Website maintenance is the routine work that keeps a business website safe, working and accurate: installing software updates, taking and testing backups, renewing the domain and the HTTPS (TLS) certificate, keeping forms free of spam, fixing broken links, checking speed and accessibility, and correcting content when your facts change. Most known WordPress security flaws are in plugins. In Patchstack’s report on 2025, 91% of the 11,334 new vulnerabilities it recorded in the WordPress ecosystem were in plugins, and 6 were in WordPress itself[1]; WordPress runs 40.2% of all websites[2]. Few website maintenance jobs have an official schedule. WordPress’s own documentation suggests weekly backups for small sites and daily for busy ones[3], and no primary source, Google included, sets how often a small business should update its content. The most important warning: exploiting software flaws is now the most common way attackers get in, at 31% of breaches in the Executive Summary of Verizon’s 2026 Data Breach Investigations Report[4].
BaaDigi sells website maintenance and management, so we compete with companies named on this page. Every outside figure below is from the company’s own pages or a public source, so you can check it.
What does website maintenance include?
A few plain definitions first. Your domain is your web address (yourbusiness.com), which you rent from a registrar. Hosting is the computer that serves your site to visitors, which you rent from a host. A plugin is an add-on program installed into a website system such as WordPress to give it a feature, like a contact form or a booking calendar. Maintenance is keeping all of those current and working.
| Task | Why it matters | How often works well here |
|---|---|---|
| Software updates (website system, plugins, themes) | The U.S. Cybersecurity and Infrastructure Security Agency (CISA) calls outdated software one of the most significant security risks to a business[5]. | As released. WordPress installs minor and security releases automatically by default; major releases still need a click[6]. |
| Server software (PHP) on the hosting | Each PHP version gets two years of full support, then two years of critical security fixes only, then none[7]. | Before its end date. PHP 8.2 security support ends December 31, 2026[7]. |
| Backups | WordPress’s documentation says problems inevitably occur and backups let you act when they do[3]. | Weekly for small, low-activity sites; daily for busy ones; keep at least 3–5 recent copies[3]. Always before an update[3]. |
| Security (passwords, two-step login) | CISA says weak or stolen passwords are one of the easiest ways into business accounts[8]. | No official cadence. CISA says turn on multifactor login for all admin accounts[9]. |
| The HTTPS certificate (SSL/TLS) | Certificate lifetimes are being cut in steps from 398 days to 47 days by 2029[10]. | Let’s Encrypt recommends renewing its 90-day certificates every 60 days[11]. |
| Domain renewal | ICANN says you must renew with your registrar before expiry or risk losing the name[12]. | Before the registration ends; terms are typically 1–10 years[12]. |
| Forms and spam | Google says spammers often abuse open comment forms and other places visitors can post[13]. | No official cadence. |
| Speed (Core Web Vitals) | Google highly recommends good Core Web Vitals for success with Search[14]. | No official cadence. |
| Broken links and missing pages | Google removes a previously indexed page that starts returning a 404 error[15]. | No official cadence. |
| Accessibility | ADA.gov says businesses open to the public must give people with disabilities full and equal enjoyment of their goods and services[16]. | No official cadence. |
| Content (prices, hours, services, staff) | Google estimates when a page was published or significantly updated from several signals[17]. | No official cadence; update when the facts change. |
Before any update, back up. WordPress’s plugin documentation says to always have a current backup before updating plugins because problems can happen during the update[18]. Plugins can be set to update automatically one by one from the Plugins screen, a feature WordPress added in version 5.5[18].
Forms need watching because a large share of web traffic is not human. Cloudflare’s 2025 Year in Review, measuring requests for web pages across its own network (not form submissions and not any one site), found that on December 2, 2025, people made 47% of those requests and non-AI bots 44%[19]. Tools exist to filter bots: Cloudflare says its Turnstile check can be embedded in any website without sending traffic through Cloudflare and works without showing visitors a CAPTCHA[20]. Google’s reCAPTCHA developer page is now marked deprecated and points to Google Cloud Fraud Defense, so sites using it should check what that change means for them[21].
A backup you have never restored is a hope, not a backup. CISA advises testing that you can restore data fully and partially, and that you can roll back at least seven days[22]. It also recommends the 3-2-1 rule: three copies, on two kinds of storage, with one kept off-site[22].
What this costs, and what plans bundle, is covered in our guides to website maintenance cost and website maintenance packages; what you pay for the hosting itself is in the website hosting cost guide.
Why does website maintenance matter?
Because the reports below recorded more WordPress-ecosystem flaws each year, and some attackers move fast. These are the most recent figures from the main public reports, each counting its own database, so the totals differ. They count vulnerabilities in the WordPress ecosystem only, not risk to all websites.
| Report (year published) | Year covered | What it counted | Key figures |
|---|---|---|---|
| Patchstack, State of WordPress Security in 2026 (2026) | 2025 | New vulnerabilities in its WordPress-ecosystem database | 11,334 new, up 42% on 2024; 91% in plugins, 9% in themes, 6 in core[1] |
| Patchstack, State of WordPress Security in 2025 (2025) | 2024 | New vulnerabilities in its WordPress-ecosystem database | 7,966 new, about 22 a day; 96% in plugins, 4% in themes, 7 in core[23] |
| Wordfence, 2024 Annual WordPress Vulnerability and Threat Report (April 2025) | 2024 | Vulnerabilities published in the Wordfence Intelligence database | 8,223, roughly 68% more than 2023; plugins 96% of disclosures, core 5[24] |
Speed is the problem. Patchstack found that 46% of the vulnerabilities it recorded in 2025 had no fix from the developer by the time they were made public, and that about half of high-impact vulnerabilities were exploited within 24 hours[1]. In its 2025 test of popular web hosting companies, only 26% of vulnerability attacks were blocked by the host[1]. Wordfence adds context the other way: it rated over 68% of the flaws disclosed in 2024 as low risk to most site owners, and 58% were in software with fewer than 10,000 active installs[24]. It also reported that about 35% of the flaws disclosed in 2024 were still unpatched in 2025[24].
Outdated software shows up in some hacked sites, but not most. In Sucuri’s 2023 Hacked Website & Malware Threat Report, 39.1% of the content systems it found infected were outdated at the point of infection (so 60.9% were not); the sample was 39,594 sites cleaned by its incident team plus 108,122,130 remote scans from January to December 2023[25]. In the same data, 13.97% of compromised sites had at least one vulnerable plugin or theme when cleaned, and 49.21% had at least one backdoor[25]. These are shares of Sucuri’s own customers and scans, not of all websites.
Across all kinds of businesses, the Executive Summary of Verizon’s 2026 Data Breach Investigations Report, built on more than 31,000 incidents and 22,000 confirmed breaches in 145 countries, found exploited vulnerabilities were the most common way in, at 31% of breaches[4]. The median time to fully fix critical vulnerabilities on CISA’s known-exploited list rose to 43 days in that report, from 32 the year before[4]. Its small and medium business slice covered 7,256 incidents, with exploited vulnerabilities as the first step in 26% of breaches[4]. In a companion study of about 70,000 cyber-insurance claims, the worst 2.5% of breaches cost small and medium businesses more than 7% of revenue[26].
A hack can hurt you in search, not just on the page. Google’s spam policies define hacked content as content placed on a site without permission through a security hole, and warn that injected pages can harm visitors and search performance even when your existing pages look clean[27].
We did not find a primary-source figure for what an hour of website downtime costs a small business; the Verizon figures above are breach costs, not downtime costs. CISA does warn that recovering without backups can take weeks or months, and may be impossible[22].
What happens to the HTTPS certificate and the domain if nobody is watching?
Both expire on fixed dates, and both are easy to miss unless renewal is automatic.
The secure (HTTPS) connection relies on a TLS certificate (often still called SSL). In a ballot published April 11, 2025, the CA/Browser Forum, the industry body that sets the rules for these certificates, set a schedule cutting their maximum life from 398 days to 47 days in steps from March 2026 to March 2029[10].
| From | Longest a certificate can be valid | How long domain checks can be reused |
|---|---|---|
| March 15, 2026 | 200 days | 200 days[28] |
| March 15, 2027 | 100 days | 100 days[28] |
| March 15, 2029 | 47 days | 10 days[28] |
Let’s Encrypt, a free certificate provider, issues 90-day certificates by default and recommends renewing them every 60 days[11]. Its default will move to 64-day certificates on February 10, 2027, and to 45-day certificates on February 16, 2028[29]. At those lengths, renewing by hand is not realistic; check that your host renews automatically. Let’s Encrypt itself says renewing at a hardcoded 60-day interval will no longer be sufficient for 45-day certificates[29].
What a visitor sees when a certificate lapses: Chrome’s help page says a full-page "Your connection is not private" error means there is a problem with the site, the network or the device[30]. We did not find a browser-maker page that says in so many words that an expired site certificate triggers it, so we do not claim the exact wording here.
Your domain is registered for a set period, typically between one and ten years, and you must renew it with your registrar before it expires[12]. ICANN says your registrar must allow a domain name that is in the 30-day Redemption Grace Period to be redeemed (or restored)[31]; that program covers generic domains such as .com, and rules for other endings vary. If it is not renewed or restored, it may be offered to anyone on a first-come, first-served basis[32].
ICANN, which oversees domain names, says it has no authority to transfer domain names, including expired ones, back to you[12]. Turn on auto-renew, keep the card on file current, and make sure the registrar account is in your name, not your web person’s.
What does Google say about keeping a site up to date?
Less than most maintenance sellers imply. Google does not publish a schedule for updating a website, and we found no primary source that does. Here is what its documentation does say.
- Page experience counts. Google says its core ranking systems look to reward content that gives a good page experience, and its self-check asks whether pages have good Core Web Vitals and are served securely[33].
- Secure pages were a small signal in 2014. When Google began using HTTPS as a ranking signal, it called it very lightweight, affecting fewer than 1% of global queries, and said it might strengthen it over time[34]. We did not check whether that has changed since.
- Speed is recommended, not a trump card. Google highly recommends good Core Web Vitals for success with Search[14].
- Freshness depends on the search. Google runs "query deserves freshness" systems that show fresher content for searches where it would be expected[35]. That is about particular searches, not a rule that every page must change on a schedule.
- Dates are estimated, so show yours. Google estimates when a page was published or significantly updated from several factors, and advises adding a visible date and featuring it prominently[17].
- Dead pages drop out. A page that returns a 404 error is removed from Google’s index if it was there, and Google gradually crawls it less often[15].
Changing a date or a sentence just to look fresh is not something Google documents as helping. Its wording is "significantly updated"[17]. Update a page when something on it has changed.
How often should you update your website?
Split it into two questions, because the answers come from different places.
- Software: as soon as security updates are released. WordPress applies minor and security releases automatically by default and calls switching that off strongly discouraged[6]. In mid-2026 it shipped point releases from 7.0.1 on July 9 to 7.0.6 on September 22[36]. CISA says to prioritize critical vulnerabilities on public-facing systems and turn on automatic updates[5], and the FTC says to set a schedule for updates without naming a frequency[37].
- Content: when the facts change. A new price, new hours, a service you added or dropped, a new phone number. No primary source we found, including Google, sets a content schedule for a small-business website[35][17].
- Backups: WordPress’s documentation gives a general suggestion of weekly for small sites and daily for busy ones[3].
If someone tells you Google wants your site updated monthly or quarterly, ask for the Google page that says so. We could not find one.
How long it takes depends on what you run. A site with dozens of plugins has dozens of things to update and test; a site with none has no plugin updates to apply, though it still has the other jobs in the table above. No public study we found measures maintenance hours for small-business sites, so we do not give a number.
A website maintenance checklist
This is our suggested routine, not an official standard. The grouping into weekly, monthly and yearly is ours; each factual statement is sourced.
Weekly
- Confirm last week’s backup ran and is stored somewhere other than your hosting. WordPress suggests weekly backups for small sites, daily for busy ones[3].
- Check that security updates applied. WordPress installs minor and security releases automatically unless someone turned that off[6].
- Send a test enquiry through every form on the site and confirm it arrives.
Monthly
- Take a backup, then update plugins and themes. WordPress says to have a current backup first, because updates can fail[18].
- Install new major WordPress releases, which need a manual click by default[6]. WordPress.org says only the most recent release in the 7.1 series is safe to use and actively maintained[36].
- Remove plugins you no longer use. In Patchstack’s report on 2025, 91% of the new WordPress-ecosystem vulnerabilities it recorded were in plugins[1].
- Look for broken links and missing pages, and redirect or fix them. Pages returning 404 errors drop out of Google’s index[15].
- Check speed against Google’s thresholds: Largest Contentful Paint 2.5 seconds or less[38], Interaction to Next Paint 200 milliseconds or less[39], Cumulative Layout Shift 0.1 or less[40], at the 75th percentile of visits[41].
- Review who has admin logins, delete old ones, and make sure every admin account uses multifactor login[9]. The FTC says a strong password is at least 12 characters[37].
Quarterly and yearly
- Restore a backup to prove it works, and confirm you can roll back at least seven days[22].
- Check the domain’s expiry date and that auto-renew is on[12].
- Check that the certificate renews automatically. Maximum certificate life is 200 days from March 15, 2026, and 100 days from March 15, 2027[28].
- Ask your host which PHP version the site runs and when its security support ends; PHP 8.2 ends December 31, 2026[7].
- Review accessibility against WCAG, which ADA.gov names as helpful guidance for businesses[16]. The current version is WCAG 2.2, published December 12, 2024[42].
- Read every page as a customer. Correct prices, hours, services, staff and service areas, and show a visible "last updated" date where it helps[17].
Does every website need the same maintenance?
No. The mix depends on what you run. WordPress runs 40.2% of all websites and 58.7% of sites whose content system is known[2]. Among WordPress sites, 31.5% use the Elementor page builder and 19.8% run WooCommerce for selling online[2]. Each plugin is more software that can need an update. What the security reports measure is narrower: of the 11,334 new WordPress-ecosystem vulnerabilities Patchstack recorded in 2025, 91% were in plugins, 9% in themes, and 6 in WordPress core, which Patchstack described as low priority[1].
W3Techs shows the major-version split only. As of October 1, 2026, among WordPress sites it could detect, 63.8% ran version 7, 29.1% version 6, 4.8% version 5, 2.0% version 4 and 0.2% version 3[2]. That is 36.1% on version 6 or older when added together; W3Techs does not show which 7.x release each site runs. WordPress.org says only the most recent release in the 7.1 series is safe to use and actively maintained[36]. Its security page says only the latest version is officially supported, but the Security Team also backports fixes to older versions as a courtesy[43]; the release archive shows 6.9.9 and 6.8.10 shipped on September 22, 2026[36].
As a matter of logic, a site with no plugins has no plugin updates to apply. That does not mean it needs little: we found no study that measures maintenance effort by site type. Every site still has a domain to renew, a certificate that must renew, backups of its content, logins to protect, forms that attract spam, content that goes stale, accessibility to check, and, if someone built it with code, dependency updates by whoever built it. CISA lists website databases among the business data to back up[22].
Hosted builders are another case. Shopify runs 5.4% of all websites, Wix 4.2% and Squarespace 2.4%, and 31.5% of sites use none of the content systems W3Techs tracks[44]. Our sources here do not cover what each builder patches for you, so check the platform’s own terms; our WordPress, Wix and Squarespace guides cover each one. If you run WordPress, our WordPress maintenance plans guide compares what the plans include.
Who should do it: you, a maintenance company, or a managed setup you can edit with AI?
Start with what you are actually paying someone to do. If most of your requests are small content changes, like a new price, a photo or a holiday closure, that is labor you may be able to do yourself. Our guide to how to edit your website covers doing those yourself on each platform, and the guide to editing your website with ChatGPT or Claude covers asking an AI to do it.
That second option is how BaaDigi’s AI Website Management works. It costs $97 a month plus a one-time $300 setup, month to month with no contract[45]. Your current site is rebuilt on Next.js (up to 15 standard pages), hosted on Vercel with Cloudflare in front, with spam filtering on lead forms, form leads sent to your inbox and logged, and analytics installed[45]. Your own Claude or ChatGPT is connected to the site, and you pay for that subscription yourself[45].
Your words, photos, services and FAQs are kept separate from the website’s code, and your AI may change content only. Each change goes to a preview, automated checks run, you approve it, then it publishes; every change is saved and can be rolled back[45]. You own the domain, code, content and lead data, and the code is transferred to you if you leave[45]. Online stores, membership sites, web apps, portals, complex booking or calculators and large content migrations are quoted separately[45].
At $97 we make no content changes for you. The Predictable Work Website, at $147 a month plus $500 setup, adds a dashboard of traffic, leads, sources and rankings and one update request a month of up to 30 minutes, with no rollover; the Foundation Engine, at $297 a month plus $700 setup, has changes done for you[45].
- Do it yourself. Likely a fit if your site is small, runs few or no plugins, and you will actually work through the checklist above every week and month. Our suggestion: turn on automatic updates and auto-renew first, since missed updates and expired renewals are two of the failures described above.
- Hire a maintenance company. Likely a fit if you run WordPress with a store, a page builder or many plugins and do not want to touch it. Check any plan against the task table above, ask whether restores are tested, and ask whether the domain is in your name. Our guides to the best website maintenance companies, website maintenance packages and website management for small business compare the options.
- Move to a managed setup you can edit with AI. Likely a fit if what you mostly need is small content changes, you already use ChatGPT or Claude, and you would rather someone else handle hosting, security and support. Not a fit if you want every change made for you, or if your site is a store or web app that needs a custom quote.
Every guide in this series
- Can ChatGPT or Claude Edit My Website?
- How Do You Edit a Website You Already Have?
- What Do WordPress Maintenance Plans Cost, and Do You Need One?
- How Much Does Website Maintenance Cost in 2026?
- What Do Website Maintenance Packages Include?
- Which Website Maintenance Companies Publish Their Prices?
- How Should a Small Business Manage Its Website?
- How Much Does Website Hosting Cost in 2026?
Frequently asked questions
- What is website maintenance?
- Website maintenance is the routine work that keeps a business website safe, working and accurate: software updates, backups, renewing the domain and security certificate, keeping forms free of spam, fixing broken links, checking speed and accessibility, and updating content when your facts change.
- How often should you update your website?
- Install security updates as soon as they are released, and turn on automatic updates where the platform offers them. Update content when something changes, such as prices, hours or services. No primary source, including Google, sets a fixed schedule for a small-business website’s content.
- How often should a website be backed up?
- WordPress’s documentation suggests weekly for small, low-activity sites and daily for busy ones, keeping at least 3–5 recent copies, and always backing up before an update. CISA also recommends testing that you can restore, and keeping one copy off-site.
- Does Google rank sites higher for being updated often?
- Google does not say so. It runs freshness systems for searches where newer content is expected, estimates when a page was significantly updated, and advises showing a visible date. It does not publish an update schedule, and HTTPS was described as a very lightweight signal when Google introduced it in 2014.
- What happens if my domain expires?
- For generic domains such as .com, ICANN says your registrar must allow a domain in the 30-day Redemption Grace Period to be redeemed (or restored). If it is not renewed or restored, it may be offered to anyone on a first-come, first-served basis, and ICANN cannot transfer it back to you. Keep auto-renew on and the account in your own name.
- Do sites without WordPress plugins need maintenance?
- Some. Most known WordPress-ecosystem security flaws are in plugins, so a site without plugins has no plugin updates to apply and fewer known flaws to patch. It still needs its domain and certificate renewed, logins protected, forms watched for spam, content kept accurate and accessibility checked.
Related reading
- How much does website maintenance cost?
- Website maintenance packages compared
- Best website maintenance companies
- WordPress maintenance plans
- How much does website hosting cost?
- How to edit your website
- Edit your website with ChatGPT or Claude
- Website management for small business
- AI Website Management: $97 a month, use your own AI
Sources
Every source was opened and read on the date shown. Vendor prices change; check the vendor's page before buying. How we research: methodology.
- Patchstack, State of WordPress Security in 2026 (covers 2025) — checked 2026-10-01
- W3Techs, usage statistics of WordPress (October 1, 2026) — checked 2026-10-01
- WordPress.org: WordPress backups — checked 2026-10-01
- Verizon, 2026 Data Breach Investigations Report, Executive Summary (PDF) — checked 2026-10-01
- CISA: Update business software — checked 2026-10-01
- WordPress.org: Configuring automatic background updates — checked 2026-10-01
- PHP.net: supported versions — checked 2026-10-01
- CISA: Require strong passwords — checked 2026-10-01
- CISA: Four cybersecurity essentials for businesses (August 29, 2025) — checked 2026-10-01
- CA/Browser Forum, Ballot SC-081v3: schedule for reducing certificate validity (April 11, 2025) — checked 2026-10-01
- Let’s Encrypt: FAQ — checked 2026-10-01
- ICANN: renewing your domain name — checked 2026-10-01
- Google Search Central: monitoring and debugging security issues — checked 2026-10-01
- Google Search Central: Core Web Vitals — checked 2026-10-01
- Google Search Central: HTTP status codes and network errors — checked 2026-10-01
- ADA.gov: Guidance on web accessibility and the ADA (March 18, 2022) — checked 2026-10-01
- Google Search Central: publication dates — checked 2026-10-01
- WordPress.org: Manage plugins — checked 2026-10-01
- Cloudflare blog: Radar 2025 Year in Review — checked 2026-10-01
- Cloudflare docs: Turnstile — checked 2026-10-01
- Google for Developers: reCAPTCHA introduction (marked deprecated) — checked 2026-10-01
- CISA: Back up business data — checked 2026-10-01
- Patchstack, State of WordPress Security in 2025 (covers 2024) — checked 2026-10-01
- Wordfence, 2024 Annual WordPress Vulnerability and Threat Report (April 2025, PDF) — checked 2026-10-01
- Sucuri, 2023 Hacked Website & Malware Threat Report — checked 2026-10-01
- Verizon, 2026 DBIR and Breach Impact Study: SMB revenue losses (PDF) — checked 2026-10-01
- Google Search Central: spam policies — checked 2026-10-01
- CA/Browser Forum, TLS Baseline Requirements — checked 2026-10-01
- Let’s Encrypt blog: moving from 90-day to 45-day certificates (December 2, 2025) — checked 2026-10-01
- Google Chrome Help: "Your connection is not private" errors — checked 2026-10-01
- ICANN: Redemption Grace Period complaints — checked 2026-10-01
- ICANN: expired domain complaints — checked 2026-10-01
- Google Search Central: Understanding page experience — checked 2026-10-01
- Google Search Central Blog, "HTTPS as a ranking signal" (August 2014) — checked 2026-10-01
- Google Search Central: ranking systems guide — checked 2026-10-01
- WordPress.org: release archive — checked 2026-10-01
- FTC: Cybersecurity for small business — checked 2026-10-01
- web.dev: Largest Contentful Paint — checked 2026-10-01
- web.dev: Interaction to Next Paint — checked 2026-10-01
- web.dev: Cumulative Layout Shift — checked 2026-10-01
- web.dev: Web Vitals — checked 2026-10-01
- W3C: Web Content Accessibility Guidelines (WCAG) 2.2 — checked 2026-10-01
- WordPress.org: Security — checked 2026-10-01
- W3Techs, usage statistics of content management systems (October 1, 2026) — checked 2026-10-01
- BaaDigi: AI Website Management pricing and scope — checked 2026-10-01