Skip to content
jagaweb.Book the Review
Website Maintenance & Care

What Website Maintenance Actually Includes

8 min readBy JagaWeb

A plain breakdown of what a maintenance retainer should cover, and what it usually doesn't.

Most website maintenance is sold as a phrase, not a scope. "We'll keep an eye on it" is comforting to hear and almost useless as a contract term, because it doesn't say who checks what, how often, or what happens when something breaks on a Sunday night. If you're paying monthly for maintenance — or deciding whether to start — it's worth knowing what the phrase should actually unpack into, and where the honest limits sit.

"Keeping an eye on it" should mean five separate things

In practice, a maintenance scope worth paying for breaks down into distinct, checkable activities: patching, staging, backup verification, monitoring, and content updates. Each has its own frequency, its own failure mode, and its own limits. A provider who can't describe each of these separately — who only offers "we monitor your site" as a single sentence — probably hasn't built the underlying process either.

Patching: necessary, and not risk-free

Websites are built on layers of software: a content management system, plugins or modules, server-level packages, sometimes a framework underneath all of it. Each layer gets security patches from its maintainers on its own schedule, and unpatched software is one of the more common ways a site gets compromised, defaced, or used to send spam.

But patching is not a purely mechanical, risk-free action. An update can change how a plugin behaves, conflict with another plugin, or break a customisation that was never documented. This is precisely why patching-only isn't the whole job — it's why the next section, staging, exists. Anyone who tells you patches are "always safe to apply straight to the live site" either hasn't been doing this long, or is choosing not to mention the times it's gone wrong.

Why changes get tested on staging first

A staging environment is a private copy of your website — same code, same data structure, none of it visible to the public — where a change can be applied and checked before it touches the live site. The point isn't to catch every possible problem; it's to catch the obvious ones (a broken page, a fatal error, a checkout that no longer submits) before a customer does.

Skipping staging is common, particularly for small changes that "should be fine." Sometimes they are. The cost of skipping it is that when something does break, it breaks in front of your visitors instead of in private, and the person fixing it is now working under pressure instead of on their own schedule. A maintenance provider that patches directly on live, every time, without exception, is trading a bit of speed for a risk that eventually lands on you.

Backups: the difference between "we take backups" and "we've proven they restore"

Almost every host and every maintenance provider will tell you backups are running. Far fewer can tell you when a backup from their system was last actually restored somewhere and checked. A backup file that has never been restored is unverified — you don't know if the file is complete, if the restore process even works, or how long it would take under pressure. This matters enough that it deserves its own explanation rather than a paragraph here: see our companion article on verifying that website backups actually restore for what to ask for as evidence.

The short version for a maintenance scope: ask how often a restore is actually tested, not just how often a backup file is created.

Monitoring: what it catches, and what it doesn't

Monitoring usually means something checks whether your site responds, on a schedule, and alerts a person if it stops. That's useful, and it's also narrower than it sounds — a site can return a normal response while a form, a payment step, or a specific page is broken underneath. We've written a separate breakdown of what uptime monitoring does and doesn't tell you; the point to hold onto for a maintenance scope is that monitoring is a smoke detector, not a guarantee. Monitoring makes it more likely a problem is noticed sooner. It does not guarantee zero downtime, and no honest provider should tell you it does.

Content updates: what "two a month" actually covers

When a retainer includes content updates, it typically means text and image changes on existing pages — updating a price, swapping a photo, correcting a paragraph, adding a new team member's bio to an existing page layout. It does not usually mean building a new page, changing the site's design, or adding a new feature — those are development work, not maintenance, and they take a different kind of time and judgement. Ask specifically what counts as an "update" versus what would be billed or scoped separately, because this is where informal arrangements tend to cause friction later.

What a maintenance retainer explicitly does not include

Being honest about limits protects you from being surprised later. A typical maintenance scope does not include: building new pages or features, a redesign, fixing problems caused by a third-party service outside the site itself, recovering content that was never backed up in the first place, or unlimited changes on demand. If you expect ongoing feature work, changes queued and worked through continuously, that's a different kind of arrangement — for example, a plan built around unlimited change requests processed one at a time, rather than a fixed monthly maintenance scope.

Nor does maintenance mean nothing will ever go wrong. Software has bugs, hosts have outages, and mistakes happen even with good process. What a maintenance scope should promise is that someone is actually doing the checking, patching, and testing on a schedule — not that failure becomes impossible.

What to ask before you sign anything

Before committing to a maintenance retainer, ask: how often are patches applied, and are they tested on staging first? How often is a backup actually restored and checked, not just created? What exactly counts as a "content update," and what falls outside it? What is monitored beyond "is the homepage up"? And what happens, in plain terms, when something does go wrong outside business hours — not a promised response time, but an honest description of the process.

If the answers are vague, that's information too.


JagaWeb Care (RM450/month, excluding SST) is one way to cover this: monitoring, verified backups, patching, and two content updates a month, with card checkout and no sales call required. It doesn't promise zero downtime or an instant fix for everything — nothing honestly can — but it means someone is actually doing the checking described above. Details at jagaweb.my, by email at sales@jagaweb.my, or on WhatsApp through jagaweb.my.

PROTECT YOUR ASSETS

Ready to verify who owns your website?

Replace uncertainty with a decision-ready ownership and access report. The fixed Ownership & Access Review is RM1,500 before SST and includes a 30-day action plan.

WhatsApp