A useful small-business website care plan should cover tested backups, controlled updates, security basics, uptime and form monitoring, performance checks, access ownership, change records and clear reporting. It should also state who is responsible, how often checks happen and what occurs when something fails. A vague promise to “keep the site updated” is not enough.
A business website is rarely just a set of pages. It may collect enquiries, process orders, connect to email tools, feed analytics, publish structured content and depend on several third-party services. Maintenance therefore needs to protect both the technical platform and the commercial journey running through it.
Start with ownership and scope
Every care plan should identify the website, hosting account, domain, content management system, ecommerce platform and important integrations in scope. It should name the person responsible for routine work and the person authorised to approve material changes.
Record where credentials are held, who has administrator access and how access is removed when a supplier or staff member leaves. Do not place passwords in a general maintenance document. Use an appropriate password manager and enable multi-factor authentication where available.
Backups that can actually be restored
A backup is useful only if it is complete, recent, protected and recoverable. For WordPress, that normally means both the database and the files. A plan should state the backup frequency, retention period, storage locations, encryption or access controls, and the restoration test schedule.
The National Cyber Security Centre recommends backing up important data and keeping backups separate from the computers used day to day. Its guidance also says organisations should know how to restore from backup. WordPress guidance recommends retaining several recent backups in different locations.
For an ecommerce site, the right frequency depends on transaction volume and the recovery point the business can tolerate. A monthly backup may be wholly inadequate if orders arrive every day. Define the acceptable data-loss window first, then set the schedule.
Run a documented restore test periodically in a safe environment. Record the date, result, time taken and any missing dependency. “Backup completed” is not the same as “recovery confirmed”.
Controlled software updates
Core software, themes, plugins and server components need updates, but applying every change blindly can create avoidable downtime. The care plan should describe how updates are reviewed, backed up, tested and deployed.
Prioritise security releases and software that is actively exploited. For routine updates, use a staging site when the change is likely to affect checkout, forms, account areas or integrations. Take a fresh backup, note the existing versions, apply the change and test the commercial journey before closing the task.
The NCSC advises keeping devices and software up to date because updates often include security fixes. WordPress also publishes a defined upgrading process. A good plan turns that general principle into a specific operating procedure rather than relying on a dashboard notification.
Security checks and access hygiene
Website security is broader than installing a security plugin. Review administrator accounts, failed login patterns, unexpected file changes, domain and certificate status, and known vulnerabilities in components. Remove unused plugins and themes because inactive code can still add risk if it remains installed.
Use unique accounts rather than shared administrator logins. Give each user the lowest access level needed for their work. Keep a record of emergency contacts for the host, developer, payment provider and domain registrar so incident response does not begin with searching old emails.
The plan should define what counts as an incident and who decides whether to suspend checkout, reset credentials, notify customers or seek specialist help. It should also reference the business’s data-protection and incident procedures where personal data may be involved.
Monitor the journeys that make money
Uptime monitoring can show that a server responds, but it cannot prove that a customer can complete a task. Schedule human or automated checks of the journeys that matter: contact forms, quote requests, newsletter sign-up, search, cart, checkout, payment confirmation and transactional emails.
Use a safe test method and avoid polluting live sales data. Confirm where test enquiries arrive and who follows up. A form that displays a success message but never delivers the lead is commercially broken even when the website appears online.
For WooCommerce, also review payment and shipping integrations, tax behaviour, stock synchronisation where relevant, order emails and scheduled background tasks. The care plan should distinguish between technical verification and responsibility for day-to-day order operations.
Performance and mobile usability
Performance work should focus on real customer pages, not a single homepage score. Check important landing pages, product or service pages, the basket and checkout on common mobile screen sizes. Look for slow media, layout movement, unresponsive controls and third-party scripts that delay interaction.
Content, links and search visibility
Care plans should include basic content integrity. Check broken internal links, expired campaigns, incorrect contact details, missing images and pages that no longer reflect the offer. Review indexing and coverage signals in Google Search Console, but do not promise rankings.
Reporting that shows evidence
A monthly care report should be short enough to use. It can list backups and restore tests, updates applied, incidents, uptime, journey checks, performance issues, changes made and decisions required. Separate completed routine work from recommendations that need approval or budget.
Include dates and evidence. “All good” creates little accountability, while a 40-page automated report creates noise. A concise record helps the owner understand risk, cost and next action.
What the agreement should say
Define service hours, response targets, exclusions, approval thresholds and how emergency work is charged. State whether content edits, new features, plugin licences, hosting, accessibility audits, SEO work and third-party outages are included. Explain what happens when an unsupported component blocks an update.
Most importantly, connect the plan to the business outcome. A lead-generation site needs reliable enquiry capture. An ecommerce site needs dependable product discovery, checkout and order communication. The maintenance schedule should follow those priorities.
Takeaway
A website care plan is an operating system for keeping a digital asset useful, secure and commercially dependable. It should name the assets, owners, checks, evidence and escalation route. RKS Growth Strategy Solutions can help UK small businesses turn an informal maintenance arrangement into a clear, proportionate system covering WordPress, WooCommerce, integrations and growth-critical journeys.
Frequently asked questions
How often should a small-business website be maintained?
Security and uptime need continuous or frequent monitoring, while updates and journey tests are commonly reviewed weekly or monthly depending on risk. The correct cadence follows transaction volume, change frequency and the business’s recovery needs.
Does a website care plan include hosting?
Sometimes, but it should never be assumed. The agreement must state whether hosting, domain renewal, licences, backups and support are included or separately billed.
Are automatic updates enough for WordPress?
No. Automatic updates can reduce delay, but important journeys still need testing and failures need an owner. Higher-risk changes may require a staging environment and controlled deployment.
How do I know my backups work?
Perform a documented restoration test in a safe environment. Confirm that both files and database are present, the site loads and its critical functions work.
What should a monthly maintenance report include?
Include backups, restore tests, updates, security events, uptime, form or checkout tests, performance findings, completed changes and decisions required from the owner.
Internal-link suggestions
Sources
- National Cyber Security Centre, Small organisations guide to cyber security
- NCSC, Backing up your data, updated 9 April 2026
- NCSC, Keeping devices and software up to date
- WordPress Developer Resources, Backups, updated 4 June 2026
- WordPress Developer Resources, Hardening WordPress, updated 7 January 2026
