Free site review
Request a Free WordPress Site Review or Speak to an Engineer
Request a free WordPress site review: send an address and get a written health report inside one working day - patch backlog, exposure points, load timings and where the current backup actually stands. No call is booked and no sales sequence starts. Say instead that the site is down or compromised and the request is answered at any hour, nights and weekends included.
Send us a message
Typically answered within 2–4 hours in business hours. If the site is down or actively compromised, pick “My site was hacked” and it is routed straight to an engineer.
- A written report, not a call - backlog, exposure, timings, restore position
- No login needed. The review runs from outside the site
- Down or hacked? Answered at any hour, on any plan
- Plans from $39 a month. No setup fee, no contract

- 2-4 hours Acknowledged by a person, in business hours
- 1 working day The written site review, where you asked for one
- Any hour Anything down, compromised, or losing orders
What the free site review actually contains
It is a report on the live site, produced from outside. The automated pass runs on the WordPress site audit page and returns its findings while you wait; a person reads those afterwards and adds the part a script cannot weigh. Four things get looked at.
- Patch backlog. Which core, plugin and theme versions are behind, which of the gaps carry a disclosed vulnerability, and how far back the oldest one goes.
- Exposure. The login path, XML-RPC, user enumeration, security headers, directory listing, and anything publicly advertising a version number.
- Load timings. Origin response time separately from page weight, because those two failures have different fixes and get reported as one number everywhere else.
- Restore position. What backup exists, where it lives, and whether the host holding the site is also holding the only copy of it.
What it does not contain is a score out of a hundred. A composite number hides which of the four is the actual problem, and the actual problem is the reason to read it. It also carries no price, because what the site needs decides the tier – those are set out on maintenance plans and pricing.
What to send if the site is down right now
Three things, and the first one matters most.
- The URL. Nothing can start without it.
- What changed. An update, a plugin installed, a host migration, an expired certificate, a payment that failed. Almost every outage follows a change, and knowing which one saves the hour that would otherwise go on finding it.
- What you can see. The exact error text, a white screen, a browser warning, a host suspension notice. Screenshots are fine and the wording is what matters.
Leave the site as it is until we reply. The instinct on a compromise is to change every password and restore last night’s backup, and both destroy evidence – the backup usually predates the patch as well, which puts the same hole back.
Outages and active compromises are answered at any hour, nights and weekends included, whether or not you are already a client. The contracted restore times are four hours on Professional and two on Business. Plan support – questions, edits, planned work – is the separate thing, and it runs in business hours at the window your tier carries. What happens after you report one, step by step, is on emergency WordPress support.
When we are reachable
| What you are asking about | Answered within | What arrives |
|---|---|---|
| A new enquiry | 2-4 hours, business hours | A reply from a person, not an autoresponder |
| A free site review | 1 working day | A written report on the live site, findings first |
| Support, Starter plan | 48 hours, business hours | The work, or a date for it |
| Support, Professional plan | 24 hours, business hours | The work, or a date for it |
| Support, Business plan | 8 hours, business hours | The work, or a date for it |
| A site down or compromised | Any hour, nights and weekends | Rollback first, cause second |
| Monitoring, scanning, backups | Continuously, every hour of the year | Automated, so a failure is recorded the minute it happens |
Questions people ask before calling
What happens after I send the form?
A person reads it and replies inside 2 to 4 business hours. A site review request gets a written report on the live site inside one working day. Nothing is booked into a calendar and nobody calls you.
Is the site review really free?
Yes, with no obligation attached. It names what it finds whether or not the finding leads anywhere - a report that only surfaces problems worth selling against is a quote wearing a report's clothes.
Do you need my login for the review?
No. The review is produced from outside: what is publicly observable, response timings, headers, exposed versions and reachable endpoints. Access is needed once work starts, through an account of its own that is removed at the end.
My site is hacked right now - what do I do first?
Send the address and say it is compromised. Leave the passwords alone until we have looked: rotating credentials on a live compromise can trigger a lock-out, and it overwrites the timestamps that show how they got in.
Can you work with my existing developer?
Yes, and it is often the fastest arrangement. They keep building, we hold the maintenance baseline, and the two jobs stop competing for the same afternoon.
What does it cost?
Plans start at $39 a month with no setup fee and no contract. One-off work - a recovery, a migration, a rebuild - is quoted after we have seen the site, never before.
Is there a phone number?
No. Clients are worldwide and the team is remote, so everything runs through email and this form - and that is deliberate rather than a gap: a written trail of what was asked and what was done is worth more on a maintenance account than a call nobody recorded. Reach us directly at info@wordpressmaintenanceservice.com.
Related pages