Process
Website Maintenance: What Your Site Actually Needs After Launch
By the Coast Creative team4 min read
Your website launched. It looked great. Then eight months went by, and a client mentions in passing that they filled out your contact form back in spring and never heard anything.
That is what neglected maintenance actually looks like. Not a hacked homepage with a skull on it. A quiet form that stopped sending, a plugin update that broke a layout on phones, a hosting plan that got slower as traffic grew. None of it announces itself. You find out from a customer, or you never find out at all.
Here is what a business website needs after launch, what you can check yourself in fifteen minutes a month, and which line items on a maintenance plan are worth the money.
Backups you can actually restore
You want daily automatic backups, stored somewhere other than the server your site runs on, kept for at least thirty days. Most decent hosts include this. The part people skip is verification.
Ask whoever manages your hosting to do one test restore to a staging copy. A backup nobody has ever restored is a guess. Ten minutes of checking now is the difference between a bad afternoon and a rebuild.
Updates, done in the right order
WordPress core, themes, and plugins ship updates constantly — a mix of new features and security patches. There are two ways to get this wrong. One is never updating, which leaves known holes open. The other is hitting update-all on the live site at 4pm on a Friday.
The middle path: update on a staging copy first, then load the homepage, a service page, and one form to confirm nothing shifted. Then push it live. Monthly is fine for routine updates. Security releases should go same-day.
On Shopify, the platform handles itself and your job is the apps. Every app you install adds scripts to your storefront. Audit them twice a year and remove what you stopped using — and check that the leftover code came out with it, because it often doesn't.
Test your forms like a stranger would
Forms are the most common silent failure on a business website. Email routing changes. A sending plugin's API key expires. Someone at your company deletes the address the form points to. Your host tightens spam filtering. The form still says "thanks, we'll be in touch," and the message goes nowhere.
Once a month, submit your own contact form from your phone on cell data — not the office wifi, which may be whitelisted. Write a real message, not "test." Confirm it lands in the inbox and not in spam. Do the same for your quote request, booking form, and newsletter signup.
Better yet, have leads saved to the site's database or pushed to a spreadsheet in addition to email. Then a mail problem costs you a delay instead of the lead.
Watch security and speed, not vanity metrics
Your SSL certificate renews automatically until the day it doesn't, and an expired certificate throws a full-page browser warning that stops visitors cold. Put a free uptime monitor on the site — they ping every five minutes and text you when the site goes down or the certificate lapses.
Speed drifts, too. Run PageSpeed Insights on your homepage and one interior page every quarter. The usual culprits are predictable: a huge uncompressed image someone dropped into a blog post, a new tracking script from a marketing tool, or a plugin doing more than it needs to.
Keep a little content moving
Search engines and AI assistants both favor sites that show signs of life. That does not mean blogging every week. It means a service page rewritten when your offer changes, new project photos with real captions, current details where you list them, and a copyright year that isn't two years old.
Two meaningful updates a quarter will do more for you than twelve thin posts written to hit a quota.
What you probably don't need to pay for
Auto-generated monthly SEO reports that nobody reads. Three overlapping security plugins. "Speed optimization" that turns out to be a caching plugin someone switched on once in 2023. A retainer with unlimited edits when you request two edits a year.
Ask any maintenance plan for a plain list: what gets done, how often, and who does it. If the answer is vague, that is the answer.
A fifteen-minute monthly routine
Submit your contact form from your phone. Load the homepage and two interior pages on that same phone and look for broken images or a layout that shifted. Open your analytics and check two things only: is traffic roughly steady, and are inquiries still arriving. Log into your host or backup tool and confirm the last backup date is recent. Apply pending updates, or confirm whoever handles that has.
That's it. Most months you'll find nothing. The one month you find something, you'll have caught it before a customer did.
None of this needs a developer. It needs someone paying attention, and it needs to be clear who that someone is. When we hand off a site, clients get the logins, the hosting details, and a plain rundown of what to check and when — whether they keep us on for upkeep or take it in-house. The site is theirs either way.
The worst maintenance plan is the one where nobody is sure whose job it is. Pick a person — you, someone on your team, or your developer — and write it down.
