Website surrounded by clear symbols for updates, security, backups, performance and content changes
Website maintenance

What Does Website Maintenance Include? A Plain-English Guide

Website maintenance can cover software, backups, hosting, checks, support and content changes. Use this guide to compare what a supplier actually includes.

By 8 min read

Website maintenance is the recurring work that keeps a live website available, secure, accurate and usable. It can include software updates, backups, hosting oversight, form tests, broken-link checks, content amendments and technical support. It does not automatically include redesigns, new features or an ongoing SEO campaign.

That definition matters because suppliers use the same phrase for very different services. One package may run automated updates and send a report. Another may include a person who fixes faults and changes your prices or opening hours. The package name tells you little. The written scope tells you whether the business problem is covered.

The six parts of website maintenance

Most website maintenance services combine some or all of six practical jobs. Not every site needs each task at the same frequency, and the implementation depends on how the website was built.

1. Software and technical upkeep

A website may rely on a content management system, theme, plugins, code libraries, server software and third-party services. Keeping applicable components current reduces the risk of known faults and incompatibilities accumulating.

This is especially visible on WordPress. Its official documentation recommends current core, plugin and theme versions, and advises having a recoverable backup before updates. A custom-coded or static site does not have the same WordPress dashboard routine, but its dependencies, build process and integrations still need an owner.

Technical upkeep can also include checking that an update completed, testing important pages afterwards and rolling back a change that caused a problem. “Automatic updates enabled” is a setting. It is not the same thing as a tested maintenance process.

2. Backups and recovery

A backup is a separate copy of the data and files needed to restore the website. The useful questions are what is copied, where it is stored, how long it is retained and whether restoration has been tested.

The National Cyber Security Centre’s small-business guidance recommends regular backups of important data and checking that they can be restored. For a WordPress site, that normally means both the database and website files. A static site may be recoverable from version control, while form submissions, uploaded media or customer data need their own plan.

A supplier saying “daily backups” has not answered the whole question. Ask how quickly the site could be recovered and who would perform the work.

3. Availability, security and functional checks

Monitoring can detect that a site is unavailable, but an available site can still be broken. Maintenance should identify the functions that matter to the business and test them at an appropriate interval.

Typical checks include:

  • whether the website and HTTPS certificate are working;

  • whether contact, booking or enquiry forms still deliver messages;

  • whether payment and account journeys work, where applicable;

  • whether important pages return the expected status;

  • whether security alerts or unusual changes need investigation;

  • whether integrations still exchange data correctly.

The scope should also say what happens after an alert. Detection without an agreed response can leave the owner with a notification and nobody responsible for the repair.

Laptop showing a healthy website beside a phone form test, backup drive and ticked maintenance checklist
The checklist should reflect the site’s real business functions. A brochure site, online shop and customer portal do not carry the same operational risk.

4. Hosting, domains, DNS and certificates

Hosting is the infrastructure that serves the website. The domain is the address people use to reach it. DNS connects that address to the relevant services, and an SSL or TLS certificate enables HTTPS. These are related responsibilities, but they are not interchangeable.

A maintenance provider may manage all four, only the website, or none of the underlying accounts. Record who owns each account, who receives renewal notices and who can make an urgent DNS change. The business should retain appropriate control of its domain even when a supplier manages it day to day.

Renewing a domain or paid software licence is also different from doing maintenance work. Ask whether third-party charges are included, recharged at cost or invoiced separately.

5. Content changes and website management

Content changes keep the information useful to customers. Common requests include new prices, revised service descriptions, opening hours, team profiles, images, testimonials and campaign pages.

Some website maintenance packages include a small monthly allowance for supplied text and images. Others exclude content completely. Copywriting, new photography, complex page design and new functionality are normally separate unless the agreement explicitly includes them.

This is the point where maintenance and website management begin to diverge. Maintenance preserves the current system. Website management means somebody actively helps keep the site accurate and commercially useful.

6. Performance, accessibility and search checks

A technically available website can become slower, harder to use or less visible as content and integrations change. Sensible recurring checks may cover broken links, missing page titles, indexing problems, image size, accessibility regressions and real-world performance.

Google defines Core Web Vitals around loading performance, responsiveness and visual stability, and recommends monitoring them through Search Console. The metrics are useful quality signals, but routine measurement is not a promise that every issue can be fixed within a basic care plan.

Maintenance can protect SEO foundations. It does not replace keyword research, content production, digital PR or link acquisition. If a proposal says “SEO included”, ask for the exact activities and deliverables.

How often should maintenance happen?

Frequency should follow risk and change, not a generic monthly ritual. The matrix below is a practical starting point for a straightforward small-business site.

Cadence

Typical work

Important qualification

Continuous or automated

Uptime alerts, certificate monitoring, scheduled backups and security notifications

A person still needs to own the response

Weekly or after a change

Applicable software updates, backup checks and tests of high-value forms or journeys

Update frequency depends on the platform and release risk

Monthly

Review alerts, inspect key pages, test enquiries, check broken links and confirm recent backups

A stable managed site may need less manual intervention

Quarterly

Review performance, accessibility, analytics, Search Console, user journeys and stale business information

Findings may create separate improvement work

As needed

Prices, opening hours, staff, services, campaigns, legal text and new integrations

The agreement should define allowance, lead time and approval

Annually or at renewal

Domains, licences, supplier access, recovery contacts and the full maintenance scope

Renewal dates vary, so keep a shared register

An ecommerce site or customer portal needs a more formal schedule than a five-page brochure site. Treat the table as a conversation starter, not a universal service-level agreement.

Website maintenance compared with website management

Question

Technical maintenance

Managed website service

Main purpose

Keep the existing system healthy

Keep the website healthy, accurate and useful

Typical work

Updates, backups, monitoring, fault checks and recovery

Technical upkeep plus agreed content changes and operational ownership

New content

Often excluded or tightly limited

Usually included within a defined allowance

Improvement advice

May be reported without implementation

Often includes practical recommendations within the service boundary

Best fit

A business with somebody who can manage content and suppliers

An owner who wants one accountable route for the website

Neither model is automatically better. A capable internal team may only need specialist technical cover. A small business without a web team may get more value from management because it removes coordination as well as maintenance.

Our separate guide explains what website maintenance costs in the UK and why price comparisons only work after the scope is clear.

Business owner handing an organised website responsibility folder to a specialist while retaining the domain ownership record
Management works best when operational responsibility is transferred clearly while ownership, access and service limits remain visible to the business.

A checklist for comparing maintenance packages

Ask every provider to answer the same questions in writing:

  1. Which site, hosting account, domain and third-party services are covered?

  2. Which tasks are automated, and which results does a person review?

  3. What is backed up, where is it stored and when was restoration last tested?

  4. Which forms, payments or customer journeys are tested?

  5. What monitoring runs, and who responds to an alert?

  6. Are text and image changes included? If so, how is the allowance measured?

  7. Are new pages, copywriting, design and development excluded?

  8. What response target applies to routine requests and urgent faults?

  9. Which hosting, domain, licence and VAT charges sit outside the fee?

  10. Who owns the domain, content, analytics data, source files and supplier accounts?

  11. What happens when an update breaks something outside the original scope?

  12. What will be handed over if the arrangement ends?

Look for specific boundaries rather than the longest list. A provider that clearly excludes weekend incident response is easier to evaluate than one that promises “complete security” without defining a response.

How Elkwood’s managed website model works

Elkwood combines the original website, managed hosting, technical upkeep and reasonable text and image amendments from £25 a month. The model works because we build and operate the site within a controlled system. We are not offering a £25 maintenance takeover for an unknown WordPress installation, ecommerce platform or bespoke application.

For a straightforward small-business site, that removes the need to coordinate separate hosting, maintenance and routine content suppliers. It does not include an ongoing SEO campaign, unlimited redesigns or formal support for complex software. You can review the service on our pricing page and see what is included.

Sources checked

Quick answers

Frequently asked questions

What does monthly website maintenance include?

A monthly plan commonly includes applicable software updates, backups, monitoring, basic functional checks and support. Hosting and content changes may be bundled, limited or excluded. The written scope should name the tasks, frequency and response process.

Does website maintenance include content updates?

Not automatically. Some plans include a time allowance for supplied text and images, while technical plans may exclude visible changes. Ask whether new pages, copywriting, image preparation and design are covered.

How often should a website be maintained?

Monitoring and backups can run continuously. Important updates and journey tests may happen weekly or after changes, while broader performance and content reviews can be monthly or quarterly. Business critical sites need a schedule based on their actual risk.

Is website hosting part of maintenance?

Hosting and maintenance are separate services, although a supplier may bundle them. Hosting serves the website. Maintenance is the work that keeps the website and its supporting services healthy.

What is the difference between website maintenance and website management?

Maintenance protects the existing technical system. Website management adds active ownership of content, routine changes and coordination. A managed service is broader, so its limits should be stated just as clearly.

Related reading