WordPress 07 Oct 2026 5 min read

What should a WordPress maintenance plan include? A checklist for site owners

Updates, security, monitoring, backups and who actually answers when something breaks. A checklist for comparing maintenance plans – or for seeing what your site is missing today.

Most WordPress sites are built with care and then left to their fate. A year later fourteen plugins are out of date, the PHP version has stopped receiving security fixes and nobody knows whether the backup can actually be restored. It is rarely carelessness – it is just that nobody has it as their job.

A maintenance plan is the answer. But plans vary enormously, and the word "support" can mean anything from "we update plugins once a quarter" to a developer who actually monitors the site around the clock. Here are the nine things we think a plan should cover. Use the list to compare offers, or to see what your site is missing today.

1. Updates – of everything, and tested

WordPress core, every plugin and every theme. The question to ask is not whether they get updated but how: continuously or "when we get around to it"? Are major updates tested on a copy of the site before going live? Is an extra backup taken first? And who replaces a plugin that is no longer maintained?

Do not forget the server. PHP versions reach end of life, and a site on an old version gets neither security fixes nor good performance.

2. Security – monitoring, not just a plugin

A security plugin is a good start but not a plan. What makes the difference is someone monitoring known vulnerabilities in exactly the plugins on your site, protecting the login, scanning for malware and removing unused plugins, themes and old accounts that only widen the attack surface.

3. Monitoring – so someone notices before your customers do

Uptime around the clock is the foundation. Just as important are PHP errors in the logs, forms that stopped sending, SSL certificates and domains about to expire, and pages that suddenly respond with errors. Ask: how do you find out something is wrong – and how fast?

4. Backups – with tested restores

Everyone says they have backups. Ask instead: how often, where are they stored, is one taken before every update, and when was a restore last tested? A backup that has never been tried is an assumption, not insurance.

5. Performance – over time

Sites get slower as content, images and plugins are added. A good plan tracks load times and Core Web Vitals over time and does something about it: caching, image optimisation, database cleanup, and an honest word when hosting or the theme is the bottleneck.

6. WooCommerce – the checkout is what costs

If you run a store this is the most important point. Are checkout, payments and shipping calculation verified after every update? Are WooCommerce updates with database migrations run in a controlled way? Are integrations with payment, shipping and ERP systems monitored so orders never get stuck? And are the theme's template overrides kept compatible – the most common reason a store breaks on update?

7. Errors and incidents – within the plan, not billed by the hour

Conflicting plugins, a white screen after an update, a breach. Is troubleshooting and fixing included, or does every incident become a separate invoice? And what happens in a breach: is the site secured, cleaned and restored, and the cause closed?

8. Minor changes – what you actually need help with

Text changes, image swaps, a new page from an existing template. These small things are what decide in practice whether the plan feels worth the money. Are they included in the pool of hours, and is there a developer to ask when you wonder about a plugin or an offer you have received?

9. Reporting – short and readable

You should know what has been done without having to ask. A short monthly report is enough: what was updated, what was found and fixed, and what is recommended next. If it takes more than two minutes to read, it is too long.

Packages or a pool of hours?

Many providers sell tiers – Basic, Standard, Premium – with fixed lists. Easy to compare, but rarely a good fit: a small company site pays for things it does not need, a store gets too little. The alternative is a pool of hours: you agree on a number of hours per month that becomes a fixed fee, and the scheduled work plus whatever comes up fits within it. Ask how unused hours are handled and how larger work beyond the pool is priced – it should be in the agreement.

Proactive or reactive?

The last question may be the most important: is the plan a support line you call when something has broken, or someone who detects and fixes things before you notice them? The first is insurance. The second is maintenance. A good plan is the second, with the first as a safety net.

How we do it

This is exactly how we build our own plans: no package tiers, a pool of hours based on the site's needs, monitoring and updates that mean we usually get there first, and a short report every month. Read more about how it works on the page about WordPress and WooCommerce maintenance and support plans.

Share: