Nothing happens. That’s the trap. An unmaintained website looks fine for months — sometimes a couple of years — and then things fail in an order most owners never see coming: quiet breakage first, security exposure second, and only at the very end anything a visitor would notice.
The order things actually fail in
First, the edges. Contact forms stop delivering because an email service changed its rules. A payment or shipping integration retires an old API version. A map stops loading. None of this announces itself — the page still renders, and the failures land in inboxes nobody reads. It’s the dock rotting from the underside: solid to look at, right up until someone steps on it.
Second, the clock runs out. Every platform version has an end-of-life date — Drupal 7 hit it in January 2025, Magento 1 back in June 2020 — after which security fixes stop being written at all. The site keeps working; it just stops being defended. Publicly known vulnerabilities plus no patches is exactly the combination automated attacks scan for, and they scan constantly. They don’t care that yours is a small site.
Third, the visible break. A hosting migration, a forced PHP upgrade, or a hack finally produces a symptom a visitor can see. This is the moment most rescues start — and by then the fix costs a multiple of what steady upkeep would have.
The honest math
Skipping maintenance doesn’t save the money; it defers it at a bad exchange rate. A neglected site’s eventual rescue-plus-catchup routinely costs two to four years of the plan that would have prevented it.
If your site is already somewhere on this curve, the signs of abandonment guide tells you where — and the earlier you catch it, the shorter the portage back.