A real maintenance plan covers five jobs: security updates applied on a schedule, backups that get tested, monitoring that notices problems before you do, a bucket of hours for small fixes, and a named human who answers when you write. That’s the whole list. Everything else on a glossy services page is garnish.
The five, in plain terms
Updates. Core, plugins or modules, and the PHP underneath — applied monthly at minimum, faster when a security release lands. Not “when we get to it.”
Backups. Taken automatically, stored somewhere that isn’t the same server, and — this is the part that gets skipped — actually restored on purpose once in a while to prove they work. A backup nobody has ever restored is a hope, not a backup.
Monitoring. Uptime checks and error-log eyes. You should hear about an outage from your maintainer, not from a customer.
Small fixes. A predictable monthly allotment for the ordinary stuff — a broken form, a stubborn image, a text change that fights back. If every small ask becomes a new estimate, you don’t have a plan; you have a vendor.
A human. One name, one reply-time promise. When the answer to “who do I email?” is a ticket portal with no face behind it, the plan is thinner than the invoice suggests.
Three questions that sort real from hollow
Ask any maintainer these, including us: When was my last update applied, and to what? When was a backup of my site last restored, anywhere? Who specifically works on my site? A real plan answers all three from memory. A hollow one asks to get back to you.
If you’re paying for maintenance and can’t get those answers, the red-flags guide is your next read — and what it should cost is the one after that.