WordPress care

Somebody has to
be watching it

A WordPress site that nobody updates is not stable, it is just quiet. The compromise usually happens months before anyone notices.

  • WordPress maintenance services
  • WordPress malware removal
  • WordPress security services
  • Backups and monitoring
What is actually done

Six things, every month, in order

No dashboard of green ticks. These are the jobs, and you get told what they found.

  1. 01

    Updates, on a staging copy first

    Core, theme and plugins updated on a copy, checked, then applied. Not on the live site at midnight with fingers crossed.

  2. 02

    Backups you can actually restore from

    Offsite, and tested by restoring one. A backup nobody has restored is a belief, not a backup.

  3. 03

    Malware scanning and cleanup

    Scanned on a schedule, and if something is found, the route in is looked for rather than just the file removed.

  4. 04

    User and role audit

    Who has an account, who still needs one, and whether anything has quietly granted itself administrator.

  5. 05

    Uptime and form monitoring

    The contact form is checked as well as the homepage, because a form that stopped sending looks exactly like a quiet month.

  6. 06

    A short note at the end of the month

    What changed, what was found, what needs a decision. Written so you can forward it without translating it.

Why this page exists

A compromise that kept coming back

A client site was cleaned, and came back infected. Cleaned again, and came back again. Backdoors and rogue administrator accounts were part of it, but they were symptoms.

The cause was a 749MB full site backup sitting in a publicly reachable folder with the database credentials inside it. Anyone who found that file had everything, and no amount of malware removal was going to change that.

Care exists so that file is found during a routine month rather than during an incident.

Read the full case study
Before you commit

What people ask about maintenance

It runs month to month. If the site is in a good state and you want to stop, you stop, and you keep the backups and the documentation.

Monitoring notices before your customers do. Whether it is fixed at two in the morning depends on what we agree, and that is written down rather than implied.

Yes, and it should be an account in your name that you can revoke. Never a shared password, and never an account only I can reach.

That is most of this work. It starts with an audit so you know what you are inheriting, including anything the previous developer left behind.

You get told immediately, with what it is, what it can reach, and what fixing it involves. Serious findings are not saved up for the monthly note.

Tell me who is watching your site now

If the answer is nobody, or a plugin nobody reads the emails from, that is the honest starting point. The first thing back is an audit of what is actually there.