Launch day feels like the end of the project. In reality it's the start of its life: from that moment the site ages, even if nobody touches it. Libraries get security fixes, browsers change, Google updates its criteria, certificates expire. A site that isn't updated doesn't stand still: it gets worse.
What maintenance covers
- Dependency updates, security fixes first.
- Automatic backups, and above all checking they can be restored.
- Monitoring: is the site responding? Are there errors in the logs?
- Renewals: domain, certificates, external services.
- SEO and performance checks: indexed pages, speed, broken links.
- Small changes to content and features.
- Regulatory updates: privacy, cookies, accessibility.
Examples from my own site
On my site I've seen first-hand why each of these items exists. When I added the real-time live chat I also had to update the Content Security Policy: without that tweak the browser blocked the new feature in production. An SEO check revealed that the tool pages had titles in a single language, making the other versions invisible to Google. And major Angular versions ship on a regular schedule: falling a few versions behind turns a one-hour update into a migration that takes days.
The backup nobody tests
Almost every site has a backup. Very few have ever tried to restore it. A backup that has never been restored is a hope, not a guarantee: that's why, besides saving it, you should periodically load it into a test environment. These are the basic commands I use for a Node project with MongoDB:
npm outdated # which dependencies have a newer version
npm audit --omit=dev # known vulnerabilities in production dependencies
# Backup of the database, with the date in the file name
mongodump --uri="$MONGODB_URI" --gzip --archive="backup-$(date +%F).gz"
# The step everybody skips: restore it into a TEST database
mongorestore --uri="$TEST_URI" --gzip --archive="backup-2026-10-01.gz"
The checklist
| Frequency | Activity |
|---|---|
| Every month | Security updates, checking automatic backups, reviewing errors in the logs |
| Every three months | Backup restore test, dependency updates, checking performance and indexed pages |
| Every year | Domain renewal, privacy and cookie review, accessibility check, major version upgrades |
| When needed | Urgent fixes, new features, regulatory changes |
What it costs
It's often estimated at 10% to 20% of the initial cost per year, but it depends a lot on the project: a static site needs very little, a web app with a database, users and integrations much more. The right comparison isn't with zero, but with the cost of a compromised site or one that's down for days.
How to tell whether your site needs it
- Do you know when the libraries were last updated?
- Do you know where the backups are, and have you ever restored one?
- Would you notice if the site went down tonight?
- Do you know whose name the domain and hosting are in, and when they expire?
If even one answer is "no", maintenance isn't an extra cost: it's a risk you're already running.
In short
Maintenance keeps a site secure, fast and findable over time: updates, verified backups, monitoring, renewals and small adjustments. You can do it yourself, if you have the time and skills, or hand it to someone with a clear list of what's included. I've collected more good practices on security and performance, and if you'd like to talk about your site, get in touch.