What maintenance actually means

Maintenance is the work that keeps a website working after the day it launched. It is not redesign, it is not new pages and it is not marketing.

A website is software sitting on a server, connected to a domain, protected by a certificate, and in most cases built on a content management system with extensions bolted to it. Every one of those pieces is maintained by someone else and changes on their schedule rather than yours. Maintenance is the routine of keeping them current and confirming that the site still behaves after each change.

It is invisible because it is only noticeable when it stops. A site that has been maintained looks exactly like a site that has not, right up until the morning it does not load.

Website maintenance in Finland: who is responsible for what

Three parties are usually involved, and the boundaries between them are where things fall through.

  • The hosting company keeps the server running, patches the operating system and often renews the certificate. It does not touch your site.
  • Your web provider updates the site software, checks that nothing broke and fixes it when it does, but only if that is in your agreement.
  • You handle content, photos, prices and opening hours, unless you have bought that too.

Read your agreement and work out which of the three columns is empty. In small Finnish companies the middle one is empty surprisingly often, because hosting came from one supplier and the site was built by another, and neither of them believes the updates belong to them.

Updates, backups and monitoring

These three are the core, and any agreement that does not name all three is incomplete.

Updates mean the platform, the theme and the extensions, applied on a schedule, with someone looking at the site afterwards to confirm nothing moved. Backups mean automatic copies kept off the same server, going far enough back that you can return to a version from before the problem started. Monitoring means something that checks the site is answering and tells a human within minutes when it is not.

Without monitoring, the person who discovers your site is down is a customer, and they discover it by going somewhere else.

The certificate that expires on a Saturday

The padlock in the browser comes from a certificate, and certificates expire.

When one lapses, visitors do not see a small warning. They see a full page telling them the connection is not private and that attackers might be trying to steal their information. Almost nobody clicks past that, and the few who do remember it afterwards.

Most certificates renew automatically now, which is precisely why nobody checks them and why the failures land at the worst moments. Renewal breaks after a server change, a DNS change or a migration. Somebody should be watching the expiry date, and it should not be the customer who has already left.

A static site and a WordPress site need different care

How much maintenance a site needs depends on what it is made of, and that is worth knowing before you choose.

A site built as plain HTML, CSS and JavaScript has almost no moving parts. No database to corrupt, no login exposed to the internet, no plugin to update. It still needs backups, a certificate and monitoring, but the monthly work is close to nothing.

A WordPress site has a database, an admin login that the whole internet can see, and a stack of third party code. It needs attention every month without exception. Neither option is better in the abstract. The question is whether the flexibility you gain is worth the upkeep you take on.

Plugins are where most of the trouble starts

The plugin is the single most common cause of a broken or compromised small business website.

Each one is software from an author you do not know, with its own release cycle, its own security record and its own chance of being abandoned. An abandoned plugin keeps working for a year or two and then becomes a known hole that automated scanners find, with no interest at all in who you are or how small your company is.

The practical rule is to keep the list short and to know, for each item on it, what it does and what happens if it disappears. If nobody can answer that, the honest position is that the site is unmaintained whatever the invoice says.

The cost of skipping it

Skipping maintenance is cheap for about a year and then it is not.

What happens, in rough order: rankings slip as the site gets slower and staler, forms stop delivering and nobody notices, a plugin conflict breaks the layout on phones, the certificate lapses over a holiday weekend, and at some point an old vulnerability is used to inject spam pages into your site. That last one is the expensive one, because cleaning it costs more than three years of upkeep and a search engine may flag the site while you work.

There is a slower cost too. A site nobody touches becomes a site nobody trusts, and eventually the answer stops being repair and starts being a rebuild.

Contact forms fail quietly

The most expensive maintenance failure is a contact form that has stopped sending mail, because nothing about it looks wrong.

The visitor fills it in, sees a thank you message and waits for a reply that never comes. You see no error, no bounce and no enquiry. Mail delivery rules have tightened across the industry, so forms that used to send happily from a web server now get silently rejected, and the failure is invisible from both ends.

Test your own form once a month from a phone that is not on your office network. While you are in there, check that what the form collects and where it ends up still match what your privacy notice promises.

Speed drifts downwards on its own

A site that was quick at launch gets slower without anyone doing anything obviously wrong.

Images get uploaded at full camera size because it was quicker that way. A tracking script goes in for a campaign and never comes out. A plugin adds its own stylesheet to every page including the ones that do not use it. None of these is dramatic alone and together they add seconds.

Part of maintenance is a periodic sweep. Resize what is oversized, remove the scripts nobody reads any more, and open the site on a phone using mobile data rather than office wifi. That last test is the honest one.

Content upkeep is a different job

Technical maintenance keeps the site alive. Content upkeep keeps it true, and the two usually come from different places or from nobody at all.

Out of date opening hours, a phone number for someone who left in spring, a price list from two years ago, a news page whose latest item is from a previous summer. Each one costs you a customer quietly and none of them shows up as an error.

The fix is either a monthly slot with your provider or a system you can edit yourself without breaking the design. A light content management system that only exposes the text and the images is usually enough, and it avoids the situation where changing a phone number needs a developer.

Backups only count if someone has restored one

An untested backup is a belief, not a safeguard.

The common failures are all boring. The backup runs but covers only the files and not the database. It saves to the same server that has just died. It has been failing silently for five months and nobody read the notification. Or it keeps seven days and the problem started in July.

Ask your provider to restore your site to a test address once. Not a description of how it would work, an actual restore. It takes them an hour and it is the only way anybody ever finds out.

What a maintenance agreement should list

A real agreement names things and frequencies. A vague one names a price.

  • What is updated, and how often.
  • How backups are taken, where they are stored and how far back they reach.
  • What is monitored, and who gets told.
  • Response time when the site is down, and whether that applies at weekends.
  • How many hours of content changes are included, and the rate beyond them.
  • Who handles the certificate and the domain renewals.
  • What is explicitly not included.

The last line is the one that prevents arguments.

What to ask your provider

Send these by email and keep the reply.

  1. When was the last update applied to my site?
  2. Where is my most recent backup and how old is it?
  3. Has anyone ever restored it?
  4. Who is told first if the site goes down at two in the morning?
  5. When does the certificate expire?
  6. Which of these is inside my current price, and which is billed separately?

Clear answers to all six are a good sign. Vague answers to any of them mean the work is probably not happening, whatever you are paying for it. If you are choosing a provider rather than checking one, our hosting and upkeep page sets out what that covers.

What you can reasonably do yourself

Not all of it needs a contract, and a small routine catches most of what matters.

Once a month, open your own site on a phone that is not yours, send yourself a message through the contact form and confirm it arrives. Once a quarter, check the domain renewal date and the certificate expiry, and fix any content that has gone out of date. Once a year, ask for a restore test and watch it happen.

That is perhaps two hours a year of your own attention. The technical updates still need somebody competent, but the checking does not, and the checking is what turns a silent failure into a five minute fix.