Synthetic Industry

Standing service wp-keep-wordpress-updated-backed-up-and-monitored · revised 11 October 2026

Standing service

Keep your WordPress site updated, backed up and watched, month after month

Each month we apply updates on a copy first, check your backups still restore, review alerts and your administrator list, and tell you what changed and what needs a decision.

This starts a conversation by email. Nothing is charged, and nothing on your site is touched, until we have agreed scope and terms with you in writing.

The responsibility you hand over

A WordPress site needs regular, tested updates and backups that are proved to restore. When nobody owns that work, updates are either never applied, so known flaws stay open, or applied straight to the live site, so one bad plugin update takes the site down. Backups fail quietly and are first tested on the worst day.

Who it’s for: Owner of a small business with a WordPress brochure or booking site who knows updates and backups matter but has nobody whose job it is.

Usually starts when: Update warnings have piled up for months, a past update broke the site, or the person who built it has moved on.

The result: Your single-site WordPress installation is updated each month after a test on a copy, its backups are checked and restored on a test site each quarter, alerts and the administrator list are reviewed, and each month you see what changed and what is waiting for your decision.

What stays true, and what we do about it

No response-time guarantee is published for this new service. A target is agreed in writing before it starts, set to what a service at this stage can actually keep.

Hours are agreed in writing before the service starts. At launch the service is not staffed round the clock, so we do not offer round-the-clock cover.

What must remain true

  • WordPress core, plugins and themes are updated each month after a test on a copy, or an unapplied update is explained and waiting for your decision
  • The backup schedule ran, a copy sits off the host, and the quarterly restore test passed
  • Uptime and certificate alerts are being received by the named people
  • Every administrator user is a current person you have confirmed

What we watch

  • The update notices shown in the WordPress dashboard and the release notes of each plugin and theme
  • The backup job's own results and the quarterly restore test
  • The uptime and certificate alerts the monitoring job sends
  • The administrator user list in the dashboard

When something happens

Scroll the table sideways to read it all.

WhenWhat we do
The monthly update cycle starts.We update a copy, run the test sheet, and ask for your approval before applying the updates to the live site.
An update makes the site show a fatal error.We stop, return to the previous versions from the copy, and prepare the repair.
Priced as: WordPress critical error or 500
A backup fails or the quarterly restore test does not pass.We tell you under the notification target agreed in writing before the service starts, and prepare a plan to rebuild the backup path.
Priced as: Off-site backup and restore test
An unknown administrator, unknown PHP file or a host malware notice appears.We stop updates, tell you under the notification target agreed in writing before the service starts, and prepare the restore plan.
Priced as: Restore hacked WordPress site
A month ends.We send a short written summary: versions, tests, alerts and decisions waiting for you.

We do on our own

  • Read update notices, backup results and alerts
  • Update and test a copy of the site
  • Prepare repair plans and the monthly summary

We ask you first

  • Applying any update to the live site
  • Removing a plugin, theme or user
  • Any change to hosting, DNS, payments or security settings

We escalate to you when

  • An update breaks the site and cannot be reversed from the copy
  • A sign of compromise appears: unknown administrator, unknown file or a host notice
  • A plugin's release notes or the dashboard update notices show that it is closed or abandoned, or you or its author tell us it has an unpatched flaw

How you know it held. Each month you get the versions before and after, the test sheet, the backup and alert results and a list of decisions waiting. The quarterly restore test record shows the backup can be used.

How we keep it true

This service is never finished. Each month's summary shows whether the site stayed updated and backed up, and it continues until you end it.

  1. Set up off-site backups for a website and prove a restore works Job First

    Back up one site and its database to a storage account you own, then restore a copy on staging and test pages and a record before signing off.

    The backup path the monthly checks rely on.

  2. Apply an agreed security hardening checklist to one WordPress site Job First

    Work through a written ten-item checklist on one WordPress site (backup check, eight hardening changes, risks report), test nothing broke, and hand over the evidence. Risk is reduced, not removed.

    The agreed starting point for users, plugins and permissions.

  3. Set up outside uptime, certificate and domain-expiry alerts and test them Job First

    Configure up to five outside checks for one site with alerts to two named people, then trigger a deliberate test failure to prove the alert arrives. No on-call cover is included.

    The alerts that the monthly review reads.

  4. Bring back a WordPress site showing a critical error or HTTP 500 Job Each time it fires

    Find the PHP fatal error behind a site that stopped loading after an update, fix it on a copy, and hand over a tested change with rollback steps.

    Each time an update breaks the site

    Bought at its listed price when you approve it; not included in the monthly price.

  5. Restore a hacked WordPress site from a clean backup and verify it Job Each time it fires

    Rebuild one compromised WordPress site from fresh core files and a backup dated before the earliest evidence we find, check it against official checksums, and give you a credential reset list.

    Each time a compromise is suspected

    Quoted when needed; not included in the monthly price.

What is included, and what is not

  • A before and after list of versions for each cycle
  • The test sheet for each cycle with a result for each agreed page, form and login
  • The quarterly restore test record
  • A written monthly summary, with any decision waiting for you set out plainly

Included

  • One single-site WordPress installation with up to 10 GB of files
  • A monthly update cycle: core, plugins and themes updated on a copy first, tested against an agreed page list, then applied to the live site with your approval
  • A check each month that the backup schedule ran and a restore test on a non-public copy each quarter
  • A review of uptime and certificate alerts and of the list of administrator users, with you
  • A written monthly summary of versions before and after, tests run, alerts seen and decisions waiting for you

Not included

  • New features, design changes, content edits or plugin development
  • Shops, membership sites and any site that takes payments, or Multisite networks
  • Paying for premium plugin or theme licences, which you hold
  • Cleaning or restoring a hacked site: that is a separate job
  • Out-of-hours cover or any guaranteed response time

How we know it’s done

Agreed with you before work starts. Each check produces evidence you keep.

  1. Each monthly summary lists every plugin, theme and the WordPress version before and after the cycle, and any update not applied is listed with the reason and who must decide.

    Evidence: The written monthly summary and the before and after version lists

  2. In each cycle the test sheet shows the agreed pages, one form and one login passing on the copy before the live update and on the live site after it.

    Evidence: The test sheet with a result for each item

  3. Each quarter a restore of the latest off-host backup onto a non-public copy loads the agreed pages and a database record, or the failure is explained and a repair is proposed.

    Evidence: The restore test record with screenshots

Sign-off. You approve each live update and read each monthly summary. A cycle counts as delivered when you accept its summary.

If it fails. If an update cannot be applied safely, the summary says so with the reason and it does not count against the service. If the service is not working for you, you can end it at the end of any month.

When it fits, and when we stop

It fits when

  • The off-site backup, hardening and uptime-alert jobs are done, or you buy them first
  • A non-public copy of the site can be made at your host, or in a private location we hold that is deleted at the end of each cycle, and you can approve updates to the live site each month
  • You hold the licences for any premium plugin or theme, and can supply a named administrator account for this service with a strong unique password and two-step sign-in. It has the full administrator role, because the updates need it

We stop and tell you if

  • The site is already compromised or shows unexplained users or files
  • Updates repeatedly break the site because of an unmaintained plugin that you cannot replace
  • A premium plugin cannot be updated without a licence you do not hold

What could go wrong

Every live update is applied only after a tested copy and with a backup in place, so the previous versions can be restored. Ending the service leaves the site as it is with its latest tested versions.

Scroll the table sideways to read it all.

RiskHow we handle it
An update passes the copy test but breaks something only real use shows.The test sheet covers your key pages, form and login, the live update is followed by the same checks, and the backup is the way back.
Delaying an update leaves a known flaw open for longer.Updates are applied once a month. A security fix released between cycles waits for the next monthly cycle: the service does not watch for vulnerability notices in between. Each summary flags updates whose release notes describe a security fix and asks for your approval. If you want one applied sooner, an out-of-cycle update is quoted separately. The cycle timing is agreed in writing, with no guaranteed response time.
Access given to us is more than needed.We ask for one named administrator account (the role the updates need), protected with two-step sign-in, and host access scoped to this site, which you create and can revoke at any time.

Each change or report is checked by a reviewer separate from the work that produced it before it reaches you. No human supervisor is included unless your agreement names one. At launch the work is largely automated, and we say so.

Stays with a person

  • You approve every update to the live site
  • You approve the removal of any plugin, theme or user

Access we would need

  • A named administrator account for this service, with two-step sign-in
  • Scoped host access or a way to create a copy of the site

Questions

How is this different from the one-off hardening job?

Hardening sets a safe starting point once. This keeps updates, backups and alerts going each month, so the site does not drift back.

Will updates ever break my site?

They can. That is why each cycle runs on a copy first and the live update has a backup behind it. If one does, the repair job is available.

Do you cover WooCommerce shops?

Not in this service. Shops take orders while updates run, which needs a different plan and a separate quote.

Send an enquiry

Send us

  • The site address and host
  • The WordPress and plugin versions if you can see them, and the plugins you rely on
  • Who approves updates and who should receive the monthly summary

Later, once you agree

  • A named administrator account created for this service, with a strong unique password and two-step sign-in, which you can remove at any time
  • Scoped access to the host's panel or secure file transfer, or the means to create a copy
  • The ten pages, one form and one login to test each month
  • No live passwords or customer records by ordinary email

The site, the host and every account stay in your name. We use only the access you grant, change the live site only with your approval, keep any test copy private and delete it at the end of each cycle, and you can remove our access at any time. The administrator account is a full administrator: WordPress describes that role as access to all the administration features within a single site, which is why it is named for this service.

A public HTTPS link only, without login details, query strings or fragments. No code or logs.

Sending emails your enquiry and contact address to our team through our mail provider (Resend). It is not kept in a website database. Do not send passwords, keys, recovery links, confidential code or customer records. Your contact email is unverified; nothing is ordered, charged or reserved. Privacy notice.

Email fallback: open your mail app

If website submission is unavailable, review and send the fallback email yourself. An email fallback is not a website receipt. Or write to hello@syntheticindustry.ai with “wp-keep-wordpress-updated-backed-up-and-monitored” as the subject.