If you do not maintain your website, the honest short term answer is that nothing happens. Your site still loads. Your contact form still works. Nobody calls to complain.
That is exactly why maintenance is often the easiest business expense to postpone. The cost of skipping it is invisible until suddenly it is not.
Then, one week, something goes wrong. Google may show a Japanese pharmacy page instead of your website. Your checkout might stop accepting cards. Or an outdated plugin could break your site when you finally update it.
None of these are freak accidents. They are the predictable result of problems that started months earlier.
Here's what that process actually looks like, using last year's numbers rather than scare-quotes — and why it tends to hit small businesses hardest.
Quick Answer
- WordPress itself is not your risk. Your plugins are. In 2025, WordPress core had 6 disclosed security vulnerabilities. The wider ecosystem had 11,334 — and 91% of them were in plugins.
- The window to patch is hours, not quarters. For vulnerabilities that attackers actively target, it can take as little as five hours for someone to exploit them.
- Updating on its own isn't a plan. 46% of vulnerabilities had no developer fix available when they went public, so there was nothing to update to.
- Cleanup is rarely one bill. A basic malware cleanup might cost a few hundred dollars. Add developer time, lost traffic, and the work needed to get your site reindexed, and the cost can climb quickly.
The Numbers That Changed in 2025
Patchstack's State of WordPress Security in 2026 report is one of the most useful sources here. It tracks vulnerabilities reported across the WordPress ecosystem instead of trying to estimate how many attacks actually happen.
Four figures from it are worth sitting with:
| Finding | Figure | What it means for you |
|---|---|---|
| New vulnerabilities disclosed in 2025 | 11,334 — up 42% over 2024 | The volume is growing, not levelling off |
| Found in plugins | 91% (themes 9%, core just 6 total) | The platform is fine; the add-ons are the exposure |
| High-severity vulnerabilities | 1,966 — up 113% year over year | More of them are the serious kind |
| Median time to first exploit | ~5 hours | "I'll get to it this quarter" is not a strategy |
That third column is the whole argument. A site with fourteen plugins is not running one piece of software. Fourteen different pieces of software from fourteen different developers are running.
Each plugin follows its own update schedule, and its developer may eventually stop maintaining it. Thousands of people help maintain WordPress core. It had just six reported vulnerabilities in 2025.
Meanwhile, you may still rely on a plugin you installed in 2022 that one developer no longer maintains.
Hackers don't target your site simply because you use WordPress. Hackers get in through the twelve things you added and never checked again.
What Happens If You Don't Update WordPress Plugins?
Since plugins are where 91% of the risk sits, they deserve their own answer — and the honest version has two halves.
The first is security. Every plugin with a known vulnerability gives hackers another way into your site. Automated scanners actively look for these weaknesses.
You may have seen the figure "97% of WordPress vulnerabilities come from plugins" quoted online. Patchstack's own data puts the number at 91%. Themes accounted for 9% of reported vulnerabilities. WordPress core had just six reported vulnerabilities all year.
The real numbers are concerning enough without overstating them.
The second half is quieter and far more common: outdated plugins simply stop working alongside each other. When developers leave a plugin unupdated for two years, it can fall out of step with PHP, WordPress, and your other plugins. That can cause forms to stop working, checkouts to fail, or your layout to break when you update something else.
The worst case is an abandoned plugin — one whose developer has stopped shipping updates altogether. No patch is coming, so you need to replace the plugin. That takes much more work than simply clicking "update."
What Happens to a Website You Don't Maintain: A Timeline
This is the pattern we see most often when a site comes to us after a year or two of neglect. It rarely arrives as one dramatic failure.
Months 1–3: silent drift. Plugin and core updates queue up. Nothing visible changes. The site is now running code with known vulnerabilities. It may look the same as it did a month ago, but the risk has changed.
Months 3–6: small cracks. A form stops delivering email because an SMTP plugin fell out of step with its provider. An image gallery breaks on iOS after a browser update. Page speed drifts down as bloat accumulates. These are the ones that quietly cost you leads, because nobody reports a contact form that silently fails — they just leave.
Months 6–12: the update trap. By now the backlog is the problem. Updating a plugin that skipped five versions is genuinely risky, so the update gets postponed again — not out of laziness, but because doing it carelessly, without a staging environment to test in first, could take the site down. The longer you wait, the more expensive and frightening the update becomes. This is the stage where most business owners get stuck.
Month 12+: something gives. Malware, an outage, a broken checkout, or a PHP version deprecation that takes the whole site white-screen. Now it's an emergency, on someone else's timeline, priced accordingly.
It Isn't Only a Security Problem
Security gets the headlines, but in practice the slower losses are the ones that appear in revenue.
- Broken forms and silent lead loss. The single most common thing we find on a neglected site. Weeks of inquiries going nowhere, with no error message to warn anyone.
- Site speed decay. Poorly optimized images, redundant plugins, and outdated PHP compound into slow load times. Page speed is a ranking factor and a conversion factor at the same time, so it costs you twice.
- Broken links and outdated content. Products you no longer sell, staff who left, prices that changed, a blog post that trails off two years ago. Every one is a small trust withdrawal from a potential customer deciding whether to call you.
- Expired SSL certificates. When a certificate expires, visitors get a full page security warning in their browser. One of the few maintenance problems that can stop people from visiting your site right away.
- SEO erosion. This is not a penalty. Your rankings can slowly drop while competitors add new content and keep their sites fresh. Meanwhile, your site stays the same.
- Recovery costs after a compromise. If Google flags your site for malware, cleaning it up is the easy part. Getting the warning lifted, re-earning crawl trust, and climbing back in search results takes considerably longer.
A site that's merely out of date doesn't announce itself. It just converts slightly worse every month, which is much harder to notice than an outage and often more expensive over a year.
What Does It Cost to Fix a Neglected Website?
No reliable average cost exists for a hacked website. The cost depends on what hackers accessed and what your site was storing. But the reported ranges are consistent enough to be useful for planning:
| Scenario | Typical reported range |
|---|---|
| Straightforward malware cleanup, brochure site | $300 – $1,800 |
| Emergency cleanup plus developer time to repair damage | $1,200 – $4,500 |
| Compromised admin accounts | $1,000 – $10,000 |
| Incident response on an e-commerce site | $1,800 – $6,500+ |
| Breach involving stored customer data | $10,000 – $200,000, including notification and regulatory exposure |
Those figures cover the invoice only. They also do not include the cost of downtime or the inquiries you lose while the site is down. They do not account for the weeks it can take to recover your search rankings either. That cost is often much higher, and you will never see it on a bill.
Maintenance is different from most business expenses. The cheaper option is often the one that works best. Routine updates cost the same whether or not anything was going to go wrong.
"My Host Handles That"
Sometimes, partly. This is worth explaining because it is the most common reason people skip maintenance.
Managed hosting typically covers backups, server-level patching, uptime monitoring, and often automatic WordPress core updates. That matters, which is why all of our hosting plans include daily backups, SSL, and monitoring as standard.
What server-level defenses don't reliably do is stop exploitation of a vulnerability in your specific plugins. Patchstack's testing shows the limits of traditional hosting security. It blocked only 12% of attacks targeting known vulnerabilities and 26% of attacks overall.
The rest looked like normal traffic to a real page. That makes those attacks much harder for a basic firewall to spot.
And no host will notice that your contact form stopped sending email, or that your pricing page still lists last year's rates. Hosting keeps the server healthy. It doesn't keep the site healthy.
Do You Actually Need a Website Maintenance Plan?
We'll be straight about this, the same way we are on our maintenance packages page: not every business needs a monthly plan.
You may not need one if your website is small, simple, and mostly informational.
You also need managed hosting with automatic WordPress updates and daily backups. Keep your plugins to a minimum and make sure the developers actively maintain them.
Finally, you need to be willing to log in every month and handle updates yourself. That's a real and legitimate setup.
The catch is the last condition. Almost everyone intends to do this. Very few people keep up with updates for a full year. If you stop after four months, your site can end up just as exposed as one that never had maintenance. The difference is that you may think you are covered when you are not.
A maintenance plan makes more sense once your website brings in leads, handles payments, or stores customer data. It also makes sense if you rely on several plugins or if having your site down for two days would cost you money.
What Good Maintenance Actually Covers
Two different things fall under "maintenance." One keeps your website secure. The other keeps it working.
Knowing the difference makes it much easier to understand what your maintenance plan actually covers.
The first is upkeep — core, theme, and plugin updates, backups, content edits, broken-link checks, and performance monitoring. That work prevents the timeline above and keeps a site running smoothly, and our ongoing maintenance plans focus on it.
The second is security. This includes firewalls, security scans, malware detection, intrusion prevention, and 24/7 threat monitoring.
It also includes a plan for what to do if something gets through. Nearly half of vulnerabilities become public before anyone has a fix ready. That makes security especially important when there is nothing to update yet. That's the website security side of the work.
You want both, and you want them to work together. Ideally, the same team finds the problem and fixes it. You should not have to deal with two companies and multiple support tickets.
If you are comparing your options, two other guides can help. Custom Website vs. WordPress explains how your choice affects long term maintenance. WordPress vs. Squarespace looks at how much upkeep each platform requires.
The Bottom Line
Not maintaining your website isn't a decision most business owners make deliberately. What happens by default is that a neglected site gives you no feedback at all until it gives you a lot at once. A web design project ends at launch; the website itself doesn't.
The businesses that avoid the emergency aren't the ones spending the most. They're the ones for whom security updates and plugin updates are boring, routine, and already handled.
QuestionsFrequently asked questions.
How often does a website actually need updating?
Check for plugin, theme, and core updates at least monthly, and apply security updates as soon as they appear. Given that the median time to first exploit on heavily targeted vulnerabilities is around five hours, security patches aren't something to batch up for a convenient moment. Beyond updates, a quarterly review of forms, links, speed, and content keeps the slower problems from accumulating.
How do I know if a plugin is outdated or abandoned?
Your WordPress dashboard flags available updates, but it won't tell you a plugin has been abandoned. Check the plugin's page in the WordPress.org directory for its "last updated" date — more than a year without a release is a warning sign, and beyond two years it should be treated as abandoned whether or not it still appears to work. Check the "tested up to" WordPress version while you're there. An abandoned plugin needs replacing, not updating.
Can I just do website maintenance myself?
Yes, if your setup is simple and you'll actually keep it up. The workflow that matters: back up before updating, update in a staging environment rather than live, apply updates one at a time so you can tell which one broke something, and then test your forms and key pages afterward. Most self-maintenance fails not on skill but on consistency — and on skipping the backup, which is what turns a bad update into a bad week.
Doesn't my hosting company handle security and updates?
Partly. Managed hosting generally covers server patching, backups, uptime monitoring, and often automatic core updates. It does not reliably block exploitation of vulnerabilities in your particular plugins — hosting-level defenses blocked only 12% of attacks against known exploited vulnerabilities in Patchstack's testing. It also won't tell you your contact form has stopped delivering. Hosting protects the server; maintenance protects the site.
How do I know if my site is already compromised?
Common signals: a sudden traffic drop, pages in Google's index you didn't create, a browser or Search Console malware warning, redirects that only happen on mobile or only for visitors from search, new admin users you don't recognize, unexpected slowdowns, or outbound spam from your domain. Check Google Search Console's Security Issues report first — it's free and it's usually where the warning appears earliest.
Is website maintenance worth the monthly cost?
It depends on what the site does for you. If it's a static brochure that rarely changes and you're comfortable updating it yourself, a plan may be unnecessary. If it generates leads, takes payments, holds customer data, or would cost you real money to have down for two days, then the comparison isn't cost versus nothing — it's a predictable monthly figure versus an unpredictable four-figure recovery on someone else's schedule.