Control
Make the website observable
Availability, application errors, form delivery, expiry dates, Search Console and security signals should produce actionable information rather than accumulated logs.
Guides
A published website does not become static: hosting, browsers, external services, threats, content and objectives continue to change. Maintenance observes those changes, prevents problems, restores service and evolves what creates value.
Short answer
Professional maintenance is not simply “updating plugins”. It covers an agreed scope of monitoring, verifiable backups, security, technical checks and support—plus content, SEO and evolutionary work where the plan includes them. Cost depends on responsibilities, frequency, response times and included work. CARE plans start at €59 per month; on-demand SPOT work starts at €80 per hour.
The result is not “having done something every month”, but keeping the website observable, recoverable and aligned with the business.
A serious service defines what is checked, what can be changed, response times and the boundary between included work and a new project.
Control
Availability, application errors, form delivery, expiry dates, Search Console and security signals should produce actionable information rather than accumulated logs.
Prevention
Backups, access control, hardening, compatible updates and integration checks reduce risk before it becomes downtime.
Continuity
Having a copy is not enough: its content, retention, access, restoration process and decision ownership must be clear.
Evolution
Services, evidence, prices, contacts, content and commercial journeys change. Maintenance can include agreed improvements without becoming unlimited development.
The agreement matters as much as the code
“Maintenance included” does not describe a service. You need scope, channels, working hours, priorities, frequencies, evidence, exclusions and a rule for additional work.
Separating categories makes the price understandable and prevents every request from becoming an emergency—or an assumed free favour.
Scheduled checks, backups, access, configuration, compatibility, expiry dates and unusual signals. It reduces risk but cannot guarantee that incidents will never happen.
Diagnosing and resolving errors, failed forms, missing resources, configuration problems or regressions. Contain the impact first, then correct the cause.
Agreed improvements to features, structure, journeys and integrations. A new private area or configurator remains a project, not a micro-edit.
Updating copy, images, data, links, metadata and content. It can include Search Console and ongoing SEO where the chosen plan provides them.
The code can remain identical while its environment changes. Stability comes from noticing those changes and responding methodically.
PHP versions, certificates, DNS, server rules, space, email and infrastructure have expiry dates and updates independent of the website.
New versions can change rendering, forms, APIs and security policies. Essential journeys should be retested on representative cases.
Maps, payments, email, analytics, privacy and embedded services can change endpoints, prices, agreements or integration methods.
People, offers, regulatory references, images, dates and links stop representing reality even when the page continues to work.
A technically healthy website can become commercially useless if it no longer reflects current services, positioning, evidence, markets and contact routes.
Stolen credentials, vulnerabilities, weak configurations and exposed dependencies require risk-based control and response capability.
Operating principle
A focused, controlled architecture makes diagnosis, updates and recovery more predictable. That is a maintenance advantage, not a claim of invulnerability or permanence.
The combination changes with the website, but excluding whole areas without assigning them to anyone creates gaps that only emerge during a problem.
Renewals, TLS certificate, server configuration, runtime versions, space, provider backups, access and administrative contacts.
Hardening, credentials, privileges, useful logs, vulnerabilities, separate copies, restoration tests and a process to contain incidents.
Email delivery, anti-spam, payments, maps, feeds, webhooks, APIs and confirmations should be tested as complete journeys, not merely viewed on screen.
Services actually loaded, cookies, notices, consent and agreements should describe the published configuration. Every new integration can change the scope.
Pages, prices, people, links, metadata, sitemaps, structured data and language versions should remain consistent, reachable and current.
Performance, mobile, keyboard, focus, contrast, errors and compatibility need retesting after changes to code, media, content or external services.
Explore practical website security and how to choose and manage hosting.
A dashboard full of graphs is not maintenance. Every useful signal needs a threshold, a recipient and a possible action.
External checks can detect unresponsive pages, HTTP errors and TLS expiry. An alert should separate a real failure from a transient interruption.
Application logs, email delivery and periodic form or checkout tests expose problems that merely checking the homepage cannot see.
Unusual access, unexpected changes, suspicious files and repeated errors should be recorded proportionately without collecting unnecessary data.
Search Console reveals changes, errors and indexing problems; technical analytics helps determine whether pages and goals continue to be used.
An alert without ownership is only noise
Before enabling a notification, define who receives it, when they assess it, what the intervention includes and when additional work needs approval.
An automated copy is a useful foundation, but it does not prove that everything is present, accessible during the incident or recoverable within the required time.
The right question
Files, databases, configuration, DNS, email, media, variables and external services can follow different cycles. The copy’s scope must match the scope of the service being restored.
CISA recommends offline, encrypted copies and regular availability and integrity tests. SiteGround documents automatic copies and restoration, but the operating plan must still define retention, access and checks.
List required files, databases, email, configuration and source. A partial copy may restore a page while leaving the real process broken.
The window should reflect how often data and content change. Closely spaced copies may all contain the same undetected problem.
Copies in the same environment and shared credentials can fail with the primary system. Documented access and proportionate protection are needed.
Testing verifies integrity, process, dependencies and realistic recovery time. It should not be attempted for the first time while the website is already offline.
No website is “secure forever”. The work is to reduce the surface, manage change, detect signals and limit damage when something happens.
NIST frames patching as preventive maintenance. Before applying change, assess relevance, compatibility, priority and the path back.
Personal accounts, least privilege, strong authentication where available, removal of obsolete access and protected credentials reduce avoidable incidents.
Every plugin, theme, panel, endpoint or integration adds code, configuration and responsibility. Keeping only what is necessary makes control and diagnosis manageable.
Containment, evidence preservation, recovery, root-cause correction, credential changes and review requests are separate tasks to plan before an emergency.
A fast website at launch can become heavy after new images, fonts, scripts or integrations. Even an editorial change can break hierarchy, contrast or keyboard navigation.
Unoptimised media, widgets and accumulated tags increase transfer and browser work. Maintenance addresses the cause rather than hiding the issue behind one isolated score.
Menus, forms, payments, contacts and primary content need testing on real viewports and interactions, especially after changes that look harmless on desktop.
New copy, images, components and documents can introduce barriers. W3C recommends review processes and schedules to maintain the chosen level.
Tests should be proportionate to the change and focus on affected journeys. A new feature is not complete until it has been verified in the real environment.
Also read why a website becomes slow and the guide to accessibility duties, exemptions and maintenance.
Search engines and AI systems encounter what the website publishes today. Outdated information, conflicting signals and abandoned pages reduce usefulness and trust.
Prices, services, locations, people, dates, references and availability should match reality. Changing the date without updating the content does not create quality.
Internal and external links, PDFs, images and removed pages need checking. Errors and chains waste time for users and crawlers.
Canonicals, hreflang, sitemaps, structured data, titles and visible content should describe the same resource in the correct languages and URLs.
Queries, pages, clicks, goals and enquiry quality help decide what to maintain, correct or develop. They do not promise positions.
For SEO and GEO
Every intervention should begin with a verifiable reason, preserve what works and measure effects over time. No update guarantees rankings, AI citations or conversions.
The answer should exist before the incident. Ownership, access and responsibility cannot depend on one person’s memory.
| Area | Responsibility to assign | Evidence required |
|---|---|---|
| Domain and DNS | Ownership, renewal, access and record changes | Named account, current contacts and recoverable access |
| Hosting and server | Technical management, provider escalation and renewals | Active plan, access, tickets and documented configuration |
| Code and configuration | Diagnosis, change, testing, versions and release | Source, history, backup and deployment process |
| Content and approvals | Accuracy, materials, priorities and authorisation | Named contact and traceable requests |
| External providers | Licences, agreements, accounts, privacy and support | Ownership, renewals, documents and support channels |
| Incident or emergency | Priority, containment, communication and decisions | Agreed channel, timing, contacts and authorisations |
Accounts and licences should remain in the client’s name; delegated technical management should not become proprietary dependency on the supplier.
There is no single frequency. Availability and security may need continuous observation; content, testing and reviews follow different cycles.
Continuous
Availability, certificates, significant errors and selected security events can generate automated notifications with defined thresholds and recipients.
Monthly
Forms, backups, relevant updates, Search Console, approaching expiry dates and agreed changes are reviewed according to scope.
Quarterly
Priority pages, links, evidence, performance, mobile, accessibility and measurement are compared with real website changes.
Annual
Responsibilities, providers, risks, content, objectives and support level are reassessed. A suitable plan one year earlier may no longer fit.
Urgency does not justify random change. A clear sequence limits damage, preserves useful information and separates immediate restoration from the definitive correction.
Response time is not a guaranteed resolution time
Acknowledgement can be defined; resolution depends on cause, access, providers, backup availability and authorisations. A serious agreement distinguishes the two.
CARE plans run for 12 months and turn work and response times into a readable scope. The price does not buy unlimited intervention: it buys continuity proportionate to the chosen plan.
| Item | CARE Light | CARE Full | CARE Premium |
|---|---|---|---|
| Monthly fee | €59 | €140 | €280 |
| Hosting, technical privacy, backups, hardening, monitoring and micro-edits | Included | Included | Included |
| Content entry and editing | No | Yes | Yes |
| Ongoing SEO | No | Technical | Technical and operational |
| Agreed evolutionary work | No | No | Yes |
| Emergencies included | No | No | Yes |
| Working response time | 48–72 hours | 24–48 hours | Within 24 hours |
On-demand work
Standard work costs €80/hour and urgent work €110/hour. Five-hour packages cost €375 and ten-hour packages €700.
SPOT covers one-off requests, work not included in the chosen CARE plan or exceptional volumes. If work substantially changes features or structure, it receives a dedicated quotation.
CARE lasts 12 months, payable monthly, quarterly, six-monthly or annually in advance with a 5% discount. It renews automatically unless cancelled at least 30 days before expiry. Provider subscriptions and licences remain excluded and in the client’s name.
The answers should appear in the proposal or agreement. If they only emerge after a failure, the service was never properly defined.
Domain, hosting, email, databases, languages, APIs, ecommerce and external tools should be listed without generic wording.
Ask for frequency, thresholds, recipients and intended actions. Automated scanning does not replace testing and professional judgement.
Verify components, frequency, retention, separation, access and the restoration process.
An operational definition prevents a copy change and a new feature from being treated as equivalent requests.
Content, SEO, new features, emergencies, licences and third-party work should each have an explicit place.
Separate working hours, acknowledgement, priority and resolution time. External dependencies can prevent a certain deadline.
The client should be able to recover domain, hosting, suppliers, data and materials without relying on the maintainer’s personal credentials.
Requests, tests, versions and releases should be traceable in proportion to the website’s risk and complexity.
Concise reports, tickets, history and check results make the work verifiable without producing useless documentation.
Duration, cancellation, return of access, work status and service continuity should be clear from the outset.
The sources support principles for patching, backups, monitoring, search, hosting and accessibility. CARE prices, scope and method are commercial statements by Gian Luca Partengo.
Patching is framed as preventive maintenance and part of risk management, planned alongside operational needs.
Offline encrypted copies, regular availability and integrity testing and recovery preparation before an incident.
Website monitoring, the Search Console Security Issues report, notifications and careful choice of external providers.
Period comparison, seasonality, pages, queries, devices and indexing problems through the performance report.
Risk-proportionate logging and monitoring design with useful information for analysis, operations and security.
Automatic copies, restoration options, plan-based retention and additional features for manual or downloadable backups.
Processes, responsibilities and review schedules for maintaining the chosen accessibility level across content and tools.
Sources checked on 17 August 2026. Services, interfaces, provider prices and recommendations can change and should be reviewed in the website’s actual context.
Direct answers about frequency, costs, backups, security, CMSs, bespoke code, response times and responsibilities.
There is no general obligation to buy a maintenance subscription. Concrete responsibilities remain for security, data, services, published information and applicable rules. The level of control should reflect risk, features and business impact.
It depends on the signal. Availability, certificates and critical events may be observed continuously; forms, backups, content, Search Console and journeys need periodic checks proportionate to change and risk.
It can require less when it removes unnecessary CMSs, themes, plugins and dependencies and keeps code, deployment and responsibility under control. It does not remove hosting, browsers, APIs, content, security or regulatory and commercial change.
No. Updates are part of patching and can introduce incompatibilities. Backups, verification, monitoring, journey tests, current content, security, measurement and a restoration process are also required.
It is a useful foundation, but content, frequency, retention, access and restoration need verification. External data or services may fall outside the copy and an untested backup does not prove actual recovery time.
No. It can reduce likelihood and impact through hardening, access management, patches, monitoring, backups and response. No serious provider can guarantee the absolute absence of vulnerabilities or incidents.
No. Response time indicates when the request is acknowledged. Resolution depends on diagnosis, severity, access, providers, backups and authorisations and may not be predictable before analysis.
CARE plans start at €59/month for Light, €140/month for Full and €280/month for Premium, all for 12 months. SPOT work starts at €80/hour; emergencies and out-of-scope work follow the stated conditions.
Major new features, redesign, unplanned integrations, large content volumes, provider costs and work beyond the chosen plan. These should move into SPOT or a dedicated quotation.
It depends on the plan. CARE Full includes content, ongoing technical SEO, Search Console and technical analytics; Premium adds operational SEO and agreed evolutionary work. Light covers the technical foundation.
Preferably the client, with current account and recovery details. The professional can manage them technically without becoming the infrastructure owner or the only person capable of recovering it.
CARE suits websites that need continuity, checks and defined response times. SPOT suits one-off work, the absence of an ongoing plan or requests outside the scope of the chosen CARE plan.
Next step
Compare CARE Light, Full and Premium: scope, response times and included work are stated before the engagement. SPOT support remains available for one-off needs.