Website maintenance is not exciting work. It is the kind of work that matters precisely because you do not notice it when it is being done correctly — and you notice it very quickly when it is not. We have been maintaining WordPress sites for clients since 2012 and we have seen both sides of that equation.
WordPress, WooCommerce, and the plugins that extend them receive regular security updates. A vulnerability in an outdated plugin can give an attacker access to your database, your admin panel, or the ability to inject malicious code into your pages without your knowledge. Most successful WordPress security incidents target known, documented vulnerabilities in plugins that were not updated. The patch existed. The update was just never applied. Regular, tested updates are the most effective preventative security measure available to any WordPress site owner.
WordPress sites drift in performance over time without active management. The database accumulates post revisions, draft content, transient data, and orphaned metadata from plugins that have been removed. Plugin updates occasionally introduce code that is less efficient than what it replaces. Image uploads accumulate in the media library without compression being applied. Caching configurations that worked correctly at launch can stop working as expected after a hosting environment change or a plugin update. A site that passed Core Web Vitals at launch may fail them 12 months later without any dramatic incident — just accumulated drift that nobody was watching.
We update WordPress core and all active plugins monthly — but not blindly. Updates are applied to a staging environment first and tested for conflicts, regressions, and broken functionality before being applied to the live site. If an update causes a problem on staging, we fix it before it affects your live site and your live clients. This is what separates proper maintenance from just clicking the update button and hoping.
We run automated security scans for malware, unauthorised file changes, and known vulnerability signatures. If a security issue is detected, it is investigated and resolved as a priority — not queued alongside routine maintenance items and addressed on the next monthly cycle. Security problems get worse the longer they are left.
If your site goes down, we know before you do. Uptime monitoring alerts us to downtime immediately — we investigate the cause and work to restore the site without waiting for a client support ticket to arrive. For e-commerce sites in particular, every minute of downtime has a direct revenue cost.
Core Web Vitals scores are reviewed monthly against the baseline established at launch. If scores degrade — LCP increasing, CLS appearing on pages that previously had none — we identify the cause. If a specific fix is outside the scope of the standard maintenance plan, we document what needs to happen and provide a separate quote for the resolution.
We maintain WordPress sites built by other developers and agencies — not just sites we have built ourselves. The process starts with a site audit: we review the current state of all active plugins and their update history, the WordPress version, the hosting environment configuration, the security setup, and the current performance baseline. This gives us a clear picture of what we are taking on and identifies anything that needs immediate attention before a monthly plan begins.
If a site has significant technical debt — severely outdated plugins, active security vulnerabilities, or performance issues that need fixing before maintenance can be meaningful — we document what we find and provide a quote for a cleanup phase. We do not take on maintenance for sites in a state we cannot stand behind, because starting a maintenance relationship that way does not serve either party well.
Our website maintenance service is available for businesses across the United States, Canada, and Australia. All work is delivered by our 14-person in-house team. Founded in 2012, Saints Soldier has 14 years of experience maintaining WordPress sites — and enough experience to know exactly what deferred maintenance eventually costs.