← Back to the blog

· By Sergio Bermúdez

Website maintenance: why your website isn't finished on launch day

Updates, security, performance and content: what good website maintenance includes and what happens when it's neglected.

Many businesses treat their website like a printed brochure: it’s made once and forgotten. But a website is software, and software degrades if nobody looks after it. Dependencies age, vulnerabilities appear, browsers change and content goes out of date.

What happens when there’s no maintenance

The symptoms usually appear gradually:

  • Unpatched vulnerabilities. Every month, security flaws are discovered in libraries, plugins and frameworks. An un-updated website is the favourite target of automated attacks.
  • Things stop working. A form that no longer sends emails, a payment gateway integration whose API has changed, a certificate that expires.
  • Performance loss. New unoptimised images, third-party scripts piling up, a database growing unchecked.
  • Outdated content. Opening hours, prices or services that no longer exist. It looks careless and generates unnecessary calls.

Worst of all, many of these things fail silently. A form that doesn’t send emails can go unnoticed for weeks, and every day means lost customers.

What good maintenance includes

Security updates. For the framework, dependencies and server, applied with care: first in a test environment, then in production.

Monitoring. Automatic alerts if the website goes down, if a certificate is about to expire or if loading times get worse. Better to find out before your customers do.

Verified backups. Automatic, stored away from the main server and tested periodically.

Performance reviews. Checking Core Web Vitals from time to time and fixing anything that has degraded.

Small improvements and changes. Content tweaks, new sections or fixes identified through real use.

WordPress vs. custom architectures

The amount of maintenance depends a lot on how the website is built. A WordPress site with twenty plugins needs constant updates, and each one can break something through incompatibilities between them.

A static website built with Astro has a much smaller attack surface and needs far less intervention. A well-designed Django backend has controlled dependencies and a predictable update cycle. It’s not that they need no maintenance, but it’s simpler and brings fewer surprises.

In-house or outsourced maintenance?

If you have someone technical on the team, part of the maintenance can be done internally. If not, the usual approach is a monthly plan with the developer or agency, with clear tasks and response times.

When assessing a maintenance plan, ask:

  • Exactly which tasks does it include, and how often?
  • How quickly will you respond to a serious incident?
  • Are small content changes included or billed separately?
  • Will I receive some kind of report on what’s been done?

A different way of looking at it

Maintenance isn’t a cost for “not doing anything new”. It’s what protects the initial investment. A well-maintained website stays fast, secure and useful years after launch. An abandoned one ends up needing to be rebuilt, and that always costs more.

← Back to the blog

Got a project in mind? Let’s talk about building it right from the start.

Tell us about your project →