· 7 min read · Wwwebtech Team
Nobody Quotes for Maintenance. Here's What Breaks
Certificates expire, plugins drift, forms fail silently. What actually breaks on an unmaintained site — and the cheap checks that catch it early.
In this piece
A website quote usually covers design, build, content migration and launch. It almost never covers the next three years, because nobody wants to put a recurring line item next to a number the client is already wincing at. So the site goes live, the invoice is settled, and everyone moves on.
Then, somewhere between eight and twenty months later, something stops working. Not dramatically. Usually quietly. And because nobody owns the site any more, it stays broken until a customer mentions it, or until you notice the enquiries have thinned out and assume the market has gone soft.
This piece is about what actually breaks, how you find out, and the small set of checks that catch most of it. It is a risk argument, not a sales argument. Several of the things worth doing cost nothing and take fifteen minutes.
The things that expire without telling you
A website is not one thing you own. It is half a dozen things you rent, on separate clocks, from separate people, each of which renews to a different email address — often the address of whoever set it up, who may no longer work with you.
The domain. Typically a one-to-ten year registration. If it lapses, you usually get an auto-renew grace period, then a redemption period where getting it back costs considerably more than the renewal would have, then it drops and anyone can take it. The failure mode is not just a dead website — it is dead email, if your business mail runs on the same domain. Everything stops at once.
The SSL certificate — the thing that puts the padlock next to your address and makes it https rather than http. Certificates from Let's Encrypt, the free authority most hosts use, last 90 days and are meant to renew automatically. Paid certificates from public authorities are now capped at 398 days. When auto-renewal silently fails — and it does, usually after someone changes a server setting — every visitor gets a full-page browser warning telling them your site is not private and may be trying to steal their information. Most people leave. Payment gateways will refuse to work at all.
The PHP version your site runs on, if it is WordPress, Laravel, Magento or most other common platforms. PHP versions have published end-of-life dates after which they get no security patches — PHP 7.4 stopped receiving security support in November 2022, PHP 8.0 in November 2023. Hosts eventually force an upgrade. If your plugins and theme have not been updated in three years, the forced upgrade is the day your site goes blank or starts throwing a 500 error.
Third-party keys and APIs. Payment gateway credentials, map keys, WhatsApp integrations, SMS and OTP providers. Providers deprecate old versions of their interfaces on announced schedules. Your checkout works right up until the Tuesday it does not.
None of these send you a warning you will actually read. They send an email to admin@ or to the developer who built the site in 2021.
The broken form is worse than the broken site
A site that is down is a bad day. A site that is up and quietly swallowing enquiries is a bad quarter, because nothing tells you it is happening.
Contact forms fail in ways that leave the visitor's screen looking completely normal. The thank-you message appears. The email never arrives. Common causes:
- The form sends mail using the web server's own mail function, with a From address at your domain that the server is not authorised to send for. Gmail and Outlook increasingly treat that as forgery and drop it into spam or reject it outright. Since 2024 Google and Yahoo have tightened their requirements on sender authentication — SPF, DKIM and DMARC, three DNS records that prove you are allowed to send from your own domain.
- The notification goes to an employee who left. The mailbox was deleted. The bounce goes nowhere anyone reads.
- A plugin update changed the form's field names and the integration into your CRM — the system where your sales team actually works — now writes leads into a field nobody looks at.
- A spam filter was tightened after a bot wave and is now eating genuine enquiries that happen to contain a URL.
The fix is embarrassingly simple and almost nobody does it: submit your own form once a month, from your phone, on mobile data, using a personal email address. Then check that the lead appears everywhere it is supposed to — the inbox, the CRM, the WhatsApp alert. Do the same on your checkout with a one-rupee test transaction if your gateway allows it. Fifteen minutes. It catches more lost revenue than most marketing spend recovers.
Backups that have never been restored are not backups
Almost every host advertises backups. Three questions decide whether yours are worth anything:
- Where are they stored? A backup sitting on the same server as the site protects you against your own mistakes, not against the server being compromised, suspended or lost. Off-server copies matter.
- How far back do they go? Many hosts keep seven days. Defacement and malware injections are often discovered weeks later. By then every retained backup contains the problem.
- Has anyone ever restored one? This is the question that matters. An untested backup is a belief, not a safeguard. Restoring to a staging copy once a year tells you whether the database and the files actually come back together, and how many hours it takes.
If you take one thing from this article, make it a written answer to those three questions, from whoever holds your hosting. It costs you an email.
What maintenance contracts sell, and what they should
We sell ongoing technical support, so treat the next few lines as us arguing against our own easier products.
Uptime monitoring on its own is close to useless as a maintenance plan. It tells you the server answered. It does not tell you the form is broken, the certificate expires on Thursday, or the checkout returns an error at the payment step. Most of the damaging failures happen on a site that is technically up.
"Unlimited edits" is usually a bet that you will not ask. It is priced on the assumption that most clients send two requests a year. If you genuinely change your site weekly, it is good value. If you do not, you are buying something you will not use while the actual risks go unwatched.
A security plugin is not a substitute for updating. Most WordPress compromises exploit known vulnerabilities in outdated plugins — ones with a published fix available. A firewall plugin on a site with a two-year-old booking plugin is a lock on a door with no frame.
Blind auto-updates are not maintenance either. Updating everything automatically with no staging copy and no backup immediately before is how a working site becomes a blank page on a Saturday night. The point of a maintenance arrangement is that someone takes a backup, applies updates, loads the key pages and submits the form — in that order.
What a sensible arrangement actually contains: regular updates applied after a backup, a monthly functional test of forms and checkout, certificate and domain expiry tracked in someone's calendar rather than someone's inbox, PHP version watched against its end-of-life date, an off-server backup with a known retention period, and a restore tested at least annually. If a quote does not describe those mechanics, ask what it does describe.
The free version you can do yourself
You do not need an agency to reduce most of this risk. You need a recurring reminder and a short list.
Once a month, fifteen minutes
- Submit your contact form from your phone on mobile data. Confirm it lands in the inbox and in your CRM.
- Open the site in an incognito window. Check the padlock is there and the homepage, a service page and the contact page all load.
- Place one test order or booking if you take payments.
Once a quarter, half an hour
- Check Google Search Console for coverage or security messages. Make sure the alert email goes to someone who still works with you.
- Confirm who holds the domain, the hosting and the certificate, and which email address receives their renewal notices.
- Ask your host for the date of the most recent off-server backup.
Once a year
- Restore a backup to a staging copy and see whether it works.
- Check your PHP version against its published end-of-life date.
- Review every third-party key and integration — gateways, WhatsApp, analytics — and remove the ones nothing uses any more. Dormant integrations are unmaintained attack surface.
This is also a good argument for building fewer moving parts in the first place. A site assembled from fourteen plugins has fourteen update cycles and fourteen chances of a conflict. One of the quiet benefits of a deliberately simple build is that there is less to go wrong at two in the morning.
What to do this week
Send one email, to whoever currently holds your hosting, asking four things: when the domain expires, when the SSL certificate renews and whether renewal is automatic, where backups are stored and for how long, and which PHP version the site runs. Then put a monthly reminder in your calendar to submit your own contact form.
If the answers come back vague, or nobody is sure who holds what, that uncertainty is the actual risk — not the technology. If you would like someone to take the checks off your desk, get in touch and tell us what you have; if the leads are arriving but getting lost after that, the problem is further down the line and our notes on routing enquiries properly may be more use.
Questions we get asked
How often should a WordPress site be updated?
Core, theme and plugin updates are best applied at least monthly, and security releases sooner. The important part is the sequence: take a backup first, apply the updates, then load your key pages and submit the contact form to confirm nothing broke. Updating blind with no backup is riskier than updating late.
My website is up, so why would I pay for maintenance?
Most costly failures happen on sites that are technically up — a contact form that silently stops sending, a checkout that fails at the payment step, an expired certificate that triggers a browser warning. Uptime tells you the server answered, not that the business functions still work. A monthly functional test is what catches those.
What happens if my SSL certificate expires?
Visitors see a full-page browser warning saying the connection is not private, which most people will not click past. Payment gateways and many integrations will refuse to connect at all. Free Let's Encrypt certificates renew every 90 days automatically, but auto-renewal can fail quietly after a server change, so it is worth checking the padlock monthly.
Are my host's automatic backups enough?
Only if they are stored off the server, retained for long enough to predate a problem you might discover late, and have actually been restored at least once. Many hosts keep seven days on the same machine. Ask your host those three questions in writing — the answers tell you whether you have a safeguard or an assumption.
How do I know if my contact form emails are going to spam?
Submit the form yourself from a personal Gmail or Outlook address and see where it lands, including the spam folder. If messages are missing or filtered, the usual cause is missing sender authentication — SPF, DKIM and DMARC records in your domain's DNS that prove your server is allowed to send mail for your domain.
If this is your problem
What we’d actually do about it.
Service
Technical SEO & Core Web Vitals
Service