The contact form stopped working sometime last Tuesday. You found out on Friday, when a customer called to ask why nobody had answered them.
That is what doing your own WordPress maintenance usually costs. Not a dramatic outage at 2am, just three quiet days of leads you will never know you lost.
Here is the short answer, and it is probably not the one you expect from a company that sells maintenance plans. WordPress has patched its own core automatically since 2013, so the thing most owners worry about is largely handled already. The exposure is everywhere else. Plugins account for 91% of WordPress vulnerabilities, and plugin updates are opt-in, one extension at a time. If your site brings in leads, takes bookings, or takes money, paying someone between $125 and $695 a month to own that gap is usually cheaper than the first bad week. If it does not, doing it yourself is a reasonable call, and we will say so further down.
What WordPress already handles without you
Most articles on this topic open by telling you to log in every week and click the update button. That advice is more than a decade out of date.
Since version 3.7 shipped in 2013, WordPress has applied its own minor and security releases automatically, in the background, by default. WordPress's own documentation puts it plainly: “you don't have to lift a finger to apply minor and security updates.”
You watched this work twelve days ago, whether or not you noticed. On July 17, 2026, WordPress patched wp2shell, a pair of flaws including CVE-2026-63030: unauthenticated remote code execution in core itself. No plugin required, no login required, complete site takeover on a stock install. The security team force-pushed the fix through the auto-update system across three release branches at once, and CISA added it to its Known Exploited Vulnerabilities catalog four days later.
That is the system working exactly as designed. It is also close to the last time it will save you, because core is not where your risk lives.
The part nobody automates for you
Patchstack's State of WordPress Security in 2026 counted 11,334 new vulnerabilities across the WordPress ecosystem in 2025, up 42% from 7,966 the year before. Of those, 91% were in plugins and 9% in themes. WordPress core accounted for six, and Patchstack rated all six low priority.
Six, out of eleven thousand.
Plugin and theme auto-updates do exist. They are off by default, and you switch them on one extension at a time, which most owners never do because nobody tells them it is an option. So the layer carrying 91% of the risk is the layer still waiting on a human.
Two more numbers from the same report explain why waiting is expensive. Nearly half of vulnerabilities, 46%, had no fix available on the day they became public knowledge, up from 33% the year before. And when Patchstack weighted its data by how intensely each flaw was actually being attacked, the median time from disclosure to first exploit was five hours.
Five hours. Not five days. Which means “I check my site every Monday” is not a maintenance strategy, and it also means updating on a schedule is a second line of defense rather than a first. For almost half of these, on the day the world finds out, there is nothing to update yet.
About that “required” update order
You will read on a lot of agency blogs that there is a required sequence: core first, then themes, then plugins. There is not.
WordPress.org publishes no such rule. WPBeginner argues for core, then plugins, then themes, because extensions are built against current core. Other practitioners argue the exact reverse, so that you are not running a brand new core against extensions whose compatibility fixes have not shipped yet. WordPress publishes no official update order. What the internet has instead is a large number of people with very firm opinions about one.
What everyone genuinely agrees on is duller and more useful. Back up first. Test on a copy of your site rather than the live one. Change one thing at a time, so when something breaks you know what did it.
Where doing it yourself breaks down
The backup you have never restored
A backup you have never restored is a hope, not a safety net. We got reminded of that in July.
An author came to us with a site his publisher had built for him years earlier. He had never held the logins. Not the hosting, not the domain, none of it. In early July the site collapsed into a 500 error, and there was nobody left to call.
We pulled his most recent backup, dated June 30, and started a clean restore onto managed hosting. The backup was infected.
Inside it we found three web shells, five obfuscated malware payloads, and six hidden administrator accounts. One of them had been created at 3am and given a forged 2019 registration date so it would look old and trusted sitting in the user list. His own security plugin's log had been swept up in the backup too, and it dated the campaign to October 10, 2025, with more than 580 failed login attempts behind it.
He had been compromised for roughly nine months. Every backup he owned was a backup of a hacked site.
Scott Sumner unpacked all 23,971 files in an isolated workspace, cut out eight malicious files and fifteen marker files, removed four plugins including two fakes planted to look legitimate, rebuilt core from clean managed files, and issued new security keys so any attacker session still open died on the spot. The final sweep came back clean, and core verified byte for byte against WordPress.org's own checksums.
Nothing in that job was an update gone wrong. It was nine months of nobody looking.
The update that takes the site down
This is the failure most owners actually picture: a plugin updates, something conflicts, and you get a white screen where the admin login used to be.
Let us be straight about the evidence, because most articles are not. No published dataset ranks the causes of WordPress outages. Anyone telling you plugin conflicts are the single most common cause is guessing, including the hosting companies that say it.
What we can tell you is what we do about it. Every Website HQ plan, including the $125 tier, runs updates on a staging copy of your site before anything touches the live one. Most plans at that price do not include staging at all, which is worth knowing when you compare.
The time, counted honestly
Across the sites we manage, keeping a typical business site current runs a few hours a month once you count everything: reviewing what is pending, testing it somewhere safe, confirming the backup actually ran, and reading the security alerts closely enough to know which ones matter.
If those hours come from you, or from someone on your team who is not a WordPress professional, there is a second cost underneath the first. The learning curve. The second-guessing. The cleanup afterward.
On what downtime costs, a warning about the numbers you will see. Figures between $8,000 and $300,000 an hour get quoted constantly in articles like this one. Nearly all of them trace back to enterprise IT outage or ransomware research and have very little to do with a small business website going quiet. The most recent survey that actually asked small businesses, from Calyptix and ITIC in 2025, found 37% of 715 respondents put an hour of IT downtime between $1,000 and $5,000.
Your own number beats all of theirs anyway. Take what your site produces in a normal month, in revenue or in leads you can put a value on, and divide by the hours you are open. That is your cost of an hour offline, and it is the only figure worth setting next to a monthly plan price.
Your time should be protected by your site, not consumed by it.
What handing it off actually costs
Website HQ's Site Care Club runs three tiers: Covered at $125 a month, Managed at $349, and Mission-Critical at $695.
The difference between them is how much hands-on human time you get, not how safe your site is. Every tier includes the same care stack: core, theme, and plugin updates, a staging environment with updates tested before they go live, daily backups written to two separate servers, 24/7 monitoring with daily security scans, Cloudflare firewall and CDN, free SSL, security hardening, and hack recovery with malware cleanup if the worst happens. There is a 30-day satisfaction guarantee on all of it, and if we are not the right home for your site we will help you move on cleanly.
For a full breakdown of what drives the difference between $125 and $695, and how that compares to hiring a freelancer, see our WordPress management pricing guide.
When doing it yourself genuinely makes sense
DIY WordPress maintenance works fine in real circumstances, and we would rather tell you that than sell you something you do not need.
If you are a developer, or you have deep hands-on familiarity with WordPress, and the site you are managing has a small plugin footprint and no revenue riding on it, the overhead is completely manageable. Turn on plugin auto-updates, keep an off-site backup you have actually restored at least once, and get on the security mailing lists for whatever you run. That is a legitimate setup.
The calculation changes when the site starts carrying weight. If it generates leads, books appointments, or takes payments, an hour offline during your busiest window costs real money. And a compromise carries consequences past the cleanup bill. Google's Security Issues report can attach a “This site may be hacked” label to your listing and trigger a full-page browser warning before anyone reaches you. Injected spam can separately earn a manual action called “Site abused with third-party spam,” where a human reviewer at Google demotes or removes your pages with no visible signal to you at all. Sucuri found SEO spam on more than 20% of the sites it cleaned.
The useful question is not whether you could handle WordPress maintenance yourself. It is what that time is worth, and what it costs you the week it goes wrong.
Looking for WordPress maintenance services in Jacksonville? Website HQ handles updates, security, and backups so you can focus on running your business. See our plans at websitehq.com/wordpress-site-care-club.
Four questions worth asking any provider, us included
- Do you test updates somewhere other than my live site? If the answer is no, they are updating in production and you are the test environment.
- Where do backups go, and have you ever restored one? Backups stored on the same server they are protecting are not backups. Ask where the second copy lives.
- What happens if an update breaks something? You want a rollback path described in specifics, not reassurance.
- Who answers when it breaks, and during what hours? Get the real answer. Ours is a person, by email, within one business day, 9am to 5pm Eastern Monday through Friday.
That last one is worth asking us as hard as you ask anyone else. Julie Chenell, who runs a portfolio of sites we manage, put it in her newsletter this way: “Website Support: Jeane Sumner. She will respond to me on Thanksgiving Day at 7am if my WordPress site is down for any reason. She manages a bunch of my sites (both personally and with Funnel Gorgeous), is the person who coded the new design last year, and can do SEO, DNS, you name it. She's someone you want in your corner.”
Frequently asked questions
Does WordPress update itself?
Partly, and this is the most misunderstood thing about WordPress maintenance. Minor and security releases to WordPress core have installed themselves automatically since version 3.7 in 2013. Major releases do not. Plugin and theme auto-updates are available but switched off by default, and you enable them individually. Since plugins carry 91% of WordPress vulnerabilities, that unattended layer is where nearly all the real exposure sits.
How often do WordPress plugins need updating?
More often than most owners expect, and unevenly. Security plugins can ship several releases in a month and then go quiet for a quarter. Wordfence, installed on more than five million sites, shipped three releases across three consecutive weeks in spring 2026. A weekly review catches most of it, but given that Patchstack measured a five-hour median from disclosure to first exploit, anything flagged as actively exploited needs attention the same day.
What happens if I stop maintaining my WordPress site?
Unpatched vulnerabilities accumulate, mostly in plugins. If the site is compromised, the damage is not only technical: Google can flag your listing with a “This site may be hacked” warning or show visitors a browser interstitial before they reach you, and injected spam can trigger a separate manual action that quietly demotes your pages. Recovery from a compromise without a clean backup takes days and costs considerably more than prevention would have.
How much does WordPress maintenance cost?
Website HQ's plans run $125, $349, and $695 a month, and every tier includes the same security and backup stack. The tiers differ in how much hands-on development and support time is included. Freelance rates for one-off work generally run $50 to $150 an hour, so a single incident often costs more than several months of a plan. Our pricing guide breaks the comparison down properly.
Can I maintain my WordPress site myself?
Yes, and for some sites you should. It requires enabling plugin auto-updates, keeping an off-site backup you have restored at least once so you know it works, watching for security disclosures on what you run, and having a plan for the day an update breaks something. If that sounds manageable and your site is not carrying revenue, do it yourself. If reading that list made you tired, that is your answer too.
Stop being your own IT department
Website HQ keeps your WordPress site updated, backed up, and monitored daily, so you can run your business, not your website. See what the Site Care Plan covers at websitehq.com/wordpress-site-care-club.

You didn't start your business to become a WordPress technician, yet here you are treating your most critical business asset like a hobby project. While you're spending hours on updates and crossing your fingers that nothing breaks, your competitors are focused on what actually makes money.
👋 I'm Jeane Sumner, and Website HQ doesn't just host your site – we armor it, optimize it, and monitor it so you can get back to running your business instead of fixing it. Book your Site Care strategy call and never worry about your website again.
Written by Jeane (sounds like Genie) Sumner, founder of Website HQ, a boutique WordPress company in Jacksonville, Florida. Website HQ has kept WordPress sites online for small businesses since 2015 and was named to the Jacksonville Business Journal's list of Top Advertising and Marketing Agencies for 2026. Every statistic in this article was verified against its primary source on July 29, 2026. Read how we make our content.