones no longer get updates. I also check the PHP version, where the backups are kept and who holds the logins and premium licenses.
If this check turns up a serious problem, we deal with it separately before maintenance begins. A white screen, a broken form or a half-finished setup falls under WordPress error fixing.
How I test WordPress updates
An update breaking the site is the part of maintenance people fear most. So for theme, plugin and major version updates, I follow the same order every round:
- Before updating, I take a full backup of the files and the database.
- I read the release notes, then apply the updates to a test copy of the site first (a staging site).
- If the test copy has no problems, I apply the same updates to the live site.
- Then I check the contact forms, the cart and checkout steps if you have them, and your most important pages one by one.
- If something doesn’t work as expected, I roll the plugin or theme back to its previous version, or restore from the backup if needed. I solve the problem on the test copy, not on the live site.
By default, WordPress installs its minor security releases automatically, and that’s a useful feature. But on a business site, I don’t think plugin and theme updates should run with no backup, no testing and nobody watching.
A backup only counts if it can be restored
Many sites have a backup plugin installed, but nobody has ever tried restoring one of its backups. WordPress’s official guide to updating also recommends taking a backup before you update and verifying it.
Backups from your hosting company are valuable, but they aren’t enough on their own. They often sit on the same server as your site, are kept for a limited time and are rarely tested with a restore. I follow the 3-2-1 rule: three copies (including the live site), on two different types of storage, with one copy off the server. At regular intervals, I restore a backup to a test environment and check that the site actually loads.
PHP versions and abandoned plugins
Maintenance is more than clicking “Update.” PHP, the software that runs your site on the server, has a lifespan too. Each version gets two years of active support, then two years of security fixes only, and after that no updates at all. As of September 2026, PHP 8.1 and older are out of support, and WordPress recommends PHP 8.3 or higher. Upgrades don’t always go smoothly, so I test your theme and plugins with the new version on the test copy first.
Then there are plugins that nobody develops anymore. The WordPress.org plugin directory shows a warning on plugins that haven’t been tested with the last three major WordPress releases. When I come across one, I let you know and suggest what could replace it.
Maintenance for WooCommerce stores
After a WooCommerce update, I check that the database update has finished and whether your theme uses outdated WooCommerce templates. Then I place a test order to try the cart and checkout from start to finish. Restoring a full backup could wipe out orders placed in the meantime, so if something goes wrong, I first roll back only the plugin that caused it. WooCommerce e-commerce websites are one of my core areas of expertise.
What isn’t included in the maintenance plan?
I don’t like surprise invoices, and I doubt you do either. If one of my updates causes a problem, fixing it is part of maintenance. Errors that were there before maintenance started are a separate job. So are new faults that have nothing to do with updates. The same goes for fixing custom code or replacing a plugin that turns out to be incompatible with a PHP upgrade. Beyond that, the maintenance plan doesn’t cover:
- New pages, new sections or a redesign
- Adding new features, forms, integrations or payment methods
- Cleaning up a hacked site, which is a separate job under WordPress error fixing
- Large-scale content entry and bulk product uploads
- Premium theme and plugin license fees. The licenses stay in your name, and I remind you when they’re up for renewal
- Server and hosting failures
- In-depth speed work. There’s a separate WordPress speed optimization service for that
When I see a need like this, I write to you first and give you the scope and fee separately. No work starts without your approval.
What determines website maintenance costs?
No two WordPress sites need the same maintenance. These are the things that affect the fee most:
- The number and type of plugins, especially paid and custom-built ones
- Whether the site is a WooCommerce store
- Whether the theme or the site has custom code
- Whether a test copy (staging environment) is already set up
- How often updates and checks are done
- Whether small content edits are part of the plan
- The state the site is in when maintenance starts
You can briefly describe your site and its maintenance needs in the free quote form, and I’ll get back to you within one business day. We settle how often maintenance happens, how it’s billed and the exact fee together after the initial check.
Who handles your maintenance?
I do. I’m Utku Sakallıoğlu, a freelance web designer and developer based in Ankara, Türkiye. You always deal with the same person: I answer your questions and follow the work from start to finish. I keep all communication in writing, over WhatsApp, email or the contact form. My About page explains why I only communicate in writing and how I work.
When your site goes down, the monitoring tool alerts me. I work alone, so I’m not on call around the clock like a support team. But when an alert comes in, I look into it as soon as I can. As long as your site is live, I’m here too.