Security and maintenance are the parts of a website engagement nobody gets excited about in a pitch meeting, and they’re exactly the parts that determine whether a site is still standing a year later. When I talk to operations managers and marketing directors about vetting a WordPress partner, this is usually the section of the conversation that gets the most hand-waving from agencies — and the most trouble later if it’s ignored.
Why This Gets Skipped, and Why That’s a Problem
Security and maintenance don’t show up in a launch demo. They’re invisible when they’re working and expensive when they’re not — a compromised site, a missed vulnerability patch, or a failed backup rarely surfaces until something has already gone wrong. That makes it easy for an agency to underinvest here without a client noticing until there’s an incident.
WordPress’s popularity cuts both ways. It means broad plugin support and a huge ecosystem, but it also makes WordPress sites a constant target for automated attacks scanning for outdated plugins, weak credentials, and known vulnerabilities. A site that isn’t actively maintained isn’t just neglected — it’s actively exposed.
What to Ask an Agency Before You Sign
- What’s the patching cadence for core, themes, and plugins? Get a specific answer — weekly, monthly, as-needed — not “we keep things updated.” Ask how updates are tested before they go live on your production site.
- How are backups handled? You want automated, offsite backups on a defined schedule, with a tested restore process. Ask when they last actually restored a backup, not just whether one exists.
- What monitoring is in place? Uptime monitoring, malware scanning, and failed-login tracking should all be running continuously, not checked manually once in a while.
- What happens if the site is compromised? Ask for the actual incident response process: who gets notified, how fast, and what the remediation steps look like. If there’s no documented process, that’s the answer.
- Who owns credential management? Shared admin logins, weak passwords, and no two-factor authentication are common failure points. Ask how access is controlled and audited, especially as staff turn over.
- Is the hosting environment actually managed, or just hosted? There’s a real difference between a host that provides server space and one that actively manages security at the server level — firewalls, malware scanning, and isolation between sites.
- What’s included in the retainer, and what’s billed separately? Some agencies treat security incidents as emergency billable work rather than something covered under an ongoing maintenance agreement. Get this in writing before you need it.
What Good Coverage Actually Looks Like
A well-maintained WordPress site has updates applied on a predictable schedule, automated backups stored offsite with periodic restore testing, real-time monitoring for uptime and malware, and a documented response plan for when something does go wrong — because eventually, something will. None of this is exotic. It’s routine work that has to actually happen on a routine basis, which is precisely the kind of thing that’s easy to promise and easy to skip.
What I’d Tell a Colleague Making This Call
Ask to see evidence, not assurances — a recent update log, a backup history, a monitoring dashboard. And ask what happened the last time a client’s site had a security issue. How that got handled tells you more about an agency’s real practices than anything in a proposal.
