The evidence problem
Website maintenance is invisible when it works. The updates were applied, the backups ran, the scan found nothing, the site stayed up. From the owner's side, nothing happened, and a monthly fee for nothing happening is hard to value.
The monthly report is how maintenance becomes visible. It is also how you know it occurred. A care plan that sends no report is asking you to take the work on faith, and faith is not a good basis for paying a monthly fee.
What it should contain
Short. One page, or one email, readable in two minutes. Seven items.
1. What was updated. The platform version, the theme, and each plugin that changed, with the version numbers. Not because you will read the version numbers, but because their presence proves the work was done and gives a trail if something goes wrong later.
2. Whether anything broke on staging and what was done about it. "The gallery plugin update conflicted with the theme; held back pending a fix from the author." This is the line that shows the staging step is real.
3. Backup status. Backups ran on every day of the month, the most recent is dated, and, once a quarter, a restore was tested and worked.
4. Security. Scans ran, what they found, what was removed or patched. Plugins that were flagged as abandoned and what replaced them.
5. Uptime and speed. Any outages, with duration and cause. The load time on a phone this month against last, so you can see drift before it becomes a complaint.
6. Changes you asked for. Each one, done, with how much included time it used and how much remains.
7. Anything you need to decide. A plugin that should be replaced, a renewal coming up, a recommendation. One or two items, with a clear question, not a list of upsells.
What it should leave out
Everything else. A report padded with charts of visitor numbers, keyword rankings and generic "SEO tips" is a marketing document wearing a maintenance report's clothes. Those things may be worth having, but not mixed into the note whose job is to prove the site was looked after.
It should also leave out jargon. "Applied 3 security patches" says less than "Fixed a vulnerability in the contact form plugin that was disclosed on the 12th; patched on staging and live the same day."
How to read one in two minutes
Skim for four things:
- Did updates happen, and were they staged? Item 1 and 2.
- Are backups real? Item 3 should have dates and a restore test at least quarterly.
- Did anything go wrong, and was it handled? Items 4 and 5.
- Is there a decision for me? Item 7.
If all four are present and specific, the plan is doing its job. If the report is the same text every month with the date changed, or it is all charts and no version numbers, ask harder questions.
Red flags in a report
- No version numbers. Suggests updates were not tracked, or not applied.
- "All backups successful" with no dates or restore test. Backups that are never tested are hope.
- Nothing ever goes wrong. Over a year, something will fail on staging. A report that never mentions it either has no staging or is not honest.
- Every month recommends something to buy. The report has become a sales channel.
- No report at all. The most common case, and the clearest signal.
Why we send one
Ours goes out monthly on every plan. It follows the seven items above, it is written in plain words, and it is short. It exists so you know what you paid for, and so that if anything ever does go wrong, there is a record of what the site looked like every month before it did. The care plan page says "a monthly note on what changed" because that note is the difference between a plan you can see and one you are trusting.