Skip to content
NewHost
Menu

What a Website Maintenance Plan Should Include - SA Guide

What a website maintenance plan should include - updates, security, backups, monitoring, content changes and reporting - plus questions to ask before signing.

By NewHost team · · 6 min read

A website maintenance plan should cover six things: software updates, security, backups with tested restores, uptime and performance monitoring, a set amount of content changes, and regular reporting. Anything less leaves gaps that tend to show up at the worst moment, like a hacked site before a big sale or an expired domain during a campaign. This guide explains each part, what "good" looks like, and the questions to ask any developer or agency before you sign.

Why websites need maintenance at all

A website isn't a brochure you print once. It's software running on a server connected to the internet, and:

  • The CMS, plugins, themes and frameworks it uses release security fixes regularly.
  • Automated bots constantly probe sites for known vulnerabilities in outdated software.
  • Server software, PHP and Node.js versions reach end of life and must be upgraded.
  • Your business changes: prices, staff, services, hours.
  • Browsers and search engines change their expectations over time.

Skipping maintenance usually doesn't break a site overnight. It slowly accumulates risk until something fails.

What a good plan includes

1. Software updates

  • CMS core, plugins and themes (for WordPress sites) or framework and dependency updates (for Next.js and Node.js apps).
  • Security updates applied promptly, not saved up for a quarterly batch.
  • Testing after updates: a quick check of key pages, forms and checkout. Better still, updates tested on a staging or preview copy first.
  • Runtime upgrades (PHP or Node.js versions) planned before they reach end of life. Check nodejs.org for Node's release schedule.

Ask how they handle an update that breaks something. The answer should include a backup taken before updating and a way to roll back.

2. Security

  • Admin accounts with strong passwords and two-factor sign-in; old accounts removed.
  • Removing unused plugins and themes (they still carry vulnerabilities while installed).
  • HTTPS with automatic certificate renewal.
  • Spam protection on forms.
  • Monitoring for signs of compromise, and a defined response if the site is hacked: who cleans it, how fast, and whether that's included or billed extra.

The website security checklist lists the controls to expect.

3. Backups and restores

Backups are only useful if you can restore them. A good plan specifies:

  • Frequency: daily for sites that change often (stores, bookings, blogs), weekly at minimum for static sites.
  • Retention: how many days or weeks of backups are kept.
  • Location: at least one copy stored separately from the website itself.
  • What's included: files, databases, uploads and configuration.
  • Restore testing: a restore is tested regularly, not assumed to work.

Your hosting may already provide part of this. NewHost app hosting includes automatic backups (weekly on Starter, daily on Developer and up) plus on-demand backups before risky changes, with restores handled by the support team. Your maintenance plan should say how it builds on that. A website backup strategy that actually works explains the 3-2-1 approach.

4. Monitoring

  • Uptime monitoring that alerts someone when the site goes down, day or night.
  • SSL and domain expiry tracking. Expired domains and certificates are entirely avoidable outages.
  • Performance checks, such as page speed on mobile after updates or new content.
  • Search Console checks for crawl errors and security warnings.

5. Content changes and small fixes

Most plans include a bank of time each month for updates like new team photos, price changes, a new service page or a fix to a form. Check:

  • How many hours or requests are included per month.
  • Whether unused time rolls over.
  • The turnaround time for requests.
  • The rate for work beyond the included time.

6. Reporting

A short monthly report keeps both sides honest. It should list updates applied, backups confirmed, uptime issues, security events, work done in the included hours, and any recommendations such as a runtime upgrade coming up.

What's usually not included

Clarify these, because they're common sources of surprise invoices:

  • New features or major redesigns
  • Writing new content or blog posts
  • SEO campaigns or paid advertising
  • Hosting, domain and email fees (sometimes bundled, often not)
  • Recovery from a hack caused by something outside the maintainer's control
  • Third-party licence renewals for premium plugins or themes

Hosting and maintenance: who does what?

It helps to be clear where your host's responsibility ends and your maintainer's begins:

Task Typically handled by
Server hardware, network, power Hosting provider
Operating system and server software patches Hosting provider (managed hosting)
Automatic platform backups Hosting provider, per plan
SSL certificate issuing and renewal Hosting provider (e.g. free Let's Encrypt)
CMS, plugin and dependency updates Maintainer or you
Site-level security and user accounts Maintainer or you
Content changes Maintainer or you
Testing restores and monitoring the site itself Maintainer or you

With managed app hosting, the platform handles the servers so your maintainer can focus on the application. On a self-managed VPS, the server patching lands on your side too.

POPIA and maintenance

If your site collects personal information, maintenance is part of POPIA's requirement (section 19) to keep that information secure with reasonable technical measures. Your maintainer will have access to that data, so they act as an operator on your behalf. Have a written agreement that covers confidentiality and security, and remove their access when the relationship ends. Get professional advice for your specific obligations.

Questions to ask before signing

  1. What exactly is updated, and how often?
  2. What happens if an update breaks the site?
  3. How are backups taken, where are they stored, and when was a restore last tested?
  4. What's the response time if the site goes down or is hacked, and is recovery included?
  5. How many content changes are included, and what's the rate beyond that?
  6. What do I receive each month as a report?
  7. Can I cancel, and what do I get on the way out (access, backups, documentation)?

Frequently asked questions

Do small websites really need a maintenance plan?

They need maintenance, whether through a plan, a developer on call or your own time. A small WordPress site with outdated plugins is just as attractive to automated attacks as a large one.

Can I maintain my website myself?

Yes, if you're comfortable applying updates, checking the site afterwards and restoring a backup when needed. Set a weekly reminder and keep a simple log. Many owners do this for simple sites and hire help for anything larger.

How often should a website be updated?

Security updates should be applied as soon as practical after release. Other updates can be batched weekly or monthly, with a check of the site after each round.

Is website maintenance included in hosting?

Hosting usually covers the platform: servers, network, often backups and SSL. Updating your site's own software and content is normally separate, unless your provider explicitly sells a managed maintenance service.

If you're reviewing your setup, see web hosting for WordPress sites, or contact us about moving a site to hosting with automatic backups and free SSL.

Related guides

Ready to launch on NewHost?

Choose a plan and go live today, or tell us what you need and we'll recommend the right setup.