WordPress maintenance services for UK businesses.
Plugin and core updates tested in staging, security hardening, weekly-to-daily backups, uptime monitoring, and small edits. From £49/mo. Cancel anytime.
Why WordPress needs active maintenance
WordPress powers around 40% of the web. That is also why it is the most-attacked CMS on the planet, why the plugin ecosystem generates a steady stream of security patches, and why "the site was fine last week" is such a familiar phrase in support tickets. WordPress maintenance services in the UK exist because leaving a WordPress site to fend for itself is a plan for eventually paying a much larger recovery bill.
Our care plans specifically for WordPress cover the operational work most owners silently accumulate as debt: plugin updates that never get tested, backups that never get verified, admin passwords that get set once and never rotated, security scans that never happen. Every plan is billed monthly, no lock-in, cancel anytime with 14 days notice. This page covers what is included, how the update process works, security hardening, tier pricing, and what to do if you have decided WordPress itself is no longer serving you.
What is included in WordPress maintenance
Every WordPress care plan includes the following as standard, with tier-based differences on frequency and time budgets:
- WordPress core updates. Every core release patched within days of stable release, always after staging verification.
- Plugin updates. Every plugin update ran through staging before production. Full changelog in the monthly report.
- Theme updates. Parent theme and child theme updates handled, with any custom modifications preserved.
- Off-site backups. Weekly on Care, daily on Care Plus and Care Pro. Stored on separate infrastructure from your live site.
- Weekly security and malware scans. Known signatures, injected scripts, backdoors, vulnerable plugin versions.
- SSL certificate renewal and monitoring. Automatic renewal, alerts before expiry.
- Uptime monitoring. Every minute from multiple locations, alert to us within seconds if the site goes down.
- Broken link and form checks. Monthly automated check for 404s, 500s, and broken contact forms.
- Small content edits. 30 minutes on Care, 2 hours on Care Plus, 4 hours of dev time on Care Pro, monthly.
- Monthly report. Plain English, forwardable to a stakeholder or client, showing exactly what we did.
Anything outside this scope (new pages, feature builds, major redesigns, e-commerce migrations) is quoted separately with a fixed price before work begins. No surprise invoices.
How plugin and core updates actually work
This is the part that separates a real maintenance service from a shortcut one. Most agencies enable auto-updates in production and hope. When something breaks, the first anyone hears about it is a customer emailing to say the checkout stopped working, or Google Search Console reporting a spike in 5xx errors.
Our update process:
- Staging pull. The current live site is cloned to a staging environment (separate URL, same code, real database).
- Updates applied on staging. Core, plugin, and theme updates applied to staging first.
- Automated checks. Site still loads, homepage renders, key template pages render, contact forms accept submissions, no PHP errors, layout has not shifted.
- Manual eyeball. A human clicks through the top-traffic pages to catch anything the automated checks miss.
- Push to production. Only if staging passes. If anything breaks in staging, the update is held, the incompatibility investigated, and either the plugin is patched, replaced, or the issue is worked around before pushing.
- Post-push verification. Site checked live within 30 minutes of the push.
- Report entry. Every update logged in the monthly report with plugin name, version bumps, and any notable changes.
Security hardening for WordPress
WordPress is attacked constantly. Not because it is uniquely vulnerable, but because the surface area is enormous: 60,000+ plugins from thousands of developers, most on autopilot updates, running on servers with wildly varying configurations. Standard hardening included in every care plan tier:
- Admin login rate limiting. Failed logins trigger progressive lockout so brute-force attacks stop being viable.
- Admin username hardening. Default "admin" accounts renamed, weak usernames flagged.
- Two-factor authentication enabled on WordPress logins where you want it (recommended for admin users).
- File permission audit. World-writable directories fixed, config file permissions locked down.
- WordPress version disclosure disabled so attackers cannot easily fingerprint your specific version.
- XML-RPC access restricted or disabled depending on whether you use it, since it is a common attack vector.
- Weekly malware scans. Known signatures, injected script tags, unusual file changes in core directories.
- Google Safe Browsing monitoring so we know if the site gets flagged before your visitors do.
Higher tiers add real-time monitoring, faster response SLAs, and proactive intrusion detection.
WordPress care plan tiers
All three of our care plan tiers work with WordPress. Which one fits depends on how much your site earns, how much downtime hurts, and how often it needs edits.
Care
Weekly backups, plugin/core updates, uptime monitoring, security scans, 30 min edits/mo, 2-day response. Brochure sites, blogs.
Care Plus
Daily backups, real-time alerts, performance audits, 2 hours edits/mo, 24-hour response. Lead-gen sites and small e-commerce.
Care Pro
Real-time monitoring, staging environment, 4-hour emergency SLA, 4 hours dev/mo, direct WhatsApp line. Revenue-critical sites.
Full tier comparison and pricing in GBP, USD or PKR on the website care plans page. Every tier is month to month, cancel anytime with 14 days notice, 30-day money back on the first month.
What happens when something breaks
Emergency response is the reason care plans exist. Response window depends on your tier: 2 business days on Care, 24 hours on Care Plus, 4-hour emergency SLA on Care Pro (any time, weekends included). Order of operations when a site goes down is always: contain the issue, get the site back online (usually by rolling back to the last known-good backup), then work out root cause, then make sure it does not happen again.
For hacked sites specifically, cleanup is available as a one-off engagement regardless of whether the site is currently on a care plan. After cleanup, most clients move onto Care Plus or Care Pro to prevent recurrence, since the same unpatched plugin that let attackers in the first time will let them in again if nothing changes.
Sick of updates? A hand-coded alternative.
Some clients arrive already exhausted by WordPress. Forty plugins accumulated over five years, each renewing annually, each shipping updates that occasionally break the site. If that is you, the honest answer is not always another care plan. Sometimes it is a rebuild.
Hand-coded sites do not have plugins. No plugin update schedule. No compatibility issues between plugin A and plugin B. No annual licence renewals stacking up. No page builder overhead making the site slow. Trade-off: content edits need us or a proper CMS layer, not a drag-and-drop editor. Most owners never touch design after launch, so the constraint is theoretical for the majority of clients.
When to consider a rebuild instead of a care plan:
- WordPress site is more than 5 years old and running dozens of accumulated plugins
- You have already been hacked once, or hosting has suspended you for security issues
- Page speed is consistently poor and plugin optimisation has hit diminishing returns
- You never actually use the WordPress editor because you email us for changes anyway
- Annual plugin licence costs are approaching what a rebuild would cost
When to stay on a care plan instead:
- The site works fine and just needs maintenance
- You (or a team member) actively use WordPress for regular content publishing
- You depend on specific WordPress-only integrations (WooCommerce, learning platforms, membership tools) that would be expensive to replace
- Budget for a rebuild is not there right now
The right answer depends on your specific site. We start with a free technical audit and give you an honest recommendation either way, care plan or rebuild, with numbers attached so you can decide.
See hand-coded website designCommon questions
Do you take on WordPress sites you did not build?
Yes. Any WordPress site, any theme, any plugin count. Every new engagement starts with a free technical audit so you know exactly what you are getting into before you commit to a monthly plan.
How do you handle plugin updates without breaking the site?
Every update runs in a staging environment first. Site checked, forms checked, layout checked, then pushed to production. Auto-updates in production are how most agencies operate. That is exactly why "the site broke" is such a common opening line in support tickets.
What if my site has been hacked?
Hacked-site cleanup is a one-off engagement regardless of whether you are on a care plan. Contain, clean, patch entry point, submit Google reconsideration if blacklisted, monitor 30 days. Most clients move to Care Plus or Care Pro after to prevent recurrence.
Do you include WordPress hosting?
Optional. Most clients keep their existing hosting (SiteGround, Hostinger, WP Engine, Kinsta) and we manage on top. Hosting from us is available as a separate quote. Not bundled or mandatory.
Can you help if I want to move off WordPress?
Yes. Our hand-coded website design service builds sites with no plugin dependencies. See the section above on when a rebuild makes sense.
Is there a contract?
No lock-in. Month to month, 14 days notice, 30-day money back on the first month. Cancel any time and we hand over site access and credentials.
Get your WordPress site looked after.
Book a free 30-minute audit. We look at your current WordPress install, tell you what state it is in, and recommend the right tier. No pushy sales.