Website maintenance and troubleshooting
How to keep a business website fast, secure and online — monthly maintenance routines, common failure causes, and what to do when your site breaks.
Intermediate · 9 min read · Updated
Key takeaways
- →Most website outages trace to expired domains or hosting, failed plugin updates, or SSL certificates lapsing.
- →Run a monthly routine: updates, backup verification, uptime check, form test, broken-link scan and speed check.
- →Verified backups — restored at least once a year — are the only backups that count.
- →Budget R500–R2,500 per month for maintenance depending on site complexity.
- →If a site is hacked, take it offline, restore a clean backup, rotate every credential, then patch the entry point.
A website is not a finished object; it is running software with dependencies that change underneath it. Here is what ongoing care actually involves and how to respond when something breaks.
The monthly routine
- Apply core, plugin, theme or dependency updates on a staging copy first
- Verify that a backup exists and can actually be restored
- Check uptime logs for the past month
- Submit every contact and enquiry form and confirm the email arrives
- Scan for broken links and fix or redirect them
- Run a speed test on mobile and investigate regressions
- Review security logs and failed login attempts
Quarterly, add
- →A full restore test into a staging environment
- →Review of user accounts — remove people who have left
- →Search Console coverage and Core Web Vitals review
- →Content audit: outdated prices, stale team pages, dead offers
Why sites go down
- →Expired domain or hosting — the most common cause, and the most avoidable. Set calendar reminders independent of the registrar's emails.
- →A bad update — a plugin conflict after an unattended auto-update. This is why staging exists.
- →Expired SSL certificate — visitors see a full-page security warning and leave.
- →Resource limits — a traffic spike or runaway process exceeding your hosting plan.
- →Compromise — outdated software with a known vulnerability.
When your site breaks: a triage order
- Confirm it is not just you — check from mobile data and an external uptime tool
- Check domain and hosting expiry
- Check the SSL certificate
- Check whether the host has an incident in progress
- Roll back the most recent change
- Restore the last known-good backup
- Only then start debugging the root cause
If you have been hacked
Take the site offline or into maintenance mode immediately. Restore a clean backup from before the compromise. Rotate every credential — hosting, CMS, database, FTP, email. Patch the vulnerability that allowed entry, or the same thing happens again within days. Request a review in Search Console if Google has flagged the site. Then add monitoring so the next attempt is caught early.
What maintenance should cost
| Site type | Monthly | Includes |
|---|---|---|
| Brochure site | R500 – R900 | Updates, backups, uptime, monthly checks |
| CMS / content site | R900 – R1,800 | The above plus content support and monitoring |
| E-commerce | R1,800 – R5,000 | The above plus checkout testing and integrations |
Frequently asked questions
How often should a website be updated and maintained?
Run a maintenance pass monthly: software updates on staging, verified backups, uptime review, form testing, broken-link scan and a mobile speed check. Add a full restore test and content audit each quarter.
Why did my website suddenly go offline?
The most common causes are an expired domain or hosting account, an expired SSL certificate, a failed plugin or dependency update, exceeded hosting resource limits, or a security compromise.
What should I do if my website is hacked?
Take the site offline, restore a clean backup from before the compromise, rotate every credential, patch the vulnerability that allowed access, then request a security review in Google Search Console.
Work with us
Want this handled for you rather than done yourself? These services cover the ground in this guide.