Web Development
Website Maintenance & Support
The least interesting service on this site and the one clients regret not buying. Almost every emergency we are called into was preventable.
Website maintenance covers updates, backups, monitoring and someone to call when something breaks. The Nexclick tests updates on staging rather than auto-applying them to a live site, keeps backups off-site, and answers within agreed hours. Sites without this stay working until they suddenly do not.
Is this you?
What usually prompts the call
- You do not know when your site was last backed up, or whether the backup restores.
- Updates are avoided because the last one broke something.
- The developer who built it is no longer contactable.
- You found out the site was down because a customer told you.
What we do
The actual deliverables
Things that appear on an invoice, not adjectives.
- Updates tested on staging
- Core, plugin, theme and dependency updates applied to staging, checked, then promoted. Auto-updating a live site is how a Tuesday becomes a bad day.
- Off-site backups with restore testing
- Daily backups stored away from the server, and periodically restored to prove they work. An untested backup is a hope, not a plan.
- Uptime and error monitoring
- Alerts within minutes rather than when a customer notices. Includes checking that forms still deliver, which is the failure nobody detects.
- Security monitoring and hardening
- File integrity checks, login protection, and removal of abandoned plugins — the most common route into a compromised site.
- Performance watch
- Core Web Vitals tracked monthly, so gradual degradation is caught rather than discovered in an audit two years later.
- A defined support channel
- A named contact, agreed response times and an escalation route. Not a ticket queue where urgent and cosmetic requests sit together.
- Small changes included
- A monthly allowance of content and minor development work, so a text change does not need a purchase order.
Comparison
What actually goes wrong, and what prevents it
The incidents we are called into most often, with what would have prevented each and what it costs to fix afterwards. Almost all of it is cheaper to prevent than to repair.
| Incident | Usual cause | Prevented by | Cost to fix after |
|---|---|---|---|
| Site hacked, malware injected | Abandoned plugin, unpatched core | Update discipline, file monitoring | Days of work plus reputation damage |
| Site down, nobody noticed for hours | Host issue or expired certificate | Uptime monitoring | Lost orders and enquiries |
| Update broke the layout | Auto-updates on a live site | Staging test before promotion | Emergency fix at emergency rates |
| Enquiry form stopped delivering | Host mail change or plugin update | Form delivery monitoring | Weeks of lost leads, unrecoverable |
| SSL certificate expired | Auto-renewal failed silently | Certificate monitoring | Browser warnings; immediate traffic loss |
| Domain expired | Renewal to an old email address | Domain expiry monitoring | Site offline; possible domain loss |
| Backup needed and did not restore | Never tested | Periodic restore testing | Potentially total data loss |
| Site gradually got slower | Accumulated plugins and images | Monthly performance checks | A full optimisation project |
| Nobody can access the CMS | Sole admin left the business | Documented access register | Recovery work, sometimes a rebuild |
| Payment gateway stopped working | API version deprecated | Dependency monitoring | Every order lost until noticed |
How it works
Step by step, with timeframes
Timeframes are typical rather than guaranteed, and they assume we get account access and approvals when we ask.
- 01Week 1
Onboarding audit
Current state: versions, vulnerabilities, backup status, hosting configuration and anything actively broken. Frequently the first time anyone has looked.
- 02Week 1–3
Stabilise
Backups established, monitoring configured, outstanding updates applied on staging, and known vulnerabilities closed.
- 03Monthly
Maintain
Update cycle, backup verification, security and performance checks, plus the included change allowance.
- 04Monthly
Report
What was updated, what was fixed, what was flagged, and uptime for the period. Short, and in English.
What you get
Reporting and ownership
- Daily off-site backups, with restores periodically tested rather than assumed.
- Alerts within minutes of downtime, including form delivery failures.
- A monthly report covering updates applied, issues fixed and uptime.
- A named contact and agreed response times, not a shared queue.
- A monthly allowance of small changes, so minor edits do not become a quote.
Tools and platforms
- Staging environments
- Off-site backup services
- Uptime and error monitoring
- WP-CLI / deployment tooling
- Lighthouse CI
- Vulnerability databases
Timeline
How long this actually takes
Onboarding takes one to three weeks depending on how much needs stabilising first. After that it is continuous. The value is entirely preventative, which makes it the hardest service to justify on a report — a good month looks like nothing happened, because nothing did. What we can show is uptime, updates applied without incident, and vulnerabilities closed before they were exploited. Almost every emergency malware or downtime job we are called into was on a site with no monitoring, no tested backup and eighteen months of skipped updates.
Pricing model
Monthly retainer
Monthly retainer, tiered by site complexity and response time. No minimum term beyond the first three months, and no obligation to have built the site with us.
Questions
Website Maintenance & Support questions
Is our host not already doing this?
Hosts back up the server, not necessarily your site in a form you can restore selectively, and they do not test application updates or monitor whether your forms deliver. Managed hosting covers infrastructure; maintenance covers the application on top of it. They are different jobs.
Why not just enable automatic updates?
Because a plugin update can break a layout, an integration or a checkout, and auto-updating a live site means discovering that from a customer. Testing on staging first takes a few minutes and turns an incident into a non-event. It is the single most valuable habit in this service.
What counts as an emergency?
Site down, checkout broken, forms not delivering, or a security compromise. Those get immediate attention within agreed hours. A text change or a new page is normal work, and separating the two is what stops urgent things queueing behind cosmetic ones.
Do you maintain sites you did not build?
Yes, most of them. The onboarding audit establishes what is there and what needs stabilising first. Occasionally the honest answer is that a site is in a state where maintenance is not economic and a rebuild costs less — we will say that rather than bill indefinitely.
How do we know the backups work?
Because they are periodically restored to a staging environment and checked. An untested backup is a hope. This is the single most common gap we find at onboarding, and it is invisible until the day it matters.
What is included versus quoted separately?
Updates, backups, monitoring, security and a monthly allowance of small changes are included. Anything larger — a new template, a feature, a redesign — is quoted separately, with the allowance stated in the agreement so there is no argument about where the line sits.
Last reviewed 28 July 2026.
Tell us what you are trying to fix
A 20-minute call, no pitch deck. The Nexclick will tell you what we would do, roughly what it costs, and whether we are the right people for it.