
Most sites are not maintained, they are repaired after something breaks. Axiom runs yours on a fixed monthly plan: core, theme, and plugin updates applied on staging first, security patching, off-site backups, uptime monitoring, and the performance work that keeps Core Web Vitals inside Google's thresholds.
Website maintenance and management for US businesses whose site is a revenue channel, not a brochure. You keep every credential, backup, and log.
Maintenance, security, and performance handled by the team that builds, not by a plugin on autopilot.
Patchstack recorded 7,966 new WordPress ecosystem vulnerabilities in 2024, 96% of them in plugins. Skipping updates is dangerous and applying them blind breaks pages. We apply every update on staging, check the templates that matter, then release.
Uptime and error monitoring runs continuously, so we are already looking at the problem before your team hears about it. Alerts route to engineers, not into an inbox nobody watches.
Performance decays quietly as images, scripts, and plugins accumulate. We track LCP, INP, and CLS against Google's published thresholds each month and fix the regression that caused the drift.
An untested backup is a rumour. Backups run off-site on a schedule and are restore-tested, so recovery is a procedure we have already rehearsed rather than a hope.
Plans include a standing block of development time for the copy tweaks, new sections, and small fixes that otherwise queue behind a purchase order.
We start with an audit and a written inventory: hosting, DNS, certificates, licences, and access. Everything documented in your account, so the knowledge survives a change of vendor.
The difference between a maintenance plan and an auto-update plugin is that somebody looks at the site afterwards.
Core, theme, and plugin updates go to a staging copy and are checked against your key templates before anything reaches production.
Vulnerability feeds are monitored continuously. Critical patches are applied out of cycle rather than waiting for the monthly window.
Scheduled off-site backups of files and database, with periodic restore tests, because a backup nobody has restored is not a backup.
Continuous checks on availability, certificate expiry, and server errors, with alerts routed to the engineers who can act on them.
LCP, INP, and CLS tracked every month against Google's thresholds, with the regression fixed rather than reported.
What was updated, what broke, what we fixed, and what we recommend next. Not a dashboard screenshot with a green tick and no explanation.
The standing scope of an Axiom maintenance retainer. Plans differ in hours and response time, not in whether the fundamentals are covered.
Applied on staging, checked against your key templates, then released to production with a rollback point in place.
Vulnerability monitoring, out-of-cycle critical patches, file permission and login hardening, and malware scanning.
Scheduled backups of files and database held off the server, with periodic restores to prove they work.
Continuous availability checks, certificate expiry warnings, and server error alerting routed to an engineer.
Monthly measurement of LCP, INP, and CLS with image, script, and caching work to hold the thresholds as content grows.
A standing block of hours for edits, new sections, and small features, so routine changes do not need a new quote.
A written summary of updates applied, incidents handled, performance trend, and what we suggest doing next.
Hosting, DNS, certificates, licences, and credentials recorded in your account, so nothing is locked inside a vendor.
The first month is an audit and a stabilisation pass. After that it settles into a monthly cycle you can predict.
Full review of the site, hosting, plugins, security posture, backups, and performance baseline.
Audit report
Hosting, DNS, certificates, and licences documented, with staging and backups provisioned.
Access inventory
Outstanding updates applied, known vulnerabilities patched, worst performance regressions cleared.
Stable baseline
Staged updates, security patching, backup verification, performance check, and your requested changes.
Release log
Uptime, certificates, errors, and Core Web Vitals watched continuously between cycles.
Alerting in place
When something breaks we roll back or fix forward, against the response time set in your plan.
Incident record
A written monthly summary of what changed, what it cost you in downtime, and what we recommend.
Monthly report
Recurring problems get engineered out rather than re-patched every month.
Improvement backlog
Maintenance is platform-specific. These are the stacks we support and the signals we monitor on each.
Core, theme, and plugin update cycles
Store, checkout, and payment gateways
Theme releases and app compatibility
Dependency and framework upgrades
Runtime version upgrades
Backups, restores, and query health
Caching, TLS, and security headers
DNS, CDN, and edge rules
LCP, INP, and CLS tracking
Availability and certificate expiry
Crawl errors and index coverage
Every change rehearsed first
Three ways to engage, depending on how defined the work is. Every engagement is quoted against an approved scope document.
$500 – $35,000
per project, fixed scope
A defined build with an agreed feature list, milestones, and a launch date. Priced per phase against the scope document.
Fits: new sites, redesigns, replatforms.
Discuss this model$250 – $10,000
per month, continuous
A standing block of development time for ongoing releases, maintenance, performance work, and support.
Fits: live sites that keep shipping.
Discuss this model$30 – $500
per hour
Time-boxed help where scope is still forming: consultation, audits, fixes, or a second pair of hands on your own build.
Fits: short engagements and unknowns.
Discuss this modelEvery engagement is quoted against an approved scope document. Nothing is billed before you sign it off.
Managed hosting keeps the server up. It does not decide whether an update is safe to apply to your site.
A site nobody touches is not stable, it is drifting. Dependencies age, vulnerabilities are disclosed against plugins you already have installed, and browsers keep changing what they reward.
Google publishes explicit thresholds for the Core Web Vitals: 2.5 seconds for LCP, 200 milliseconds for INP, 0.1 for CLS. A site that met them at launch usually stops meeting them a year later, not because anyone broke it, but because pages accumulated images, scripts, and third-party tags. Maintenance is the work of noticing that before it costs you rankings or conversions.
The alternative is the emergency: an exploited plugin, a checkout that quietly stopped working on mobile, or a restore from a backup nobody had tested. Those cost more than a year of maintenance, and they always arrive at the worst moment.
At Axiom: core, theme, and plugin updates applied on staging before production; security patching and vulnerability monitoring; off-site backups with periodic restore tests; uptime, SSL, and error monitoring; monthly Core Web Vitals measurement with the performance work to hold them; a standing block of development time for edits and small features; and a written monthly report. Access and licence details are documented in your account throughout.
Axiom maintenance runs as a monthly retainer, typically between $250 and $10,000 per month depending on the size of the site, the platform, how much development time you want included, and your required response time. A small brochure site sits at the bottom of that range; a busy eCommerce store with integrations sits nearer the top. We quote against a written scope after the audit rather than guessing from a page count.
Managed hosting keeps the server running, and some hosts auto-apply updates. What hosting does not do is decide whether a particular update is safe for your site, check your templates afterwards, fix the layout the update broke, or measure whether your pages still load fast enough. Those are the parts that protect revenue, and they need somebody who understands how your site was built.
Yes, and it is most of what we do. The engagement starts with an audit of the existing site, hosting, and security posture, plus a documented inventory of access and licences. If we find something structurally wrong, we tell you what it costs to live with and what it costs to fix, and you decide which.
Monitoring alerts our engineers rather than an inbox, so in most cases we are already investigating before anyone on your side notices. Depending on the cause we either roll back to the last known-good release or fix forward. Response times are set in your plan, and every incident is written up in the monthly report.
Yes. WordPress is the most common platform we maintain, and it needs the most disciplined process: Patchstack recorded 7,966 new vulnerabilities across the WordPress ecosystem in 2024, 96% of them in plugins. That is exactly why we stage updates rather than letting them apply automatically, and why reducing your plugin count is usually one of our first recommendations.
Maintenance runs month to month. If you leave, you take everything with you: credentials, backups, documentation, and the access inventory, because those were always recorded in your account rather than ours. We would rather you stayed because the site is stable than because the exit is painful.
Tell us where you want to rank. We'll send back a free audit and a clear plan to get you there.