Website stewardship guide 02

Ongoing Website Maintenance for Small Businesses

Your site can look unchanged while software, forms, and outside services change around it. A useful maintenance plan says what gets checked, what happens when something breaks, and how you will know the work was completed.

← All website stewardship guidance
The operating sequence
  1. List what needs care

  2. Review alerts

  3. Prepare changes

  4. Test the live site

  5. Report open work

Why this matters

A working home page can hide a broken inquiry form.

Maintenance includes the visible parts of the site and the systems behind them. A software update can affect a menu. A changed mailbox can stop inquiries arriving. An expired subscription can disable a booking feature. These problems need different checks and different people to resolve them.

Ask your provider to describe the routine in terms you can verify: which customer paths are tested, which updates are handled, who receives alerts, and what happens outside the recurring scope. A short change record should tell you what changed, whether the important tasks still work, and what needs your decision.

Responsible practices

Build a routine around the website you actually use.

01

Agree on the maintenance scope

Identify the platform, major integrations, important pages, and customer paths. Record what the provider maintains, what the host handles, and what your staff must report or approve. A static site, a content-management system, and an online store have different needs. The plan should reflect those differences.

02

Use a calendar and respond to urgent triggers

Schedule routine checks, but give urgent security notices, outages, and delivery failures their own response path. A risk-based approach considers the affected software, exposure, and business impact. Agree who can approve an emergency change and who is available when an alert arrives.

03

Prepare before changing the live site

Ask the provider to check compatibility, create a suitable recovery point, and test significant changes in a separate preview when practical. A rollback is the route back to a known working version. It needs to cover any affected data or configuration as well as the page files.

04

Check where software comes from

Install updates, themes, and plugins only from the official source, such as the vendor or the platform's own directory. Never use "free" copies of paid plugins; they can carry hidden malicious code. On WordPress and similar platforms, remove plugins that no longer get updates, even if they still seem to work. Ask who watches security notices for the tools that build and publish the site.

05

Test, then report the exceptions

After relevant changes, check the affected pages on a phone and desktop, complete a test form, and follow call or booking links. The provider should also check technical failures such as broken redirects and unexpected indexing settings. A useful report names the work, the checks, and anything still open; you should not need to decode a list of plugin version numbers.

Worked example

A sample maintenance calendar and report

Illustrative planning example, not a service commitment. The frequency of each check should suit the site, its risks, and the responsibilities you agree with your provider.

Ongoing alerts
Route availability, certificate, security, and delivery alerts to a named responder. An alerting tool needs a person and an agreed response process behind it.
After a relevant change
Test the page or feature that changed. If form routing changed, confirm that a test request reaches the right queue and that staff can reply.
At the agreed routine review
Check supported software, backups, access, broken links, and current business details. Review outstanding issues instead of starting a new list each time.
A useful report entry
Changed: inquiry-form recipient. Checked: mobile submission, receiving inbox, reply address, and failure message. Open: owner to confirm the holiday response wording.

Separate completed work from decisions awaiting the business. The report should make the next action obvious.

Maintenance runbook

Start with these owner checks.

What you can check

  1. 01

    Choose the pages and actions your business relies on most.

  2. 02

    Ask who receives an outage or form-delivery alert and what response is included.

  3. 03

    Agree how your team reports changed hours, services, staff, and links.

  4. 04

    Review the provider's change record and assign someone to answer open questions.

What to ask your provider to handle

  1. 01

    Keep a list of the site's software and a maintenance runbook: written steps for routine checks, urgent updates, rollback (returning to the last working version), and escalation.

  2. 02

    Test material changes before release where practical, then verify the affected customer paths and technical signals.

  3. 03

    Report completed work, unresolved issues, and decisions needed in a form the business can understand.

Avoid these failures

Common mistakes to avoid.

  • Waiting for the routine review to assess an urgent security or delivery problem.
  • Approving automatic changes without knowing who handles a failure.
  • Accepting a report that lists activity but never identifies failed checks or open decisions.

Good website care lowers risk, but no provider can guarantee uninterrupted service.

Questions business owners ask

Questions to settle with your provider.

01How often should maintenance happen?

Use a routine schedule plus event triggers. Urgent security notices, outages, and failed inquiry delivery need prompt assessment. Routine reviews can follow an agreed calendar that reflects the site and the support you have purchased.

02Should automatic updates be enabled?

That depends on the platform and the update. Ask how compatibility, backups, monitoring, and recovery are handled. Automation can reduce delay, but someone still needs to respond to a failed update.

03What should the maintenance report tell me?

What changed, what was checked, what failed or remains open, and which decisions need your input. The detail should let you understand the state of the site without interpreting technical version lists.

04Are content changes included in maintenance?

Check the agreement. Technical updates, approved text edits, new pages, redesigns, and integrations may have different allowances or prices. Ask the provider to identify the scope before work starts.

Primary guidance

Read the guidance behind this guide.

Plan the next step

Agree on website care you can understand and check.

Start the conversation