The honest answer
Nobody. On most small business WordPress sites, the developer finished the build, sent the final invoice, and moved on. The owner assumed the site would keep working the way a printed brochure keeps working. Nobody was paid to look at it again, so nobody did.
That is not neglect on anyone's part. It is a gap in the arrangement, and it is worth understanding what falls into it.
What WordPress needs, and why
WordPress runs on a stack of moving parts: the core software, a theme, and typically ten to thirty plugins, each maintained by a different person or company, each releasing updates on its own schedule. Underneath sits PHP, the language it runs on, which your host upgrades periodically, and a database.
Updates exist for two reasons: to fix security holes, and to keep everything compatible with everything else. Skip them and both problems accumulate. A plugin with a known vulnerability is a target within days of the vulnerability being published, because bots scan for it. A theme that has not been updated for a PHP upgrade breaks the day the host flips the switch.
None of this happens on launch day. It happens in months six to eighteen, one small thing at a time.
What quietly goes wrong in the first year
From the inherited sites we diagnose, the usual sequence:
Month two. Plugin updates start showing in the admin. Nobody logs in to see them.
Month four. The contact form plugin updates and its email settings reset. Enquiries stop arriving. The form still says "sent".
Month six. A plugin is abandoned by its author. It keeps working, but no longer receives security fixes.
Month nine. The host upgrades PHP. A function the theme relied on is removed. Part of the layout breaks on some pages, mostly on mobile, where the owner rarely looks.
Month twelve. The domain or SSL certificate renewal email goes to the developer's address. The site shows a security warning for a week before anyone notices.
Month fifteen. A vulnerability in an outdated plugin is exploited. The site starts redirecting some visitors to a pharmacy site, or sending spam, or both. Google flags it. Now it is an emergency, and it costs more to fix than two years of maintenance would have.
Every step is small. The total is a site that is slower, partly broken, insecure, and not sending enquiries, with an owner who thinks it is fine because the homepage still loads.
What maintenance actually involves
It is not glamorous, and that is the point. Someone, every month:
- Applies core, theme and plugin updates, on a staging copy first so an update that breaks something never takes the live site down.
- Checks the backups ran and that one can actually be restored.
- Runs a security scan and removes anything that should not be there.
- Confirms the forms still send, the booking still books, and the site still loads quickly on a phone.
- Notes what changed, and tells you.
- Handles the small changes you asked for: a price, a staff member, a seasonal banner.
An experienced person does this in a couple of hours a month for a typical small site. The value is not the hours. It is that the hours happen.
The three ways to make it somebody's job
Do it yourself. Possible, if you are comfortable in the WordPress admin and willing to spend an hour a month on it. The risk is the staging step: most owners update on the live site because they do not have a staging copy, and eventually an update breaks something at the worst moment. If you go this route, at least take a backup before every update session and test the forms afterwards.
Pay the original developer a retainer. Good, if they are still around and offer one. Ask how updates are tested, where backups go, and what the response time is when something breaks.
A care plan from a studio. A monthly fee, a defined list of what is done, a stated response time, and a report. Ours start at $99 a month and are described in detail on the care plan page. The important properties are that the work is staged, the backups are tested, you keep every login, and you can leave with a month's notice.
The wrong answer is the fourth one, which is the one most sites have: nobody, until it breaks.
For a site someone else built
Most care-plan clients arrive with a site we did not build, and it is fine. The honest way to start is a paid look at what is there: how it was built, what is out of date, what is fragile. Sometimes a few things need fixing before a plan would be maintenance rather than firefighting. You should hear that before you sign up, not in month three.
If your site has had nobody responsible for it for more than six months, the diagnosis is the place to start. If it was built recently and is in good shape, a care plan from day one is cheaper than the first emergency.