A website care plan is a standing monthly arrangement in which someone else keeps your site running: software updates, backups, security, monitoring and fixing what breaks, usually with hosting included. Some plans also include a little time each month for small improvements. What a care plan usually does not include is new features, a redesign, or writing your content. “Maintenance” means different things to different providers, so read the list before you sign.
This article sets out what a good plan should cover, what it normally leaves out, and the questions to ask. It applies to WordPress sites, which is what we look after, but most of it holds for any site built on a content management system.
Is a care plan the same as website maintenance?
Mostly, yes. “Website maintenance” is the term most people search for; “care plan” is what many WordPress companies call a monthly package of it. The difference that matters is not the name but the arrangement. A care plan is ongoing and paid monthly, so someone is responsible between problems. Hourly support is paid when something goes wrong, so nobody is watching in between.
What should a website care plan include?
Software updates, tested
WordPress itself, the theme and every plugin need regular updates. WordPress installs minor core updates on its own by default, but plugin and theme auto-updates are off unless someone switches them on, one by one (WordPress.org, plugin and theme auto-updates). WordPress also only actively supports its latest version; fixes for older versions are a courtesy, not a promise (WordPress.org, security).
A care plan should apply those updates on a schedule, check the site afterwards, and roll back when an update breaks something. WordPress’s own upgrade guide is clear that a rollback without a backup is close to impossible (Upgrading WordPress).
The server and PHP underneath
WordPress runs on PHP, and PHP versions reach end of life on a fixed timetable. PHP 8.1 stopped receiving security fixes on 31 December 2025, and PHP 8.2 stops on 31 December 2026 (php.net, supported versions). A plan that includes hosting should move your site to a supported version before that happens, and test it first.
Backups you can actually restore
WordPress’s backup guidance says to back up both the database and the files, weekly for a small site and daily for a busy one, and to keep several copies in different places (WordPress, backups). The Canadian Centre for Cyber Security adds the part that is often skipped: check regularly that backups can actually be restored, and keep long-term copies offline (control BC.7, baseline cyber security controls).
Security
The basics come from WordPress’s own hardening guide: keep plugins updated, delete the ones you do not use, and keep file permissions tight (Hardening WordPress). Add to that: every login in a named person’s hands with only the access they need, accounts removed when people leave, and someone watching Google Search Console’s security issues report, which flags hacked content and malware Google has found on the site.
Monitoring
Someone should know the site is down before your members tell you. That means uptime checks, plus a regular look at Search Console for new errors (Google, Search Console) and at Core Web Vitals, Google’s measures of how fast and stable pages feel on real devices (Google, Core Web Vitals).
Fixes when something breaks
A plan should say who fixes problems, how you report them, and how quickly someone responds. “We will look into it” is not a response time.
Accessibility, kept up
A site that met WCAG at launch does not stay that way by itself. The W3C’s guidance on sustaining accessibility makes the point that changing content can introduce new problems, and recommends checks as part of publishing and regular reviews (W3C, sustain). If accessibility matters to your organization, and under the AODA it may be a legal duty, ask how the plan handles it.
A person, and a record
A named person who answers, and a short monthly record of what was updated, what was fixed and anything that needs a decision.
What does a care plan usually not include?
- New features or a redesign. Adding online registration or a member area is a project, even if the provider quotes it for you.
- Writing or editing your content. News, events and pages belong to your team. The rule we work by is simple: you edit, we manage.
- Third-party costs. Premium plugin licences, email services and payment processing are often billed separately. Ask who holds each account.
- Recovering from a serious incident. Some plans include hack clean-up; others bill it as extra work. Find out before you need it.
- Undoing changes someone else made. If another developer or a volunteer changes the site’s code, fixing it may fall outside the plan.
Do websites need monthly maintenance?
A site built on WordPress or any similar system does. Updates for plugins and themes arrive all the time, often to close security holes; only the latest WordPress version is actively supported; and PHP versions expire on a published schedule. Monthly is the natural rhythm for checking and reporting, even when updates themselves happen more often.
A static site that never changes needs much less. Most organization websites are not static: they take registrations, publish news and run on plugins.
Questions to ask before you sign a care plan
- Which updates are included, how often, and do you test the site after each one?
- How often are backups taken, where are they stored, and when did you last test a restore?
- Is hosting included, and which PHP version will the site run on?
- How do we report a problem, and how quickly will someone respond?
- Is hack clean-up included, or billed separately?
- Is there time for small improvements each month, and what counts as small?
- How do you keep the site accessible as content changes?
- Who owns the domain, the hosting account and the backups, and can we leave with them?
Disclosure: GMNI offers a care plan called Managed Care. These are the questions we would want you to ask us, too.
If you would like to go through these questions for your own site, schedule a discussion.
Related: Managed Care · Who should manage your organization’s website? · Does the AODA apply to your organization’s website?
Sources (checked 30 September 2026)
- WordPress.org, Plugin and theme auto-updates (updated 13 January 2023): https://wordpress.org/documentation/article/plugins-themes-auto-updates/
- WordPress.org, Security: https://wordpress.org/about/security/
- WordPress Developer Resources, Upgrading WordPress (updated 1 July 2026): https://developer.wordpress.org/advanced-administration/upgrade/upgrading/
- WordPress Developer Resources, WordPress backups (updated 4 June 2026): https://developer.wordpress.org/advanced-administration/security/backup/
- WordPress Developer Resources, Hardening WordPress (updated 7 January 2026): https://developer.wordpress.org/advanced-administration/security/hardening/
- PHP, Supported versions: https://www.php.net/supported-versions.php
- Canadian Centre for Cyber Security, Baseline cyber security controls for small and medium organizations (2020): https://www.cyber.gc.ca/en/guidance/baseline-cyber-security-controls-small-and-medium-organizations
- Google, Security issues report: https://support.google.com/webmasters/answer/9044101
- Google Search Central, Get started with Search Console (updated 10 December 2025): https://developers.google.com/search/docs/monitor-debug/search-console-start
- Google Search Central, Core Web Vitals (updated 10 December 2025): https://developers.google.com/search/docs/appearance/core-web-vitals
- W3C Web Accessibility Initiative, Sustain: https://www.w3.org/WAI/planning-and-managing/sustain/
