A monthly plugin-update receipt is not a security service. Useful recurring care maintains a trusted baseline, reviews high-value changes, tests recovery and defines what happens when something suspicious appears.
The scope should match the site’s commercial risk and hosting boundary.
Maintain supported software
Review WordPress core, plugins, themes and PHP compatibility. Apply security updates through a controlled process with backup/rollback and functional testing.
Remove abandoned/unused components and verify package source. Record version and change owner.
Do not auto-update high-risk checkout/integration components without a test plan, but do not leave known vulnerabilities indefinitely.
Verify backups and restoration
Keep encrypted/versioned files and database backups outside public site write access. Monitor job completion and storage.
Perform periodic isolated restore tests, verify archive integrity and document recovery time. Scan historical candidates before production restoration.
Backups are resilience, not prevention.
Review privileged access
Reconcile administrators, custom roles, application passwords, hosting/SFTP, DNS/CDN and recovery-email ownership. Remove expired accounts and review multi-factor coverage.
Use individual least-privilege access and record responsible owner. Rotate secrets on compromise/ownership change, not arbitrarily without integration testing.
Monitor meaningful indicators
Cover trusted file changes/sensitive paths, executable uploads, unknown plugins, privileged users, cron and external malicious symptoms. Retain useful authentication/change logs.
Monitor Safe Browsing/Search Console and critical forms/checkout separately.
Alerts need a response owner, severity and evidence—not just automated email.
Validate configuration and boundaries
Review site isolation, staging access, backups outside web roots, file ownership, PHP execution in uploads, DNS/CDN/tag-manager users and unknown mail forwarders.
Check that deployments do not restore vulnerable packages or secrets.
Document accepted exceptions with review dates.
Test business functionality
After relevant changes, test login/password reset, forms/SMTP, languages, scheduled jobs and authorised WooCommerce sandbox checkout/webhooks.
Security settings that silently stop leads/orders are not a successful maintenance outcome.
Record failures and rollback/repair.
Provide incident readiness
Define urgent contact, response hours, containment authority, evidence preservation and access method. No passwords should be sent through public forms.
State what investigation/remediation time is included and how larger incidents are scoped/approved.
Keep provider, payment, privacy/legal escalation contacts current.
Define service levels by symptom
Use severity categories tied to visitor/business impact. Checkout injection, phishing, malicious downloads and unknown administrators require a different response from one outdated inactive plugin.
For each severity, state acknowledgement target, containment authority, communication route and after-hours coverage. Do not promise guaranteed removal within a fixed time before incident scope is known.
Agree who can approve downtime, credential rotations, DNS changes and provider escalation. Keep an alternate contact method outside WordPress/email if those systems are part of the incident.
Report decisions, not noise
A monthly report should list material changes, vulnerabilities addressed, backup/restore status, access exceptions, alerts/investigations and next actions.
Avoid padding with thousands of blocked bot requests. Explain evidence, business impact and ownership.
Track recurring findings to completion.
State exclusions honestly
No service can guarantee a site will never be attacked. Define whether server OS, custom-code audit, legal/data-breach response, payment compliance, 24/7 response and third-party accounts are included.
An initial assessment can use public URLs, stack/hosting and risk profile without credentials.
Price/scope recurring work separately from major cleanup so monitoring does not incentivise vague unlimited promises or hidden emergency charges.
Trustworthy maintenance reduces detection time, keeps recovery workable and provides accountable action when the baseline changes.
Review the agreement after a hosting migration, checkout redesign, new agency or serious incident. The previous scope may no longer cover the real boundary.
Include a named service owner on both sides and a quarterly access review. Recurring care fails when alerts go to a former employee or nobody can approve containment.