No in-house technical staff
WordPress Maintenance for Small Business, No In-House Tech
The WordPress site was built once, it worked, and nobody has opened the dashboard since. That is the normal state of a small business website and it is also how sites get compromised. Put your numbers into the calculator to quantify what a day offline costs, then see cover priced for a business with no technical staff and no intention of hiring any.
What does an hour offline cost you?
Excludes the enquiries that never arrive because the site was down when someone searched.
See what cover costs- Nothing to learn and nothing to log into - the work happens off your desk
- Updates tested on a copy first, so an update cannot take the site down
- Off-site backups you can restore in one click, held away from your host
- From $39 a month. No setup fee, no contract, cancel any month

What goes wrong in this sector
- The site is running years-old codeThe most common state of a small business site is one built by an agency that moved on. Core, plugins and theme drift behind, and each deferred update makes the next one larger and riskier.
- Nobody is watching, so nobody knowsAn outage is discovered when a customer mentions it, which is usually hours or days later. There is no dashboard anyone checks and no alert anyone receives.
- The backup is a hypothesisEither there is no backup, or there is one held by the same host that holds the site, or there is one nobody has ever restored. All three are the same position on the day it matters.
- An abandoned plugin is the way inCompromises at this size are almost never targeted. Automated scanners walk address ranges looking for a plugin with a published vulnerability, and an unmaintained site is simply findable.
- The cost lands all at onceNothing costs anything for two years, then a cleanup, a rebuild and a fortnight of lost enquiries arrive in the same month.
The normal state of a small business website
It was built two to five years ago, probably by someone who is no longer involved. It worked on the day it launched. Since then nobody has logged in, because nothing appeared to require it.
That is not negligence, it is a reasonable response to a thing that shows no symptoms. A site does not tell you it is running a plugin with a published vulnerability. It does not mention that its last backup failed eleven months ago. It looks exactly the same on the day before a compromise as on any other day.
Which is the actual problem: the failure mode of a small business site is invisible right up until it is total.
Why small sites get compromised at all
The assumption is that nobody would bother. It is true that nobody has singled you out and false that you are therefore safe, because almost nothing at this size is targeted.
Automated scanners walk address ranges looking for a version number with a published vulnerability. They do not know what the business does, how large it is, or whether it is worth anything. The site is found because it is findable, and the overwhelming majority of compromises we recover came in through an outdated plugin or a password reused from an unrelated breach – neither of which has anything to do with how interesting the business is.
What you are actually buying
Not software. Every part of this can be bought as a plugin, and most small sites already have three of them installed and unconfigured.
What a plan buys is somebody applying patches on a schedule and reading what the scanning finds – the part that stops happening the moment it depends on a person who has a business to run. The work is dull, recurring and cheap when it is continuous. It is only expensive as a rescue.
The calculator above prices the alternative in your own numbers: what a day offline costs, against what continuous cover costs. For most businesses at this size the two numbers are not close.
The recurring work itself is patching applied and tested on a staging copy and hardening with daily scanning – the two things that stop being done the moment they depend on someone with a business to run. What each tier includes is on maintenance plans and pricing, and a trade with different failure patterns is better read through cover matched by sector.
Plans that include this
- Starter$39/monthor $390 a year — two months freeBlogs, portfolios and brochure sites
- UpdatesMonthly
- BackupsWeekly, 30-day retention
- Uptime5-minute checks
- Malware removalNot included
- Most chosenProfessional$79/monthor $790 a year — two months freeSmall businesses and lead-generation sites
- UpdatesWeekly + PHP version management
- BackupsDaily, 60-day retention
- Uptime1-minute checks
- Malware removalIncluded
- Business$149/monthor $1490 a year — two months freeStores, membership sites, anywhere downtime costs money
- UpdatesWeekly, tested on staging first
- BackupsDaily, 90-day, multi-location
- Uptime1-minute + 2-hour restore
- Malware removalIncluded
How the work runs
- Onboarding takes an inventory, not a meetingVersions, plugins, theme, PHP, host, current backup position and current exposure. You get it in writing, and it is the only part of this that needs your attention.
- Updates run weekly on a staging copyTested against the things that matter on your site - the contact form, the login, whatever takes payment - and promoted only on a pass.
- Backups go off-site, away from your hostOn separate infrastructure, so a host failure cannot take the site and its copies together. Restorable by you in one click, and tested rather than assumed.
- Monitoring runs whether or not anyone is at a deskChecks from several regions every few minutes. An outage or an active compromise is answered at any hour; everything else runs in business hours inside your plan's window.
- One email a monthWhat was patched, what was deferred, uptime, and anything that needs a decision. Written to be read by someone who is not technical.
The service that covers this
WordPress Update Management: Patching Without BreakageHand over WordPress updates and stop choosing between an unpatched site and a broken one. Core, plugins and themes are applied to a staging copy every…
More in Industries
Questions people ask before calling
I do not know anything technical. Is that a problem?
No, and it is the normal case. Nothing here needs you to learn a dashboard or approve a patch. The only thing asked of you is access at the start and a reply when something needs a commercial decision.
Is $39 a month really enough?
For a site that does not take money directly - a brochure site, a portfolio, a local service page - yes. Monthly patching, weekly off-site copies and monitoring. A site with a shop or a booking system belongs on Professional, where updates are staged and malware cleanup is included.
My web designer built it and disappeared. Can you take it on?
Yes, and it is the most common way sites arrive here. We audit before onboarding and say plainly where something needs fixing first rather than absorbing it silently into the monthly fee.
What if I want to leave?
Cancel any month in one email. No notice period, no exit fee, and your backups are handed over. There is a 30-day money-back guarantee on the first month.
Do I still need this if my site never changes?
The site not changing is the reason. WordPress core ships security releases every few weeks and plugins ship on their own schedules; a site nobody touches falls behind all of them while sitting on the public internet.