WordPress maintenance that's tested, not just clicked

Pressing "Update all" isn't maintenance. Maintenance is knowing what changed, testing it somewhere safe, being able to roll back in minutes, and keeping the server underneath on a version of PHP that still gets security fixes.

TL;DR

Who this is for

Businesses whose WordPress or WooCommerce site produces leads or orders, and who can't afford to find out it broke from a customer. Typical clients:

If your site is a handful of static pages that rarely change, paying for monthly maintenance may cost more than moving it somewhere with nothing to patch. We'll say so in the onboarding audit.

What maintenance includes

Updates, staged and verified

Since WordPress 5.5, administrators can switch on automatic updates plugin by plugin and theme by theme, and WordPress runs those auto-updates twice a day by default. That's useful for small, low-risk plugins. For anything touching checkout, forms, page builders or membership, we update on a staging copy first, run a smoke test, then deploy. Auto-updates also depend on WP-Cron, which only fires when someone loads a page; on quiet sites or when cron is broken, updates quietly stop happening, so we check Site Health every cycle and hook WP-Cron to a real server cron where the host allows it.

PHP and server health

WordPress recommends PHP 8.3 or greater and MariaDB 10.11+ or MySQL 8.0+. It will still run on PHP 7.4, but WordPress itself notes those versions are past end of life and may expose the site to vulnerabilities. PHP branches get two years of active support and two more of security-only fixes, per the official schedule. The full calendar is below. Upgrades are tested on staging because older plugins, not WordPress core, are what usually break.

Backups you can restore

Daily database and file backups stored away from the web server, with retention long enough to recover from a problem nobody noticed for a few weeks. Every quarter we restore a backup to staging to prove it works. Host-level snapshots are a bonus, not the plan — they often live on the same infrastructure you're trying to recover from.

Security hardening

Plugin and theme audit

On day one we list every plugin with its last update date, whether it's active, and what it actually does. Deactivated plugins still sit on disk; abandoned ones stop receiving security fixes; three plugins that all add SEO meta tags will fight each other. Removing them is usually the single biggest improvement in both security and speed. Premium plugins bought from marketplaces get extra scrutiny: Patchstack's 2026 report attributes much of 2025's jump in high-severity flaws to premium components that fewer researchers can inspect.

Performance, uptime and forms

Page caching and image optimization tuned to your host, Core Web Vitals checked per template after updates, uptime monitoring with alerts to a person, and a monthly test submission through every form, traced into your inbox or CRM. Forms are the thing owners notice last and customers notice first.

WooCommerce specifics

Checkout gets tested after every update to WooCommerce, payment gateways, shipping and tax plugins. WooCommerce's own update guide says to back up and test on a staging site whenever possible, and some releases need a database update after the code is updated. Order emails are checked, and subscription renewals are watched around plugin updates.

How it runs

Onboarding audit

Plugin and theme inventory, admin users, PHP and database versions, backup status, hosting, security headers, form destinations. You get a written list of risks, ranked.

Staging and backups

A staging copy and an offsite backup set up before we change anything in production.

Cleanup sprint

Remove dead plugins, fix the PHP version, harden logins, repair broken cron and email delivery.

Regular update window

Staged updates, then a smoke test of the homepage, top landing pages, every form, search, login and checkout. Critical security releases are applied out of cycle.

Monthly report

What was updated, what was tested, uptime, anything we deferred and why.

What we usually find on day one

The post-update smoke test

After every update window, before we call it done:

Check Pass means
Homepage and top five landing pages Render correctly on mobile and desktop, no PHP warnings, no layout shift from a changed plugin
Every form A labelled test submission arrives at the right inbox or CRM record
Checkout (WooCommerce) A test order completes, the confirmation email sends, stock decrements
Search and filters Return results; no broken archive or pagination templates
Login and accounts Members and customers can log in and reset passwords
Tracking Analytics and conversion tags still fire in real time
Site Health No new critical issues; WP-Cron running
Error log No new fatal errors or deprecation floods after the update

PHP support calendar

The dates that decide when your host has to move. "Security only" means critical fixes are released as needed; after the end date there are none.

PHP branch Active support ended or ends Security fixes end
7.4 and 8.0, 8.1 Ended Ended (see PHP's list of unsupported branches)
8.2 December 31, 2024 December 31, 2026
8.3 December 31, 2025 December 31, 2027
8.4 December 31, 2026 December 31, 2028
8.5 December 31, 2027 December 31, 2029

Source: php.net supported versions and unsupported branches, checked October 2026. For most sites today we target 8.3 or 8.4, after testing every plugin on staging.

Taking over from another developer

Most sites arrive with access scattered across people who may no longer be around. Before touching anything we collect, and move into your name where needed: the domain registrar, DNS, hosting account, an administrator login created for us (never a shared one), SFTP or SSH, any premium plugin and theme licences, the CDN or firewall, and Search Console and analytics. Anything we can't get access to goes on the risk list in writing.

When to stop maintaining WordPress

Maintenance is the right call while WordPress is earning its keep. It stops being the right call when a mostly static marketing site needs a stack of plugins and monthly firefighting to stay upright. That was the situation at Squeaky Clean Turf: two WordPress installs, one running WooCommerce, with plugins, PHP updates and security patches as a recurring cost. We moved them to a static Astro site with Shopify checkout, and the attack surface went from WordPress core plus plugins on two sites to static HTML and four small serverless functions.

We won't push that on you. If WordPress fits your team, we'll maintain it properly. If it doesn't, our migration service moves you without losing traffic.

Pricing and engagement

A flat monthly fee per site, set after the onboarding audit. It depends on plugin count, whether WooCommerce is involved, and how often you publish. The cleanup sprint is quoted separately because some sites need an hour and some need a week. Hosting stays in your name with your provider; we work on WP Engine, Kinsta, and most managed and VPS hosts. No percentage fees and no long contract, as on our pricing page.

Platforms we work in

What we maintain and the hosts we routinely work on. We work in your hosting account rather than moving you to ours.

WordPress logoWordPress WooCommerce logoWooCommerce PHP logoPHP WP Engine logoWP Engine Kinsta logoKinsta Cloudflare logoCloudflare WPScan GitHub logoGitHub Google Search Console logoGoogle Search Console

Proof you can check

Case study · Leaving WordPress

Squeaky Clean Turf

Two WordPress installs, one on WooCommerce, replaced by a static Astro site with Shopify checkout. The write-up lists exactly what recurring maintenance went away and what replaced it.

Read the case study →
Case study · ahmeego.com

The audit an AI agent ran on itself

Our own site's performance and header fixes, including a duplicate cache header and render-blocking fonts — the same checks we run after a WordPress update window.

Read the audit →
Free tool

Marketing Analytics Auditor

Tests security headers, cookies, tags, accessibility and Core Web Vitals on any live URL. A quick way to see what your current maintenance routine is missing.

Run it on your site →
Video

How to use Git for beginners

The version-control basics behind staging and rollback: every change recorded, every bad update reversible.

Watch the video →

Frequently asked

Should I turn on WordPress auto-updates?
For small, well-maintained plugins, often yes. For anything that touches checkout, forms, memberships or your page builder, update on staging first. Auto-updates rely on WP-Cron, so if cron is broken they silently stop — check Tools › Site Health.
What happens if an update breaks my site?
We roll back from the pre-update backup, usually within minutes, then work out the conflict on staging. That's the point of updating on staging first: most breakages never reach production.
Which PHP version should my WordPress site run?
WordPress recommends PHP 8.3 or greater. PHP 8.2 loses security support on December 31, 2026, and 7.4 is already end of life. We test the upgrade on staging because older plugins are what typically fail.
Is WordPress itself insecure?
Core is rarely the problem. Patchstack's 2026 report found only six core vulnerabilities among the 11,334 it recorded for 2025, all low priority; 91% were in plugins. The risk is in what gets installed on top, which is why the plugin audit matters more than any security plugin.
Do you include hosting?
No. Hosting stays in your account with your provider, so you're never locked in to us. We'll recommend a move if your current host is the problem.
Can you take over a site built by another developer or agency?
Yes — it's the most common way clients arrive. The onboarding audit documents what's there, who has access, and what's risky before we change anything.
Do you maintain WooCommerce stores?
Yes. Checkout, payment gateways, shipping, tax and order emails are tested after every relevant update, and subscription renewals are watched closely.

Get a WordPress maintenance audit

Send your site URL, your host, and roughly how many plugins you run. We'll reply with what we'd check first.

John, Kristy, or Sandeep will reply. One of the three of us will respond personally within 1 business day. No SDR queue.
We respond within 1 business day. No spam, ever. Read our privacy notice.

Top 25 references

The primary sources, standards, research, and tools we rely on for this work. Every link was checked on 2026-10-11. We aren't affiliated with these publishers unless noted.

Official documentation

  1. Requirements — WordPress.org
    WordPress recommends PHP 8.3+ and MariaDB 10.11+ or MySQL 8.0+, and warns that older versions are past end of life.
  2. Plugins and themes auto-updates — WordPress.org Documentation
    How per-plugin auto-updates work and that WordPress runs them twice a day by default.
  3. Updating WordPress — WordPress.org Documentation
    The official core update process, including the advice to back up before updating.
  4. Site Health screen — WordPress.org Documentation
    What the Site Health status and info tabs check, including scheduled events and PHP version.
  5. Security — WordPress.org
    How the WordPress security team handles core releases and why third-party plugins are outside its control.
  6. Hardening WordPress — WordPress Advanced Administration Handbook
    The official hardening checklist: file permissions, database users, admin access and disabling file editing.
  7. WordPress Backups — WordPress Advanced Administration Handbook
    What a complete backup includes (database and files) and why copies should be stored off the server.
  8. Editing wp-config.php — WordPress Advanced Administration Handbook
    Reference for DISALLOW_FILE_EDIT, cron and debug constants we set during hardening.
  9. Debugging in WordPress — WordPress Advanced Administration Handbook
    How to log PHP errors safely on staging without showing them to visitors.
  10. Cron — WordPress Plugin Handbook
    Explains that WP-Cron only runs on page loads and how to hook it to a real system cron.
  11. How to update WooCommerce — WooCommerce Docs
    WooCommerce's own staging-first update procedure and database update steps.
  12. Server recommendations for hosting WooCommerce — WooCommerce Docs
    Current PHP, database and memory recommendations for stores.
  13. Server environment — Make WordPress Hosting Handbook
    Hosting-team guidance on PHP extensions, versions and server configuration for WordPress.
  14. Cloudflare WAF — Cloudflare Docs
    Managed rules, rate limiting and custom rules we put in front of WordPress logins and XML-RPC.

Standards & policy

  1. Supported Versions — PHP.net
    The official PHP support schedule; 8.2 security support ends December 31, 2026 and 8.3 on December 31, 2027.
  2. Unsupported Branches — PHP.net
    End-of-life dates for every old PHP branch, including 7.4 and 8.0.
  3. OWASP Top 10 — OWASP Foundation
    The standard list of web application risks, such as broken access control and injection, that plugin flaws fall under.

Research & studies

  1. Web Almanac 2025: Performance — HTTP Archive
    Web-scale Core Web Vitals data to benchmark a WordPress site's field performance against.

Industry reports & benchmarks

  1. State of WordPress Security in 2026 — Patchstack
    Counts 11,334 new WordPress ecosystem vulnerabilities in 2025, 91% in plugins and only 6 in core.
  2. Usage statistics of WordPress — W3Techs
    Tracks WordPress's share of all websites and of CMS-built sites, which explains why it is targeted so often.

Leading tools

  1. WPScan WordPress vulnerability database — WPScan (Automattic)
    Searchable plugin and theme vulnerability database we check the plugin inventory against.
  2. Wordfence — Defiant
    Endpoint firewall and malware scanner, plus threat intelligence on actively exploited plugin flaws.
  3. WP-CLI commands — WordPress Developer Resources
    Command-line reference for scripted updates, database exports and search-replace on staging.
  4. Query Monitor — WordPress.org Plugin Directory
    Developer panel that shows slow queries, PHP errors and hooks, used to find the plugin behind a slowdown.

Communities & courses

  1. Make WordPress Core — WordPress.org
    Where release schedules, dev notes and breaking changes are announced before each core release.
AI disclosure: This page was drafted with AI assistance and edited by a human. Third-party facts link to the official source they came from (checked 2026-10-11); platform names and logos belong to their owners and do not imply a partnership or endorsement.