Synthetic Industry

Standing service wordpress-updates-staging-tested-each-month · revised 11 October 2026

Standing service

Try every WordPress update on a private staging copy first, month after month

Each month we test your pending updates on a private staging copy, check the pages and forms you name, and send a pass or hold per update. Your team applies them. No backups or monitoring.

This starts a conversation by email. Nothing is charged, and nothing is tested, until we have agreed scope and terms with you in writing.

The responsibility you hand over

Out-of-date plugins and themes are a security and compatibility risk, but applying a batch of updates to a live site can break a page or a form with nobody watching. Testing each batch on a copy is the cure, and it is the step that gets skipped because it takes time and a checklist nobody owns.

Who it’s for: Owner or agency of a WordPress site that avoids updates because an earlier one broke something, or that applies them live and hopes, and whose backups, monitoring and live updating are handled elsewhere (an agency, a managed host or an in-house person).

Usually starts when: Updates have been postponed for months, a past update broke a page or a form, or nobody on the team is willing to press Update on the live site.

The result: Before any update reaches your live site, it has been tried on a private staging copy, your named pages and forms were checked, and you hold a written pass or hold decision for each update with the evidence. Your team applies the passed updates.

What stays true, and what we do about it

No response-time guarantee is published for this new service. The monthly test window is agreed in writing before it starts, set to what a service at this stage can actually keep. A security update is tested in the next monthly test: no earlier test and no maximum delay is promised.

A test window each calendar month is agreed in writing before the service starts. The service is not staffed round the clock, so we do not offer round-the-clock cover.

What must remain true

  • No plugin, theme or core update reaches your live site without a passed staging test of the named pages and forms
  • Each month you hold a written decision for every pending update, up to twenty
  • The staging copy was private, sent no email and had its outside connections off when it was tested

What we watch

  • The monthly list of pending updates, sent by your site holder
  • The staging copy's update screens and PHP log
  • Update notices that WordPress or the plugin makers publish for security fixes, as you pass them on

When something happens

Scroll the table sideways to read it all.

WhenWhat we do
A month's test window starts or your site holder sends the list of pending updates.We check the staging copy is private with email and outside connections off, refresh the checklist if the site changed, apply the updates on staging in small groups, run the checks and send the report.
An update fails a check on staging.We hold it, record the failure with evidence and propose options. If the cause looks like a clash between components we offer the conflict job.
Priced as: Plugin conflict on one page
An update is flagged by its maker as a security fix.We list it first in the next monthly report and test it in that month's test. We do not test between monthly tests, so we tell you plainly if a failed test means you must choose between the risk and the change.
A month ends.We send a summary: updates passed, held and the open questions.

We do on our own

  • Apply updates and run checks on the staging copy
  • Read the staging copy's PHP log
  • Update the checklist when you tell us the site has changed

We ask you first

  • Anything that touches the live site, which stays with your team
  • Switching on email or any outside connection on the staging copy
  • Changing the checklist scope, the number of pages or forms
  • Adding or removing a plugin on staging beyond the update under test

We escalate to you when

  • An update fixes a security problem and also fails a check
  • The staging copy no longer matches the live site closely enough to trust
  • The staging copy is found to be public, to send email or to have an outside connection switched on
  • The same update fails repeatedly for reasons outside the site files

How you know it held. Each month the report lists every update with its decision and evidence, and the staging safety record. A pass means the named pages and forms passed on a private staging copy; it is not a guarantee about the live site or about pages outside the checklist.

How we keep it true

This service is never finished. Each month's report shows what passed and what was held, and it continues until you end it.

  1. Find which plugin or theme breaks one WordPress page, form or feature, and fix it Job Each time it fires

    Isolate the plugin, theme or setting that breaks one named page, form or feature on a staging copy, then hand over a tested fix or workaround and the evidence.

    Quoted per failure, if you buy it

    Bought separately when a held update needs its cause found and fixed.

  2. Move edits made inside a WordPress theme into a child theme, so updates stop erasing them Job Optional

    Find every change made directly in a parent theme, move it into a child theme, and prove on staging that it works with the current parent, then the updated one, and can be switched back.

    Often needed first if the theme was edited directly, because a theme update would erase those edits.

What is included, and what is not

  • A monthly report listing each update: pass, hold or needs a decision, with the evidence
  • The month's staging safety record: copy private, no email, outside connections off
  • The order in which to apply the passed updates and the way to undo each
  • For a held update, the failure and the options: wait for a fix, replace the plugin, or accept the change
  • A refreshed checklist when the site changes

Included

  • One single WordPress site and its private staging copy
  • Up to twenty pending updates a month, listed by your site holder: each plugin, theme or core update counts as one. A first month with a bigger backlog is quoted before the service starts
  • A checklist of up to ten pages (the login counts as one) and three forms, agreed at the start and revised on request
  • A check at the start of each month that the staging copy is private, sends no email and has every outside connection (CRM, newsletter, webhook, analytics or advertising tag, payment gateway) switched off, pointed at a sandbox or in test mode
  • Applying the updates on staging in small groups, so a failure points to one update
  • A pass or hold decision per update with screenshots and the log excerpt for any problem
  • Security updates marked first in the report and tested in the same monthly test, not sooner

Not included

  • Applying updates on the live site: your team or host does that
  • Backups, uptime monitoring or malware scanning, which are separate jobs: the monthly maintenance service checks backups and reviews alerts but does not include malware scanning
  • Testing between the monthly tests: a security update waits for the next one, and no earlier test or maximum delay is promised
  • Fixing the cause of a failed update beyond naming it, unless you buy the conflict job
  • Redesign or new features
  • Cover outside the agreed hours or a guaranteed response time
  • Multisite networks

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. Before each month's test the staging copy is recorded as private, sending no email and with every listed outside connection off, in a sandbox or in test mode

    Evidence: The month's staging safety record: the response to a request for the staging address without a login, and the mail and connection settings screens

  2. Each month every update on the supplied list (up to twenty) has a recorded pass, hold or decision-needed result with evidence

    Evidence: The monthly report compared with the list your site holder sent

  3. Each passed update was applied on staging and the full checklist of pages and forms was run afterward without a new error

    Evidence: Checklist results and the staging log excerpt for the test window

  4. Each held update has a recorded failure that can be repeated from the steps given

    Evidence: The repeat steps, screenshots and log lines in the report

Sign-off. You read each monthly report and your team applies the passed updates. A month counts as delivered when you accept the report.

If it fails. If we cannot complete a month's tests, we say so, explain what blocked us and it does not count as delivered. If the service is not working for you, you can end it at the end of any month.

When it fits, and when we stop

It fits when

  • A staging copy of the site can be refreshed from live each month, by your host's tool or by your site holder
  • The staging copy is private: behind a password or an address allow-list at the host, not merely set to discourage search engines
  • Outgoing email is off on the staging copy, and every outside connection on it is off, pointed at a sandbox or in test mode. Your site holder confirms this in writing before the first test and after each refresh
  • Your site holder can send the list of pending updates and apply the passed ones

We stop and tell you if

  • No staging copy can be made safely
  • The staging copy would hold real customer or member records and cannot be kept private, or its outside connections cannot be switched off
  • More than twenty updates are pending in most months: we agree a different scope
  • Failures after the first two months are mostly caused by something outside the plugins and theme, such as the host
  • The site is mission-critical with a need for round-the-clock cover, which this service does not offer
  • The checklist needs live payments or customer records to test

What could go wrong

We change only the staging copy. Your team applies updates to the live site using our order and undo steps, and can reverse each one as for any update. Ending the service leaves your site as it is.

Scroll the table sideways to read it all.

RiskHow we handle it
A pass on staging does not match behaviour on the live siteWe keep the staging copy matched to live, state what the checklist covers, and ask your team to run a short live check after applying.
The staging copy sends email or fires an outside connection such as a CRM, newsletter or payment gatewayEmail and every outside connection must be off, in a sandbox or in test mode, and the copy must be private, before any test. Your site holder confirms it in writing and we re-check it at the start of each month's test.
Staging holds real customer dataThe copy is refreshed without customer records where your host's tool allows, and it must be kept private. If it has to hold real records and cannot be kept private, the service does not start.
A held security update leaves the site exposedWe mark security updates first in the report and tell you plainly when a choice must be made. Nothing is tested between the monthly tests and no maximum delay is promised, so your site holder decides whether a fix that cannot wait is applied first.

Each report is checked by a reviewer separate from the work that produced it before it is sent. No human supervisor is included unless your agreement names one. At launch the work is largely automated, and we say so.

Stays with a person

  • Your team applies every update to the live site
  • You confirm in writing that the staging copy is private with its outside connections off or in test mode
  • You approve any change to the checklist scope

Access we would need

  • A staging copy and a staging admin login
  • The monthly list of pending updates from your site holder

Questions

Do you apply the updates to my live site?

No. Your team or host does that, using our order and undo steps. We only touch the private staging copy.

How is this different from the monthly maintenance service?

This does one thing: it tests updates before they go live. Backups, monitoring and applying updates are not included. The monthly maintenance service (published test price GBP 195 a month) also tries updates on a copy first, on its own terms, and applies them to the live site with your approval, checks the backup schedule and a quarterly restore test, and reviews alerts, so it does more and needs its own preconditions. This service is capped at twenty pending updates a month, so ask which fits if you often have more. Choose this one if backups, monitoring and live updating are handled elsewhere, for example by an agency or a managed host. Choose the maintenance service if you want those done for you.

What if an update fails?

We hold it, show you the failure and the options. Finding and fixing the cause is the separate conflict job.

What about a security update?

It is marked first in the report and tested in the same monthly test. No earlier test and no maximum delay is promised. If it cannot wait, your site holder decides whether to apply it first.

What stops the staging copy emailing or charging my customers?

The copy must be private, with email off and every outside connection off, in a sandbox or in test mode, before any test. Your site holder confirms that in writing and we re-check it each month. If it cannot be done, the service does not start.

Also part of

A managed WordPress lane: tested updates, monthly form checks and a change allowanceFor one WordPress site: staging-tested updates, monthly form checks and up to two bounded items a month, one at a time. Proposed GBP 690 a month; timing and capacity by written proposal.

Send an enquiry

Send us

  • The site address, the theme name and roughly how many plugins are active
  • Whether a staging copy exists and who can refresh it
  • The pages that matter most, up to ten (the login counts as one), and up to three forms to test
  • What the site connects to outside: a CRM, a newsletter, webhooks, analytics or advertising tags, a payment gateway
  • How updates are handled today and what went wrong last time
  • Who applies updates and who accepts the report

Later, once you agree

  • A staging copy and a staging admin login, not the live one
  • Written confirmation that the staging copy is private, sends no email and has its outside connections off or in test mode
  • The first month's list of pending updates
  • A named person to contact when an update is held
  • A company-controlled secure handoff agreed before access: no live passwords, keys, private code or customer records by ordinary email.

You keep the live site, hosting and all passwords. We work on a private staging copy only; your team applies the passed updates to the live site.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “wordpress-updates-staging-tested-each-month” as the subject.