Contact

ResourcesWhitepapers

Whitepaper

WordPress Care & SLAs: What “Managed” Should Actually Mean

Derick PayneDerick PayneFounder and lead developer

Published 16 June 2026Read 5 min

About this paper

In this paper

Nine sections, about 5 minutes to read.

  1. “Maintenance” is the most oversold word in WordPress
  2. Why a static site is not a safe site
  3. What a real care plan includes
  4. The SLA: where promises become commitments
  5. What care plans cost in South Africa
  6. Care and POPIA
  7. Questions that separate real care from a line item
  8. How Rizonetech approaches care
  9. The next step

A practitioner’s guide to what “managed WordPress” should actually mean — uptime, backups, security, performance, and reporting — and how to tell a real care plan from a line item that quietly does nothing. Written for South African businesses whose website matters to sales.

On this page
  1. “Maintenance” is the most oversold word in WordPress
  2. Why a static site is not a safe site
  3. What a real care plan includes
  4. The SLA: where promises become commitments
  5. What care plans cost in South Africa
  6. Care and POPIA
  7. Questions that separate real care from a line item
  8. How Rizonetech approaches care
  9. The next step

“Maintenance” is the most oversold word in WordPress

Almost every WordPress provider offers “maintenance.” Very few define it. The word covers everything from a genuine, monitored care service to a monthly fee that buys an occasional plugin update and nothing you could point to. The gap matters, because a website that earns enquiries is infrastructure — and unmanaged infrastructure does not stay still, it decays. This paper defines what real care includes, so you can buy the service rather than the word. It is the deeper companion to our guide to WordPress costs in South Africa.

Why a static site is not a safe site

The instinct is that a website which “works” needs nothing. The opposite is true. WordPress powers a large share of the web, which makes it a constant target, and the overwhelming majority of WordPress security issues come from outdated plugins and themes — not from WordPress core itself. A site that is never updated is not stable; it is simply untouched until something automated finds the unpatched gap. Care is the boring, ongoing work that prevents the expensive week.

What a real care plan includes

A credible care plan covers five areas. If a quote is silent on any of them, that silence is the answer.

1. Updates, tested — not just applied

WordPress core, themes, and plugins need regular updates. The difference between a good service and a risky one is testing: updates applied on a staging copy and checked before they reach the live site, so an update never silently breaks a layout or a form. “We turned on auto-updates” is not a care plan.

2. Backups you have actually restored

A backup that has never been restored is a hope, not a safeguard. Real backup coverage means off-site copies, a sensible retention window, and — the part everyone skips — periodic test restores to confirm the backup actually works. The question to ask is not “do you back up?” but “when did you last restore one?”

3. Security, layered

Security is not a single plugin. It is a layered baseline: hardened login with strong authentication, a firewall or platform-level protection, malware scanning, sensible file permissions, and a plan for the day something does get through. Because most breaches trace to outdated components and weak credentials, the update discipline above is a security control.

4. Uptime and performance monitoring

You should not learn your site is down from a customer. Uptime monitoring checks the site around the clock and alerts when it fails, and performance monitoring catches the slow creep — a bloated plugin, an unoptimised image, a database that needs attention — before it costs you a sale. Speed is not vanity; it affects both conversions and search ranking.

5. Reporting you can read

If you cannot see what was done, you cannot tell whether you are paying for anything. A plain-language monthly report — updates applied, backups taken, threats blocked, uptime, and any issues — turns an invisible service into an accountable one.

The SLA: where promises become commitments

A service-level agreement (SLA) is the difference between “we’ll get to it” and a commitment you can hold. For a website care plan, three things matter:

  • Response time — how quickly someone responds when the site is down or compromised, and whether that is business hours or around the clock.
  • Support scope — how many hours of content edits or small changes the plan includes, and what counts as out-of-scope project work.
  • Escalation — who you reach in an emergency, and how. A site-down event at month-end should not depend on a support ticket queue.

Watch the distinction between response and resolution: a fast response is a promise to start, not to finish. Ask which the SLA actually commits to.

What care plans cost in South Africa

As an indicative guide, South African WordPress care plans in 2026 range from around R500 per month for light maintenance to roughly R4,000–R7,500 per month for business and e-commerce sites that need fast response, daily backups, and active security. Hosting is usually separate — shared hosting from roughly R50–R200, managed WordPress hosting around R200–R800, and a VPS from R500–R2,000 per month. Treat these as reference points; the right figure follows from how critical the site is and how much it changes. The cheapest plan is only cheap until the month it fails to prevent something.

Care and POPIA

If your site collects personal information through a contact form, quote request, signup, or checkout, care and compliance overlap. POPIA expects you to apply appropriate technical measures to protect that data — which is exactly what updates, backups, and security hardening are. A neglected site is not only a downtime risk; it is a data-protection risk. Keeping the site current is part of keeping it compliant.

Questions that separate real care from a line item

  • Are updates tested on staging before they reach the live site?
  • When did you last perform a test restore from backup?
  • What is the response-time commitment if the site goes down, and is it after-hours?
  • Do I receive a monthly report I can actually read?
  • What exactly is out of scope and billed separately?

How Rizonetech approaches care

We treat care as the continuation of the build, not an afterthought sold separately. The same discipline that produces a clean, fast site keeps it that way: tested updates, verified backups, layered security, monitoring, and a report you can read. Because a website rarely lives alone — it touches DNS, email, and identity — care sits naturally alongside our broader managed IT work and our website care plans.

The next step

If you are not sure what your current “maintenance” actually covers, ask for the last monthly report and the date of the last test restore. If neither exists, you have your answer — and a good reason to start a conversation about real care.

Published 16 June 2026. Last updated 16 June 2026.

Get your website looked at

Tell us what is not working, or what you want the site to do. We'll tell you plainly what it takes, before any work starts.