Gian Luca Partengo Gian Luca Partengo

Guides

Website maintenance: what it includes, what it costs and who intervenes

A published website does not become static: hosting, browsers, external services, threats, content and objectives continue to change. Maintenance observes those changes, prevents problems, restores service and evolves what creates value.

Short answer

Professional maintenance is not simply “updating plugins”. It covers an agreed scope of monitoring, verifiable backups, security, technical checks and support—plus content, SEO and evolutionary work where the plan includes them. Cost depends on responsibilities, frequency, response times and included work. CARE plans start at €59 per month; on-demand SPOT work starts at €80 per hour.

Gian Luca Partengo

Gian Luca Partengo
Freelance web developer · Published

Website maintenance in four steps

The result is not “having done something every month”, but keeping the website observable, recoverable and aligned with the business.

  1. 01Observe availability, errors and important signals
  2. 02Prevent risk with checks, hardening and reliable copies
  3. 03Intervene with priorities and responsibilities already defined
  4. 04Update content, structure and features when required
The cycle is continuous: observe, prevent, intervene and improve. Missing one step turns maintenance into a delayed reaction.

What website maintenance actually includes

A serious service defines what is checked, what can be changed, response times and the boundary between included work and a new project.

Control

Make the website observable

Availability, application errors, form delivery, expiry dates, Search Console and security signals should produce actionable information rather than accumulated logs.

Prevention

Reduce likelihood and impact

Backups, access control, hardening, compatible updates and integration checks reduce risk before it becomes downtime.

Continuity

Know how to restore service

Having a copy is not enough: its content, retention, access, restoration process and decision ownership must be clear.

Evolution

Keep the website useful

Services, evidence, prices, contacts, content and commercial journeys change. Maintenance can include agreed improvements without becoming unlimited development.

The agreement matters as much as the code

“Maintenance included” does not describe a service. You need scope, channels, working hours, priorities, frequencies, evidence, exclusions and a rule for additional work.

Preventive, corrective, evolutionary and editorial work are not the same

Separating categories makes the price understandable and prevents every request from becoming an emergency—or an assumed free favour.

Preventive maintenance

Scheduled checks, backups, access, configuration, compatibility, expiry dates and unusual signals. It reduces risk but cannot guarantee that incidents will never happen.

Corrective maintenance

Diagnosing and resolving errors, failed forms, missing resources, configuration problems or regressions. Contain the impact first, then correct the cause.

Evolutionary maintenance

Agreed improvements to features, structure, journeys and integrations. A new private area or configurator remains a project, not a micro-edit.

Editorial and SEO maintenance

Updating copy, images, data, links, metadata and content. It can include Search Console and ongoing SEO where the chosen plan provides them.

Why launching a website does not end the work

The code can remain identical while its environment changes. Stability comes from noticing those changes and responding methodically.

  1. 01

    Hosting and runtimes change

    PHP versions, certificates, DNS, server rules, space, email and infrastructure have expiry dates and updates independent of the website.

  2. 02

    Browsers and devices evolve

    New versions can change rendering, forms, APIs and security policies. Essential journeys should be retested on representative cases.

  3. 03

    Providers change services and APIs

    Maps, payments, email, analytics, privacy and embedded services can change endpoints, prices, agreements or integration methods.

  4. 04

    Content ages

    People, offers, regulatory references, images, dates and links stop representing reality even when the page continues to work.

  5. 05

    The business changes priorities

    A technically healthy website can become commercially useless if it no longer reflects current services, positioning, evidence, markets and contact routes.

  6. 06

    Threats do not stand still

    Stolen credentials, vulnerabilities, weak configurations and exposed dependencies require risk-based control and response capability.

Operating principle

Fewer dependencies mean fewer surfaces to manage, not zero responsibility

A focused, controlled architecture makes diagnosis, updates and recovery more predictable. That is a maintenance advantage, not a claim of invulnerability or permanence.

Six areas a maintenance plan should cover

The combination changes with the website, but excluding whole areas without assigning them to anyone creates gaps that only emerge during a problem.

01

Domain, DNS and hosting

Renewals, TLS certificate, server configuration, runtime versions, space, provider backups, access and administrative contacts.

02

Security and recovery

Hardening, credentials, privileges, useful logs, vulnerabilities, separate copies, restoration tests and a process to contain incidents.

03

Forms and integrations

Email delivery, anti-spam, payments, maps, feeds, webhooks, APIs and confirmations should be tested as complete journeys, not merely viewed on screen.

04

Privacy and providers

Services actually loaded, cookies, notices, consent and agreements should describe the published configuration. Every new integration can change the scope.

05

Content and visibility

Pages, prices, people, links, metadata, sitemaps, structured data and language versions should remain consistent, reachable and current.

06

Experience quality

Performance, mobile, keyboard, focus, contrast, errors and compatibility need retesting after changes to code, media, content or external services.

Explore practical website security and how to choose and manage hosting.

Monitoring: observe signals that lead to a decision

A dashboard full of graphs is not maintenance. Every useful signal needs a threshold, a recipient and a possible action.

Availability and certificates

External checks can detect unresponsive pages, HTTP errors and TLS expiry. An alert should separate a real failure from a transient interruption.

Errors and essential journeys

Application logs, email delivery and periodic form or checkout tests expose problems that merely checking the homepage cannot see.

Security events

Unusual access, unexpected changes, suspicious files and repeated errors should be recorded proportionately without collecting unnecessary data.

Search and measurement

Search Console reveals changes, errors and indexing problems; technical analytics helps determine whether pages and goals continue to be used.

An alert without ownership is only noise

Before enabling a notification, define who receives it, when they assess it, what the intervention includes and when additional work needs approval.

A backup only exists when you know how to restore it

An automated copy is a useful foundation, but it does not prove that everything is present, accessible during the incident or recoverable within the required time.

The right question

Not “do we have a backup?”, but “what can we recover, from when and how?”

Files, databases, configuration, DNS, email, media, variables and external services can follow different cycles. The copy’s scope must match the scope of the service being restored.

CISA recommends offline, encrypted copies and regular availability and integrity tests. SiteGround documents automatic copies and restoration, but the operating plan must still define retention, access and checks.

Copy scope

List required files, databases, email, configuration and source. A partial copy may restore a page while leaving the real process broken.

Frequency and retention

The window should reflect how often data and content change. Closely spaced copies may all contain the same undetected problem.

Separation and access

Copies in the same environment and shared credentials can fail with the primary system. Documented access and proportionate protection are needed.

Restoration test

Testing verifies integrity, process, dependencies and realistic recovery time. It should not be attempted for the first time while the website is already offline.

Security: preventive maintenance, not an absolute promise

No website is “secure forever”. The work is to reduce the surface, manage change, detect signals and limit damage when something happens.

Update with judgement

NIST frames patching as preventive maintenance. Before applying change, assess relevance, compatibility, priority and the path back.

Control identity and privileges

Personal accounts, least privilege, strong authentication where available, removal of obsolete access and protected credentials reduce avoidable incidents.

Reduce the surface

Every plugin, theme, panel, endpoint or integration adds code, configuration and responsibility. Keeping only what is necessary makes control and diagnosis manageable.

Prepare the response

Containment, evidence preservation, recovery, root-cause correction, credential changes and review requests are separate tasks to plan before an emergency.

Performance, mobile and accessibility can regress over time

A fast website at launch can become heavy after new images, fonts, scripts or integrations. Even an editorial change can break hierarchy, contrast or keyboard navigation.

Weight and requests

Unoptimised media, widgets and accumulated tags increase transfer and browser work. Maintenance addresses the cause rather than hiding the issue behind one isolated score.

Mobile journeys

Menus, forms, payments, contacts and primary content need testing on real viewports and interactions, especially after changes that look harmless on desktop.

Ongoing accessibility

New copy, images, components and documents can introduce barriers. W3C recommends review processes and schedules to maintain the chosen level.

Regression control

Tests should be proportionate to the change and focus on affected journeys. A new feature is not complete until it has been verified in the real environment.

Also read why a website becomes slow and the guide to accessibility duties, exemptions and maintenance.

Content, SEO and GEO need as much maintenance as code

Search engines and AI systems encounter what the website publishes today. Outdated information, conflicting signals and abandoned pages reduce usefulness and trust.

Accuracy and currency

Prices, services, locations, people, dates, references and availability should match reality. Changing the date without updating the content does not create quality.

Links and resources

Internal and external links, PDFs, images and removed pages need checking. Errors and chains waste time for users and crawlers.

Consistent technical signals

Canonicals, hreflang, sitemaps, structured data, titles and visible content should describe the same resource in the correct languages and URLs.

Useful measurement

Queries, pages, clicks, goals and enquiry quality help decide what to maintain, correct or develop. They do not promise positions.

For SEO and GEO

Maintenance is not changing copy at random

Every intervention should begin with a verifiable reason, preserve what works and measure effects over time. No update guarantees rankings, AI citations or conversions.

Who intervenes when something goes wrong?

The answer should exist before the incident. Ownership, access and responsibility cannot depend on one person’s memory.

Area Responsibility to assign Evidence required
Domain and DNS Ownership, renewal, access and record changes Named account, current contacts and recoverable access
Hosting and server Technical management, provider escalation and renewals Active plan, access, tickets and documented configuration
Code and configuration Diagnosis, change, testing, versions and release Source, history, backup and deployment process
Content and approvals Accuracy, materials, priorities and authorisation Named contact and traceable requests
External providers Licences, agreements, accounts, privacy and support Ownership, renewals, documents and support channels
Incident or emergency Priority, containment, communication and decisions Agreed channel, timing, contacts and authorisations

Accounts and licences should remain in the client’s name; delegated technical management should not become proprietary dependency on the supplier.

How often should website maintenance happen?

There is no single frequency. Availability and security may need continuous observation; content, testing and reviews follow different cycles.

Continuous

Critical signals

Availability, certificates, significant errors and selected security events can generate automated notifications with defined thresholds and recipients.

Monthly

Operational review

Forms, backups, relevant updates, Search Console, approaching expiry dates and agreed changes are reviewed according to scope.

Quarterly

Quality and content

Priority pages, links, evidence, performance, mobile, accessibility and measurement are compared with real website changes.

Annual

Scope review

Responsibilities, providers, risks, content, objectives and support level are reassessed. A suitable plan one year earlier may no longer fit.

What happens when the website has a real problem

Urgency does not justify random change. A clear sequence limits damage, preserves useful information and separates immediate restoration from the definitive correction.

  1. 01Confirm impact, priority and scope
  2. 02Contain the problem and preserve evidence
  3. 03Restore service with a controlled solution
  4. 04Correct the cause and record what changed
Coming back online is one step, not always the end: after restoration, review cause, security, data, journeys and signals to users and search engines.

Response time is not a guaranteed resolution time

Acknowledgement can be defined; resolution depends on cause, access, providers, backup availability and authorisations. A serious agreement distinguishes the two.

How much website maintenance costs

CARE plans run for 12 months and turn work and response times into a readable scope. The price does not buy unlimited intervention: it buys continuity proportionate to the chosen plan.

Item CARE Light CARE Full CARE Premium
Monthly fee €59 €140 €280
Hosting, technical privacy, backups, hardening, monitoring and micro-edits Included Included Included
Content entry and editing No Yes Yes
Ongoing SEO No Technical Technical and operational
Agreed evolutionary work No No Yes
Emergencies included No No Yes
Working response time 48–72 hours 24–48 hours Within 24 hours

On-demand work

SPOT when an ongoing plan is unnecessary or the work falls outside scope

Standard work costs €80/hour and urgent work €110/hour. Five-hour packages cost €375 and ten-hour packages €700.

SPOT covers one-off requests, work not included in the chosen CARE plan or exceptional volumes. If work substantially changes features or structure, it receives a dedicated quotation.

CARE lasts 12 months, payable monthly, quarterly, six-monthly or annually in advance with a 5% discount. It renews automatically unless cancelled at least 30 days before expiry. Provider subscriptions and licences remain excluded and in the client’s name.

Ten questions before choosing a maintenance service

The answers should appear in the proposal or agreement. If they only emerge after a failure, the service was never properly defined.

  1. 01

    Which websites, environments and services are in scope?

    Domain, hosting, email, databases, languages, APIs, ecommerce and external tools should be listed without generic wording.

  2. 02

    Which checks are automated and which are manual?

    Ask for frequency, thresholds, recipients and intended actions. Automated scanning does not replace testing and professional judgement.

  3. 03

    What do the backups contain?

    Verify components, frequency, retention, separation, access and the restoration process.

  4. 04

    What does “micro-edit” mean?

    An operational definition prevents a copy change and a new feature from being treated as equivalent requests.

  5. 05

    Which activities are excluded?

    Content, SEO, new features, emergencies, licences and third-party work should each have an explicit place.

  6. 06

    What is the response time?

    Separate working hours, acknowledgement, priority and resolution time. External dependencies can prevent a certain deadline.

  7. 07

    Who owns accounts and source?

    The client should be able to recover domain, hosting, suppliers, data and materials without relying on the maintainer’s personal credentials.

  8. 08

    How are changes approved and recorded?

    Requests, tests, versions and releases should be traceable in proportion to the website’s risk and complexity.

  9. 09

    What evidence is delivered?

    Concise reports, tickets, history and check results make the work verifiable without producing useless documentation.

  10. 10

    How are renewal and exit handled?

    Duration, cancellation, return of access, work status and service continuity should be clear from the outset.

Primary sources and verifiable criteria

The sources support principles for patching, backups, monitoring, search, hosting and accessibility. CARE prices, scope and method are commercial statements by Gian Luca Partengo.

  1. NIST — Guide to Enterprise Patch Management Planning

    Patching is framed as preventive maintenance and part of risk management, planned alongside operational needs.

    Open source
  2. CISA — StopRansomware Guide

    Offline encrypted copies, regular availability and integrity testing and recovery preparation before an incident.

    Open source
  3. Google Search Central — Prevent malware infections

    Website monitoring, the Search Console Security Issues report, notifications and careful choice of external providers.

    Open source
  4. Google Search Central — Debugging traffic drops

    Period comparison, seasonality, pages, queries, devices and indexing problems through the performance report.

    Open source
  5. OWASP — Logging Cheat Sheet

    Risk-proportionate logging and monitoring design with useful information for analysis, operations and security.

    Open source
  6. SiteGround — Backup service in Site Tools

    Automatic copies, restoration options, plan-based retention and additional features for manual or downloadable backups.

    Open source
  7. W3C WAI — Accessibility policies and review

    Processes, responsibilities and review schedules for maintaining the chosen accessibility level across content and tools.

    Open source

Sources checked on 17 August 2026. Services, interfaces, provider prices and recommendations can change and should be reviewed in the website’s actual context.

Frequently asked questions about website maintenance

Direct answers about frequency, costs, backups, security, CMSs, bespoke code, response times and responsibilities.

Is website maintenance mandatory?

There is no general obligation to buy a maintenance subscription. Concrete responsibilities remain for security, data, services, published information and applicable rules. The level of control should reflect risk, features and business impact.

How often should a website be checked?

It depends on the signal. Availability, certificates and critical events may be observed continuously; forms, backups, content, Search Console and journeys need periodic checks proportionate to change and risk.

Does a hand-coded website require less maintenance?

It can require less when it removes unnecessary CMSs, themes, plugins and dependencies and keeps code, deployment and responsibility under control. It does not remove hosting, browsers, APIs, content, security or regulatory and commercial change.

Is updating WordPress and plugins enough?

No. Updates are part of patching and can introduce incompatibilities. Backups, verification, monitoring, journey tests, current content, security, measurement and a restoration process are also required.

Is the hosting provider’s automated backup enough?

It is a useful foundation, but content, frequency, retention, access and restoration need verification. External data or services may fall outside the copy and an untested backup does not prove actual recovery time.

Does maintenance guarantee that the website will not be hacked?

No. It can reduce likelihood and impact through hardening, access management, patches, monitoring, backups and response. No serious provider can guarantee the absolute absence of vulnerabilities or incidents.

Are response time and resolution time the same?

No. Response time indicates when the request is acknowledged. Resolution depends on diagnosis, severity, access, providers, backups and authorisations and may not be predictable before analysis.

How much does website maintenance cost?

CARE plans start at €59/month for Light, €140/month for Full and €280/month for Premium, all for 12 months. SPOT work starts at €80/hour; emergencies and out-of-scope work follow the stated conditions.

What is not normally included in maintenance?

Major new features, redesign, unplanned integrations, large content volumes, provider costs and work beyond the chosen plan. These should move into SPOT or a dedicated quotation.

Does maintenance include SEO and content updates?

It depends on the plan. CARE Full includes content, ongoing technical SEO, Search Console and technical analytics; Premium adds operational SEO and agreed evolutionary work. Light covers the technical foundation.

Who should own the domain, hosting and licences?

Preferably the client, with current account and recovery details. The professional can manage them technically without becoming the infrastructure owner or the only person capable of recovering it.

How do I choose between CARE and SPOT?

CARE suits websites that need continuity, checks and defined response times. SPOT suits one-off work, the absence of an ongoing plan or requests outside the scope of the chosen CARE plan.

Did you find this guide useful? Share it.

No social tracker loads before you choose an action.

Next step

Do you know who checks your website and who intervenes when needed?

Compare CARE Light, Full and Premium: scope, response times and included work are stated before the engagement. SPOT support remains available for one-off needs.

Test evidence

Mobile PageSpeed Insights: 100 in every category

PageSpeed Insights result from 28 July 2026: 100 for Performance, Accessibility, Best Practices and SEO on mobile.
Google PageSpeed Insights · Lighthouse mobile · verified 28 July 2026 Open the verifiable report
© 1995–2026 Gian Luca Partengo · All rights reserved.

GLP AI

GLP AI assistant

Answers based on the public content of this website.

Tell me what you need from your website. I will look through GLP services and Articles and point you towards the most relevant route.

Ready

You are interacting with an AI system, which can make mistakes: its answers are not binding quotations. Do not enter personal, sensitive or confidential data. Questions are sent to OpenAI to generate the answer and are not saved by this website. Read the Privacy Policy.

Search