Maintenance that keeps risk visible.
A website needs the same operational discipline as every other business-critical system: a clear owner, a patch cycle, continuous oversight and an audit trail. Choose the level of assurance that fits your site, sector and risk.
A standing operational load. Not an annual task.
The exposure sits in the stack around the site. Retained maintenance turns published fixes into applied ones — and security claims into evidence.
of WordPress vulnerabilities disclosed in 2024 were found in plugins.
had a fix available. A fix that is never applied protects nobody.
new WordPress vulnerabilities were published in Q4 2025 alone.
of UK businesses use an external cyber-security provider.
Sources: Wordfence 2024 Annual WordPress Security Report; Wordfence Q4 2025 Threat Intelligence Report; UK Cyber Security Breaches Survey 2025/26.
Choose the level that matches the risk.
Essential
Managed
Assured
Custom
Match the plan to the risk.
Tell us about the site, its operating context and the assurance you need. We will recommend the right plan — or define a bespoke service.