Skip to content
Have a project in mind?
The Gloria JournalWebsite management

What a website maintenance contract actually covers

Person in a suit signing a document at a desk

A website is not a printed document. The CMS that runs it, the plugins, the server language and the browsers all move every month. A website maintenance contract is a supplier's commitment to follow those changes for you: updates, backups, monitoring, support and, on some plans, technical SEO follow-up.

The word covers very different things. Two quotes at the same monthly price can describe two different jobs, and the gap only shows when something breaks.

What follows sets out what a contract genuinely covers, what it leaves out, and how to read an offer before you sign. Every figure is dated and attributed.

What a maintenance contract covers

Offers group four strands, rarely at the same depth. The table works as a reading grid for any quote.

The four strands of a web maintenance contract and the questions to ask
Strand Usual content Question to ask
Updates CMS core, plugins, theme, PHP version How quickly after a security fix? Is it tested on a copy before production?
Backups Files and database, off-server storage, retention period How often, stored where, and when was a restore last tested?
Security and monitoring Application firewall, login rate limiting, two-factor authentication, uptime checks Who receives the alerts, at night and at weekends?
Support and follow-up Incidents, small changes, periodic report, sometimes technical SEO monitoring What response time per severity level, and what is billed on top?

Maintenance is not a rebuild. If your site rests on an abandoned theme or an obsolete structure, no monthly contract will fix that: a WordPress redesign comes first, and maintenance follows.

Why a WordPress site cannot stand still

WordPress ships a major release roughly every four months, according to the release cycle documented by the project (make.wordpress.org). Maintenance releases stack up in between. The official archive (wordpress.org/download/releases, consulted on 10 September 2026) shows the rhythm: WordPress 7.0, released on 20 May 2026, received four maintenance releases before 7.1 arrived on 19 August 2026.

According to the WordPress.org statistics page (wordpress.org/about/stats, 10 September 2026, measured across sites that contact the update servers), 53.1% of sites run 7.1, 14.9% run 7.0 and roughly 32% something older. The policy is explicit: only the latest release is supported, and security fixes reach older branches as a courtesy (wordpress.org/about/security).

The server language follows the same logic. PHP.net states that the 8.2 branch receives security fixes only, until 31 December 2026, 8.3 until 31 December 2027, and that 8.4 and 8.5 are in active support (php.net, September 2026). The same WordPress.org statistics show 17% of sites still on PHP 7.4 and around 38% on a version receiving no fixes at all (8.1 or earlier). A serious contract includes the PHP migration, tested first, because changing branch can break an old plugin.

Most of the risk sits in the plugins

The WordPress core is rarely the weak point. The State of WordPress Security in 2026 report from Patchstack (patchstack.com, scope: vulnerabilities published across the WordPress ecosystem in 2025) counts 11,334 new vulnerabilities, up 42% on 2024. Plugins account for 91% of them, themes 9%, and the core only 6 in total, all low priority.

Two figures bear directly on a maintenance contract: 46% of those vulnerabilities had no vendor fix when they were published, and 17% carried a high risk of automated, large-scale exploitation. Updating is not enough when no fix exists. Your supplier also has to watch advisories, replace abandoned plugins, and run an application firewall able to block a known attack pattern before the patch lands. That is the difference between pressing the update button monthly and maintaining a site.

One national data set, read as such

France publishes figures on the same trend. They cover a French perimeter and should be read as such, not transposed. In its 2025 cyberthreat overview (ANSSI, March 2026, scope: incidents reported to the French national agency), small and mid-sized businesses represent 48% of recorded ransomware victims, against 37% in 2024, and the document describes site compromises through hijacked administrator accounts and unpatched vulnerabilities. An administrator login with no second factor is exactly that exposure.

Backups: the three questions that matter

Most sites have a backup. Few have checked it restores. Three points to insist on:

  • Where are the copies? A backup stored on the same server as the site disappears with it. The 3-2-1 rule — three copies, two types of media, one off site — remains a sound reference.
  • How much data loss can you accept? A brochure site that barely changes tolerates a weekly backup. A shop taking orders daily needs a daily one.
  • How long until the site is back? The contract should state a restore time and test it yearly. A restore that has never been tested is an assumption, not a guarantee.

Hosting shapes all three answers: some hosts include daily off-site backups, others leave that to you. Ask before you pay twice for the same thing.

Support: how to read response times

Offers present response times by severity level. What matters is how each level is defined and which calendar applies: working days, or seven days a week.

Example of service levels for website support
Level Situation Typical time to respond
Critical Site down, payment blocked, site compromised A few hours, weekends included if the contract says so
Major Broken function (form, basket, login) with a workaround available Within one working day
Minor Visual correction, advice, small change A few working days, scheduled

Check what falls outside the scope. Cleaning a site compromised before signature, a breach traced to a shared password, or a new feature are usually billed by time spent, and that has to be written down. If your site already shows signs of intrusion, the clean-up is a separate job on a hacked WordPress site.

What I see on the sites I follow

The technical follow-up strand is the most underestimated, because its effects are slow and invisible. One case I handled: a site that had generated 7,730 pages, of which only 392 were indexed by Google at diagnosis. The site was not down; it was being ignored. The work was identifying empty pages, merging duplicates and deleting the rest. Six months later, a little over 2,100 pages were indexed. That is not support work; it comes from a monthly crawl and a check on how Google indexes the site.

Another case: a menswear seller whose visitors searched for which tie goes with a blue suit. Those questions became short content linked to the product pages — an editorial strand that is not maintenance in the strict sense. Some contracts include it, most do not.

Reading the contract before you sign

Beyond the task list, a handful of clauses decide how much independence you keep.

  1. Ownership of access. Domain name, hosting and administrator account stay in your name. Your supplier holds access; they do not own it.
  2. Exit terms. At the end you get a full backup, the documentation and the list of credentials.
  3. Term and notice. Twelve months is common; one month's notice is reasonable. Check the conditions for moving between plans.
  4. Exact scope. Hours included, paid plugins and licences covered or not, and what switches to time-and-materials billing.
  5. Reporting. A periodic report — updates applied, incidents, backups verified — is the evidence the work happened. With no report, you pay for a promise.
  6. Insurance. Ask for the professional indemnity certificate and its cover.

A plan that "guarantees" you will never be hacked, or promises a Google ranking, should stop you. A supplier commits to actions and response times, not to the absence of incidents and not to a search engine's behaviour. The same questions used when choosing a provider apply to maintenance.

What it costs and how to decide

Price depends on three variables: how often backups and checks run, how wide the support cover is (working days or seven days a week), and whether editorial and SEO follow-up is included. In the plans I have run, a brochure-site offer and a shop offer with SEO follow-up span about one to three. Quotes only compare at equal scope.

To decide, start from what a day of downtime costs you and how much time you can genuinely give to updates. A simple brochure site can be handled in house if somebody really does it every month. A shop, a site that generates enquiries, or a site nobody has checked for a year belongs under contract. Between the two, a one-off technical audit measures the real state of the site first.

Common questions

What does a website maintenance contract include?

It usually groups updates to the CMS, plugins and PHP version, off-site backups, security and uptime monitoring, and support with response times defined by severity. Some plans add technical SEO and content follow-up. The exact scope varies by supplier and should be written into the contract rather than assumed.

How often should a WordPress site be updated?

WordPress ships a major release roughly every four months and maintenance releases in between. Plugin security fixes appear continuously. A monthly check, with security fixes applied quickly, is the minimum; major versions should be tested on a copy of the site before going live.

Can I maintain my site myself?

Yes for a simple brochure site, provided you actually do it every month: updates, backup checks, access review. The risk is not technical, it is organisational — the site nobody looks at for a year. For a shop or a site that generates enquiries, a contract buys defined response times and clear responsibility.

Is a weekly backup enough?

For a brochure site that changes little, a weekly backup stored off the server is acceptable. For a shop or a site with daily sign-ups, a daily backup is necessary. What counts in every case is the restore: it should have been tested, and its duration stated in the contract.

What happens if my site is hacked despite the contract?

A serious contract covers cleaning the site and restoring it from a clean backup, at no extra charge when the incident falls inside the maintained scope. Usual exclusions: a compromise predating the contract, or a password disclosed client-side. No supplier can guarantee that nothing will ever happen.

Does maintenance improve my search rankings?

Not on its own. Maintenance keeps the site available, fast and free of technical faults, which removes obstacles rather than creating positions. Some plans add technical SEO follow-up — crawl, indexing checks, redirects — which does contribute. Ranking depends on content and competition, and no contract can promise it.

This link opens in a new tab.