What Actually Breaks When You Skip Website Maintenance
Nothing happens the month you cancel maintenance. Here is the timeline of what decays afterwards, which failures cost the most, and what repairs cost against prevention.
On this page
- Why a website decays when you change nothing
- A timeline of neglect
- The five things that actually go wrong
- What maintenance should actually include
- What it costs to fix versus prevent
- If you want to do it yourself
- What to do if the worst has already happened
- Questions for your current provider
- Frequently asked questions
Website maintenance is the easiest line item to cancel. Nothing visibly happens when you stop paying it. The site keeps loading, the phone keeps ringing, and for a few months it genuinely looks like you found free money.
Then one Tuesday the contact form stops sending, or the site starts redirecting to a pharmacy in another language, or Google quietly drops you because the pages now take nine seconds to load on a phone. This article is about what actually decays, in what order, and how much the repairs cost compared with the prevention.
Why a website decays when you change nothing
People assume a website is like a printed brochure: finish it, and it stays finished. It is closer to a car. A modern site sits on a stack of software that keeps moving underneath it, whether or not you touch anything.
The server's PHP version gets upgraded by your host. WordPress releases a security patch. A plugin author sells their plugin to someone who abandons it. Your SSL certificate expires. A browser changes how it handles cookies. Google changes what counts as a fast page. None of these are things you did, and all of them can break something.
The most common conversation we have with a new client starts with "it was fine, we didn't change anything". That is usually true, and it is exactly the problem.
A timeline of neglect
Decay is predictable enough to put on a calendar. Here is roughly what happens to an unmaintained small business site.
| Time since last maintenance | What is typically happening |
|---|---|
| 1–3 months | Nothing visible. Plugin and core updates are queuing up. A couple of the pending ones are security patches with published exploits. |
| 3–6 months | Bots are probing known vulnerabilities daily. Spam is accumulating in forms and comments. The site is measurably slower as the database fills. |
| 6–12 months | Something breaks — commonly the contact form, a booking widget or a payment integration. Broken links accumulate. Speed scores have dropped enough to affect rankings. |
| 12–24 months | A real chance of compromise: injected spam pages, hidden redirects, or the site used to send mail. Plugin versions have drifted so far that updating becomes risky. |
| 24 months+ | Updating in place is now genuinely dangerous because the jump is too large. Rebuilding is often cheaper than repairing. Unsupported PHP means the host may force an upgrade that takes the site offline. |
The five things that actually go wrong
1. Security holes that get found automatically
Nobody hand-picks a small plumbing company to hack. Bots scan the entire internet looking for known vulnerabilities, and when a plugin flaw is published, exploitation attempts start within hours. Your site is not targeted; it is found.
What happens next is rarely dramatic. Most compromises are quiet: hidden spam pages added to your site to sell someone else's products, or a redirect that only fires for visitors arriving from Google, so you never see it yourself. Businesses often discover it weeks later when a customer mentions it, or when Google flags the site with a warning that collapses traffic overnight.
Search Google for site:yourdomain.com and look at the results. If you see pages you did not create — often in another language, or about products you do not sell — your site has been compromised and is hosting spam. This check takes ten seconds and is worth doing right now.
2. The contact form silently stops working
This is the single most expensive failure we see, and the most common. Forms break because a plugin updates, a mail provider tightens authentication, or a spam filter starts rejecting messages the site sends. The form still shows "thank you, we'll be in touch". The message goes nowhere.
Because nothing looks wrong, this can run for months. We have picked up sites where a year of enquiries had been vanishing. There is no way to recover those; the sender assumes you ignored them and calls a competitor.
A maintenance plan should include an actual test submission every month. Not a code check — a real message, sent and confirmed received.
3. Speed erodes
Sites get slower over time almost regardless of what you do. Images get uploaded at full camera resolution. Plugins accumulate. Databases fill with revisions, spam comments and expired sessions. Each addition is small; the aggregate is not.
Speed is a ranking factor and, far more importantly, a conversion factor. The gap between a two-second and a five-second load is a large share of your mobile visitors leaving before they see anything.
4. Broken links and dead pages
Every site develops rot. Pages get renamed, a supplier's site restructures, a PDF is deleted. Internally this wastes the crawl budget search engines allocate to you and frustrates visitors; externally it means the link somebody kindly gave you now points at an error page.
5. Backups that turn out not to exist
Almost everyone believes they have backups. Roughly half do. The others have a host who keeps three days of snapshots — useless if a compromise happened two weeks ago — or a plugin that quietly stopped running a year back.
An untested backup is not a backup. The only way to know is to restore one somewhere safe and look at it. If your maintenance plan does not mention restore testing, ask when a restore was last performed.
What maintenance should actually include
"Maintenance" covers everything from an automated update script to a genuine ongoing relationship. This is what the line items should mean.
| Line item | What it should mean | What it sometimes means |
|---|---|---|
| Updates | Core, plugins and themes updated on a staging copy first, with the site checked afterwards. | An automated script that updates everything at 3am and nobody looks until you complain. |
| Backups | Daily off-site copies, retained for at least 30 days, with periodic restore testing. | The host's three-day snapshots, never tested, stored on the same server. |
| Security | A firewall, malware scanning, login hardening, and a plan for what happens if it does get in. | A free plugin installed once in 2022. |
| Uptime monitoring | Checks every few minutes and a human notified out of hours. | A daily email nobody reads. |
| Performance | Caching configured, images optimised, Core Web Vitals reviewed quarterly. | A caching plugin activated at launch and never revisited. |
| Content changes | A stated number of hours a month for small edits, with an hourly rate beyond it. | "Minor changes included", never actually defined, and disputed later. |
| Reporting | A short monthly note: what was updated, what was found, what needs a decision. | Silence. |
What it costs to fix versus prevent
The economics are unusually clear-cut here, which is why this is one of the few things we push clients on.
| Problem | Typical cost to fix | Cost to have prevented it |
|---|---|---|
| Malware cleanup and removal from Google's blocklist | $500–$2,000, plus days of lost traffic | Included in any real plan |
| Three months of enquiries lost to a broken form | Unmeasurable, often thousands | A five-minute monthly test |
| Recovery with no working backup | $1,250+, or rebuilding entirely | Roughly $6 a month of storage |
| Emergency out-of-hours repair | $125–$250 an hour | Usually avoided by updating on schedule |
| Rebuilding a site too outdated to update | $2,000–$7,500 | $50–$225 a month |
Our own maintenance plans start at $49 a month and include updates, backups with restore testing, uptime monitoring, security scanning, monthly form tests and a block of time for small changes.
If you want to do it yourself
Maintenance is not mysterious, and a capable owner can absolutely handle a simple site. Here is a realistic schedule.
Weekly, fifteen minutes
- Load the site on your phone. Actually look at it, including a page deep in the structure.
- Submit the contact form and confirm the message arrives.
- Apply pending plugin and core updates, after checking a backup exists.
Monthly, an hour
- Check Search Console for coverage errors and manual actions.
- Run the site through PageSpeed Insights and note whether it is getting worse.
- Skim analytics for a sudden drop on any page.
- Delete plugins you are not using. Deactivated is not removed, and an inactive plugin can still be exploitable.
Quarterly, half a day
- Restore a backup to a test environment and confirm it works.
- Check every form, every integration and every payment path.
- Crawl the site for broken links.
- Review who has admin access and remove anyone who has left.
- Check your domain and SSL renewal dates.
If you do nothing else after reading this, set up off-site daily backups with at least 30 days of history, and restore one to confirm it works. Every other problem in this article is recoverable when you have a good backup. Without one, a bad week can cost you the whole site.
What to do if the worst has already happened
If you are reading this because something has already gone wrong, the order of operations matters. Panicked fixes frequently destroy the evidence needed to work out how the attacker got in, which means they come straight back.
If the site is compromised
- Take a copy before you change anything, including the database. You may need it, and it is the only record of what happened.
- Change every password — hosting, control panel, database, CMS admin accounts, FTP. Do this from a clean device.
- Look for extra admin accounts. Attackers routinely add one so they can return after you patch the original hole.
- Restore from a backup taken before the compromise, if you have one and can date the intrusion. Restoring a backup that already contains the malware is the most common wasted day.
- Patch the way in — usually an outdated plugin — before putting the site back online. Otherwise you will be doing this again next week.
- Request a review in Search Console if Google has flagged the site, and check site:yourdomain.com afterwards to confirm the spam pages are gone from the index.
If the site is simply down
Check in this order: is the domain still registered and paid for, has the SSL certificate expired, is the hosting invoice unpaid, did an update fail. Those four account for the large majority of outages, and three of them are billing problems rather than technical ones.
Questions for your current provider
If you already pay for maintenance, these five questions will tell you whether you are getting it.
- When did you last restore a backup to check it works?
- Where are backups stored, and is that somewhere other than the same server?
- How would you know if my contact form stopped delivering?
- What is your response time if the site goes down on a Saturday?
- Can I have a list of what you actually did last month?
Vague answers to question five are the telling one. Real maintenance produces a record.
Frequently asked questions
Do I really need website maintenance?
How much should website maintenance cost?
What happens if I never update WordPress?
How often should a website be backed up?
My site is fine — why pay for something that changes nothing?
Can I do website maintenance myself?
If you are not sure what state your site is in, we will run a free health check — updates, security, speed, forms, backups — and send you the findings whether or not you become a client.

