🍪We use cookies!

This website utilizes cookies to enable essential site functionality, as well as for analytics, personalization, and targeted advertising. You may change your settings at any time or accept the default settings.

CaptivateClick
  • Home/
  • Services/
    Website Design
    • Web designResponsive sites built to convert.
    • Branding & identityBrand identity, logo and visual system designed to stay distinctive and consistent as you grow.
    • E-commerceWebshops built to sell.
    • Shopify agencyShopify stores that sell.
    • Landing pagesCampaign and offer pages.
    Lead Generation
    • Cold emailRelevant outreach that starts conversations.
    • LinkedIn outreachSocial selling with a human voice.
    • Appointment settingQualified B2B meetings in your calendar.
    • ProspectingThe right companies, people and timing.
    SEO
    • Technical SEOHelp Google discover, read and index the right pages.
    • Local SEOMaps and local visibility.
    • SEO auditSee what holds you back and what to fix first.
    • Get found on GoogleHelp customers find your business.
    Advertising
    • Ad reviewLanding page for your ad sends.
    • Google AdsGoogle Ads and SEM built around high-intent searches, qualified conversions and measurable revenue.
    • Meta AdsFacebook and Instagram campaigns built around creative testing, clean signals and profitable scale.
    • LinkedIn AdsB2B campaigns built around account targeting, buying committees and qualified pipeline.
    AI Automation
    • AI agentsAgents that do the work.
    • Xero & QuickBooks integrationXero and QuickBooks connected to your systems.
    • HubSpot automationsHubSpot pipeline automation.
    • System integrationSystems that share the same data.
    AI visibility
    • AI checkFree AI visibility check.
    • Answer engine optimisationBecome the answer AI cites.
    • GEO SEOShow up in AI-generated answers.
    • AI search (guide)Guide: what AI search is and what it means.
    See all services
  • Projects/
    • Climentum CapitalWeb designView case
    • Nordic Acceleration GroupWeb designView case
    • NorthforkWeb designView case
    • Hawkeye AdvertisingWeb designView case
    All projects
  • About Us/
  • Blog/Wordpress Maintenance
  • Contact/
CaptivateClick

Navigation

  • Home
  • Services
  • Projects
  • About Us
  • Blog
  • Contact
  • Privacy Policy

Services

  • Website Design
  • Lead Generation
  • SEO
  • Advertising
  • AI Automation
  • AI visibility

Website Design

  • Web design
  • Branding & identity
  • E-commerce
  • Shopify agency
  • Landing pages

Lead Generation

  • Cold email
  • LinkedIn outreach
  • Appointment setting
  • Prospecting

SEO

  • Technical SEO
  • Local SEO
  • SEO audit
  • Get found on Google

Advertising

  • Ad review
  • Google Ads
  • Meta Ads
  • LinkedIn Ads

AI Automation

  • AI agents
  • Xero & QuickBooks integration
  • HubSpot automations
  • System integration

AI visibility

  • AI check
  • Answer engine optimisation
  • GEO SEO
  • AI search (guide)
© 2026 CaptivateClick

Blog

WordPress maintenance and security: how to keep your site safe

October 8, 20265 min read
A heavy steel vault door with visible locks in a modern corridor, an image of a well-protected WordPress site

On this page

  • Why WordPress needs maintenance
  • Updates
  • WordPress
  • Plugins and themes
  • PHP
  • Backups
  • Protect the login
  • More protections that make a difference
  • Checklist: week, month, year
  • If your site is hacked
  • What does WordPress maintenance cost?
  • Frequently asked questions
  • Sources

Short answer: a secure WordPress site needs four things. Updates to WordPress, plugins, theme and PHP. Backups stored in more than one place. A protected login with strong passwords and two-factor authentication. And someone who checks every week. Most hacks do not happen through WordPress itself, but through plugins that have not been updated.

In brief

In 2025, 11,334 new vulnerabilities were found in the WordPress ecosystem, and 91 percent were in plugins. The most exploited were used in attacks within hours. Update plugins weekly, back up daily on active sites, run PHP 8.3 or later, turn on two-factor authentication and remove what you do not use. 43 percent of UK businesses reported a breach or attack in the past year.

Contents

  1. Why WordPress needs maintenance
  2. Updates
  3. Backups
  4. Protect the login
  5. More protections that make a difference
  6. Checklist: week, month, year
  7. If your site is hacked
  8. What does WordPress maintenance cost?

Why WordPress needs maintenance

WordPress powers about 40 percent of all websites (W3Techs), which makes it a popular target. Security company Patchstack counted 11,334 new vulnerabilities in 2025, a 42 percent rise on the year before. 91 percent were in plugins and 9 percent in themes, while only six concerned WordPress core, all of low severity (Patchstack).

Two more figures from the same report show why speed matters. 46 percent of the vulnerabilities had no fix when they became public. And the most exploited were used in mass attacks within five hours, as a median (Patchstack).

The UK picture is no better. In the government's Cyber Security Breaches Survey, 43 percent of UK businesses reported a breach or attack in the last 12 months, rising to 65 percent of medium-sized firms (GOV.UK).

Updates

WordPress

Minor WordPress versions, which often contain security fixes, install automatically. Since version 5.6, new installations also get major versions automatically, while older installations keep their previous behaviour (WordPress Developer). Check what applies to your site.

Plugins and themes

Plugins and themes do not update automatically by default (WordPress Developer). This is where most problems start. You can switch on automatic updates per plugin, but on an important site it is safer to update in a controlled way and test afterwards.

The UK's National Cyber Security Centre gives the same advice for all small organisations: keeping software and apps up to date is the best protection, and automatic updates should be switched on where possible (NCSC). If you want Cyber Essentials certification, critical and high-risk security fixes must be applied within 14 days of release (NCSC).

PHP

WordPress recommends PHP 8.3 or later (WordPress.org). PHP 8.1 and older no longer get security updates, and 8.2 stops getting them on 31 December 2026 (PHP.net). You change version in your hosting control panel, but test first that your theme and plugins work.

Backups

A backup must include both the database and the files. WordPress recommends weekly backups for sites with little activity, daily for active sites and always before an update, keeping three to five copies in different places (WordPress Developer).

A good rule of thumb is 3-2-1: three copies, on two types of storage, one of them away from your hosting. A backup that only sits on the same server as the site does not help if that server is hit. Test a restore once a year too, or you will not know whether it works.

Protect the login

  • Two-factor authentication. The Two Factor plugin from WordPress.org supports codes from an app, email and backup codes, and has more than 100,000 active installations (WordPress.org).
  • Strong, unique passwords for all administrators, stored in a password manager.
  • Fewer administrators. Give editors the Editor role, not Administrator.
  • Application passwords for integrations. They are meant for connections to other systems and cannot be used to log in to the admin area (WordPress Developer).
  • Remove old accounts for former staff and suppliers.

More protections that make a difference

WordPress's own hardening guide recommends, among other things (WordPress Developer):

  • Turn off the file editor in the admin area, so a hijacked account cannot change the code.
  • Use SFTP instead of FTP, with correct file permissions.
  • Give the database user only the permissions it needs.
  • Monitor and log, so you see if anything changes.

Also remove plugins and themes you do not use. Every plugin is code that can contain a vulnerability, even when deactivated. Do not rely blindly on your host's protection: in Patchstack's tests, hosting providers' own protections stopped only 26 percent of attacks (Patchstack).

Checklist: week, month, year

How oftenWhat
DailyAutomatic backup of database and files, uptime monitoring
WeeklyUpdate plugins and theme, check that forms and checkout work
MonthlyReview user accounts, remove unused plugins, check load times
QuarterlyCheck the PHP version and that backups can be restored
YearlyReview the whole site: theme, plugins, content and whether the technology still holds up

If your site is hacked

  1. Take the site offline or show a maintenance page.
  2. Change all passwords: WordPress, hosting, database and SFTP.
  3. Restore from a clean backup taken before the breach.
  4. Update everything and remove the plugin that let the attacker in.
  5. Check in Google Search Console that Google has not flagged the site.

If the breach may have exposed personal data, such as customer or form data, and a risk to people is likely, you must report it to the ICO as soon as possible and, where feasible, within 72 hours (ICO).

What does WordPress maintenance cost?

There is no neutral price list. UK providers' own figures suggest maintenance ranges from around £30 to more than £1,000 a month, with around £50 a month typical for small and medium-sized sites (Website Helper). Compare what is included: how often updates are done, where backups are stored, whether testing after updates is included and how quickly someone responds when something breaks.

Doing it yourself works well for a small site with few plugins, if you really do it every week. For help choosing the right platform in the first place, read What is a CMS? and Wix vs WordPress.

Rather not think about updates?

We handle updates, backups and monitoring for your WordPress site, and are there when something needs changing.

Read about website design

Frequently asked questions

How often should you update WordPress?

Check for updates every week. Minor WordPress versions often install automatically, but plugins and themes do not update automatically by default, and that is where most vulnerabilities are.

Is WordPress secure?

Yes, if it is maintained. WordPress core has very few serious vulnerabilities. In 2025, 91 percent of new vulnerabilities were in plugins and 9 percent in themes, so the risk mainly comes from plugins that are not updated.

How often should you back up WordPress?

WordPress recommends weekly for sites with little activity, daily for active sites and always before an update. Keep several copies in different places, at least one away from your hosting.

What should I do if my WordPress site is hacked?

Take the site offline, change all passwords, restore a clean backup, update everything and remove the plugin that let the attacker in. If personal data may be affected and a risk is likely, report it to the ICO within 72 hours where feasible.

How much does WordPress maintenance cost in the UK?

UK providers' own figures range from around £30 to over £1,000 a month, with around £50 a month typical for small and medium-sized sites. Compare what is included, not just the price.

Sources

  1. Upgrading WordPress, WordPress Developer Resources
  2. Hardening WordPress, WordPress Developer Resources
  3. WordPress Backups, WordPress Developer Resources
  4. Application Passwords, WordPress Developer Resources
  5. Requirements, WordPress.org
  6. Two Factor, WordPress.org
  7. State of WordPress Security in 2026, Patchstack
  8. Protecting your devices, National Cyber Security Centre
  9. Cyber Essentials: Requirements for IT infrastructure, National Cyber Security Centre
  10. Cyber Security Breaches Survey 2025/2026, GOV.UK
  11. Personal data breaches, ICO
  12. Supported versions, PHP.net
  13. , W3Techs
PreviousWooCommerce vs Shopify: how to choose the right platform for your online shop
NextHow much does a website cost in the UK? From free to fully custom

Related Posts

  • Read the blog

    Wix vs WordPress: an honest comparison for businesses

    October 8, 20265 min read
    Read more
  • Read the blog

    What is a CMS? Content management systems explained

    October 7, 20264 min read
    Read more
  • Read the blog

    WooCommerce vs Shopify: how to choose the right platform for your online shop

    October 8, 20265 min read
    Read more
Let's get startedLet's get started

Ready to grow?

Let's talk about your project.

Trusted by 110+ businesses to grow online.

  • Mercer Consulting, Co.
  • Mercer Consulting, Co.
Usage statistics of WordPress
  • How much does website maintenance cost?, Website Helper