WordPress after launch: who presses the update button

The boring part of a WordPress site — updates, backups, who steps in when something breaks. How we share responsibility.
A new WordPress site runs well. The problem appears eight months later, when updates have piled up, someone has installed a plugin recommended in a Facebook group, and no one knows where the backup is anymore.
This discussion takes place before delivery, not after.
Why we don't leave updates on full auto
We leave security updates on automatic. Large plugin updates, especially those affecting forms, the cart, or the page builder, we do manually, on a copy of the site, and only then on the live one. The reason is simple: once, on a site with a booking form, a plugin update changed the field structure and the form was sending empty emails. We caught it because we test the form monthly, not because we were warned.
What maintenance specifically means for us
We check for updates, keep backups off-server, test forms, and look at loading times after every major change. When the client requests a small text modification, we do it within the same interval.
What's not included: new functionalities and structural changes. Those are estimated separately, otherwise the maintenance interval turns into unbilled development and spoils things for both parties.
When the client prefers to handle it themselves
It's a real and sometimes correct option, especially if they have a technical person in the company. In this case, we provide access documentation, a list of plugins with the reason for each one being there, and show them on a call how to make a backup.
We also tell them what we don't recommend: not to install optimisation plugins over the existing configuration. Two layers of cache that don't know about each other cause problems that are difficult to diagnose.
Signs that a WordPress site needs a clear-out
The administration panel loads slowly. There are deactivated plugins that remain installed. The same function is solved twice. Old pages, published in tests, indexed in Google.
For a site taken over from another team, we removed some plugins and rewrote with code what two of them did. This isn't always the right path — it depends on who maintains the site after us. If the client's team doesn't have a technical person, a plugin maintained by someone else is safer than code written by us and forgotten.
We don't know exactly what breaks first on a site we didn't build. That's why the first month of a takeover is more observation than intervention.
If you have a WordPress site and don't know what state it's in, we'll check it and send you what we would do in order of priority.
What's included in maintenance and what isn't
The most common misunderstanding: the client believes that maintenance includes content modifications and new pages. For us, it doesn't, precisely so that the price remains predictable.
| Activity | Included in maintenance | Billed separately |
|---|---|---|
| Core and module updates | Yes | — |
| Backup and its verification | Yes | — |
| Repair after a failed update | Yes | — |
| New page or new section | — | Yes |
| Rewriting text, new products | — | Yes |
| New module, annual license | — | Yes, the license belongs to the client |
| Moving to another host | — | Yes |
Checking the backup is the line we insist on. A backup you don't know if it restores isn't a backup, it's a hope.
What a typical month looks like
We access the site, see what has changed, apply updates to a copy, check important pages, and only then move to the live site. If a module crashes, we have a point to revert to. It takes longer than pressing the update button, but this is where the urgent problems we solve on sites we didn't build ourselves come from.
We've taken over sites where the last update was two years ago. In those cases, we don't start with an update, but with a complete copy and a recovery plan, because it's almost certain that something will break.
When the client handles it themselves
This is a valid option if they have a technical person in the company. We leave them a list of what needs to be checked monthly and full access. We don't hold sites hostage and we don't mind if maintenance moves elsewhere.
Signs you're putting it off too long
The administration panel is slow, compatibility warnings appear, the contact form sends intermittently, and modules that haven't received updates in a long time appear in the list. The last one is serious: an abandoned module remains a problem even if it works now.
If you don't know what state your site is in, we'll do a check for you and tell you what should be done first, without obliging you to a subscription.
Want a website that brings in customers?
We'll give you a clear proposal, with price and delivery time, no obligations.
Related service
WordPress development
See details and pricing
Written by
Andrei MunteanuHead of Development, RebeDesign
Builds the websites and online stores: speed, stability and an admin you can use without us.
Updated: 3 September 2026