Open Mon–Fri · 9:00 AM to 6:00 PM AEST · Parramatta, NSW
WebGlobals WordPress maintenance services keep Australian business websites backed up offsite, updated, scanned for malware and hidden threats, and monitored for downtime, with a team in Parramatta you can phone. Four care plans from $90 a month ex GST, with backups, updates and security checks on a schedule from monthly to daily, premium plugin licences included, and a client dashboard that shows every check and fix. Month to month with 30 days notice.
WordPress runs a huge share of the web, which makes it a constant target. Left alone, it drifts, outdated plugins are a common cause of breaches, and uncompressed images and unconfigured caching slow pages to a crawl. Our WordPress maintenance services cover the lot: backups, updates, security hardening, uptime monitoring and speed, so you don’t have to think about it.
You built your website and now need someone to maintain it properly. You don’t want to deal with updates, backups or security alerts.
Digital agencies with WordPress clients needing a reliable backend maintenance partner, billed under your brand.
Every care plan covers the full maintenance cycle: backup, update, scan, fix, monitor and report, on the schedule your plan sets.
“Maintenance” can mean almost anything, so here’s the detail. Every item below is part of the care plan, there’s no separate menu of upsells for the basics. Higher plans add depth (more frequent checks, staging, daily fixes and website changes), but the core work is the same on every plan.
WordPress core, plugins and your theme are updated on your plan’s schedule, monthly, fortnightly, weekly or daily. We take a fresh backup first and check the site afterwards, and on Weekly and Daily Watch updates are tested on a staging copy first, so a bad update can be rolled back.
Offsite backups run on your plan’s schedule: monthly on Monthly Watch, fortnightly on Fortnightly Watch, weekly on Weekly Watch and daily on Daily Watch. They’re stored away from your hosting, so even if the server fails there is a clean copy to restore from, and the restore path is tested rather than assumed.
Your site is checked around the clock. If it goes down, or starts responding slowly, we’re alerted automatically and can act, often before you or your customers even notice anything is wrong.
Login protection, file-integrity checks, sensible permissions and a firewall layer (Virusdie and Cloudflare) make the site a harder target. Hardening is ongoing, as new threats appear, the defences get adjusted, not set-and-forget.
Scans look for malware, injected code, backdoors, admin accounts nobody created and spam pages hidden behind a working homepage. Anything found is fixed in your plan’s fix round. Urgent clean-ups before then are quoted on Monthly, Fortnightly and Weekly Watch, and included on Daily Watch.
Speed optimisation is part of Daily Watch: caching, image compression, CSS/JS optimisation, lazy loading and a CDN, tuned against Core Web Vitals with Largest Contentful Paint a key target, because a faster site converts better and ranks better. On other plans, speed work can be quoted as a one-off. It pairs naturally with our SEO services.
Email support during business hours on every plan, with phone support on Fortnightly, Weekly and Daily Watch. Daily Watch also includes unlimited updates and changes to your existing pages, done by the next business day (fair use). You talk to our team in Parramatta, not a ticket bot or an offshore queue.
Every plan includes your own client dashboard: a monthly report you can download, every update applied, vulnerabilities patched, issues found and resolved, backups taken and uptime, plus our work log showing what we did and how long it took. No jargon, no 40-page export.
On Weekly Watch and Daily Watch, a staging copy of your site lets us trial updates, plugins and changes safely before they go live. It’s the difference between “we think this update is fine” and “we’ve confirmed it on a copy of your exact site first”.
We connect, audit and secure your site, then back up, update, scan and fix on your plan’s schedule, with everything recorded in your dashboard.
Connect securely, take a first full backup and run a baseline audit of your site’s health and security.
Close what the audit finds: outdated software, weak logins, unknown admin accounts and exposed files.
Backups, updates and scans scheduled to your plan, from monthly to daily, with uptime monitoring from day one.
Each cycle we back up, update, scan and fix anything found, checking the site after every change.
Every update, fix and hour of work is recorded, with a monthly report you can download.
A good care plan isn’t just backups. Our WordPress care plans bring updates, security scans, fixes, monitoring and support together under one monthly fee, so the whole site is looked after, not just one corner of it. Pick the plan that fits and we’ll handle the rest.
Offsite backups with a tested, one-click restore path if anything goes wrong.
Malware scanning, login protection and file-integrity checks to keep WordPress locked down.
Plugin, theme and core updates applied carefully, checked so an update never breaks your site.
Round-the-clock checks with instant alerts, so downtime is caught and actioned fast.
Backdoors, spam pages and admin accounts nobody created, found and removed on your plan’s schedule.
A real team in Parramatta you can talk to, and a client dashboard that shows every check and fix.
An unmaintained WordPress site rarely fails on a schedule that suits you, it fails the week you’re busiest, or the night before a campaign goes out. Maintenance isn’t about ticking a box; it’s about removing the small risks that quietly stack up until one of them costs you real money, time or trust.
Outdated plugins and themes are one of the most common ways WordPress sites are compromised. A breach can mean defacement, spam, stolen customer data, and a Google “this site may be hacked” warning that scares away every visitor.
Plugins, themes and core need to stay in sync. Apply the wrong update at the wrong time with no backup and no staging, and you can be left with a white screen, a broken checkout, or a layout that’s fallen apart, with no quick way back.
Plenty of owners assume their host has a recent backup, then find it’s days old, incomplete, or stored on the same server that just failed. Without a tested offsite backup, “restore the site” can turn into “rebuild the site”.
Bloated plugins, uncompressed images and no caching make pages crawl. Visitors leave before they convert, and slow Core Web Vitals can drag your search rankings down with them, losing you leads you never even see.
If your site goes down and no one is watching, it can stay down for hours. Every hour offline is lost enquiries, lost sales and a knock to your credibility with anyone who tried to reach you and couldn’t.
These are real findings from websites we look after or were asked to check. In every case the site looked fine from the front, and the owner had no idea anything was wrong. Names and identifying details have been removed.
What the owner saw: forms saying “thank you”
Every contact and admission form had been emailing the theme’s demo address since August 2024. 112 enquiries and applications never arrived.
We pointed every form to the right inbox, replaced a revoked mail key and recovered the missed enquiries from the site’s records.
What the owner saw: a normal website
Windows visitors were shown a fake “verify you’re human” box telling them to run a command on their own computer. It hid from logged-in staff and ran for about five months.
We removed it along with five administrator accounts nobody had created, changed every security key and blocked the spam pages.
What the owner saw: a browser security warning
The site had been under an attacker’s control for around nine months, with seven unknown admin accounts and a tiny hidden file that recreated one on demand.
We removed the backdoor first, tested it was gone, and had the site clean and back online in a day.
What the owner saw: a site that suddenly looked broken
Someone signed in with a genuine admin password, installed a plugin that hid admin accounts, then deleted 24 plugin folders in under two minutes.
We restored it from a backup taken 75 minutes before the attack, and removed the hiding plugin that backup still contained.
What the owner saw: a normal website
A plugin that hid itself and faked its own date made visitors’ browsers do its work: nearly 5,000 requests, including from Google’s and Meta’s ad crawlers.
We switched it off at the database, quarantined it, and confirmed all 3,338 core WordPress files were genuine.
What the owner saw: their blog, as usual
In a separate incident, 23 of its 52 blog posts were turned into casino spam within 45 minutes by a long-standing admin account.
We took the posts offline, locked the account and signed it out everywhere. Our file guard blocked about 60 attempts to open the code editors.
What the owner saw: a few extra sign-ups
Bots used an open registration form to create 861 fake accounts in under two weeks, advertising 713 other websites.
We removed every fake account, locked down registration and added bot protection to the forms.
What the owners saw: “update successful”
Routine updates quietly switched plugins off, including one site’s lead-capture form. On another, the backup plugin itself was off, so nothing ran for six weeks.
A guard on every site now switches them back on, and our system checks for anything turned off every 30 minutes.
What the owners saw: nothing at all
Full copies of the website and its database sat in a folder anyone could download. On one, a leftover restore file with the database password had been exposed for four and a half months.
Backups now live offsite and outside the public folder, and a weekly sweep looks for anything exposed.
hacking-tool probes across our sites, 01/09 to 17/09/2026
failed sign-in attempts, 02/09 to 17/09/2026
bot requests for spam pages in 30 days, on just two sites
business domains we checked could have email sent in their name (23/09/2026)
Over the past year we have seen far more harmful activity on the WordPress sites we look after. Automated bots trying passwords around the clock. Administrator accounts that nobody at the business created. Spam pages slipped in behind a homepage that still looks perfectly normal. Fake plugins built to hide themselves from the dashboard.
Keeping a site safe now takes more checks, more often, and more of our team’s time. So we rebuilt our plans around one simple idea: the more often we back up, update and scan your site, the less time anything harmful has to sit there unnoticed. You choose the rhythm that suits your business, from monthly to daily.
We have also invested in our own maintenance and security system, so every check is consistent, recorded and visible to you. That is why our weekly plan moves to $195 a month, and why we have added Daily Watch for businesses that can’t afford a day of exposure.
Every finding above taught us something, and each lesson became an automatic check. Your plan sets how often we back up, update, scan and fix. The monitoring in step 05 runs all the time, on every plan.
A fresh offsite backup is taken before anything on your site is changed, and stored outside the public web folder.
Updates run on a test site first. Each site is then checked after updating and rolled back automatically if something breaks.
Malware, core files compared against the official WordPress copy, admin accounts nobody created, spam posts and pages, and exposed files.
Anything found is fixed in your plan’s fix round and written into your work log, with what we did and how long it took.
Uptime checked every 5 minutes, bypassing the cache. Plugins switched off unexpectedly are caught within 30 minutes. Every plugin checked nightly against a vulnerability database.
A monthly report in your dashboard: updates applied, vulnerabilities patched, issues resolved, backups taken and uptime.
We work hard to keep every site we look after maintained and safe, but it would be dishonest to call any website completely safe. New threats keep emerging as technology moves on, and AI now helps attackers find weak spots faster and run attacks at a scale that wasn’t possible a few years ago.
When a cached homepage hid a crashing site from a normal uptime check, we changed our uptime checks to bypass the cache and read the page itself.
When routine updates quietly switched plugins off, we built a guard that switches them back on and a check that runs every 30 minutes. Each new threat makes the next check better.
Every plan includes access to your own client dashboard. It shows the same information our team works from, so you don’t have to wonder whether anyone is looking after your site.
● ● ● Client dashboard · yoursite.com.au
September 2026 report
Published · PDF
Updates applied
14
Vulnerabilities patched
2
Issues found and resolved
3 of 3
Backups taken
4
Uptime this month
99.98%
Work log entries
6 · 2.5 h
Illustrative example.
Uptime monitoring, we know before you do if something goes down
Offsite backups, so a recent clean copy is ready to restore
Starting investment per month, ex-GST, with no lock-in contract
A Sydney-based team you can call, no subcontractors
All prices in AUD, ex-GST. No lock-in contracts, cancel with 30 days notice.
Keep it running · per month · + GST · no lock-in
$99 a month including GST
For standard websites: pages, blog and enquiry forms
Fully managed · per month · + GST · no lock-in
$165 a month including GST
For standard websites: pages, blog and enquiry forms
Business-critical · per month · + GST · no lock-in
$214.50 a month including GST
For standard websites: pages, blog and enquiry forms
Save 5% on annual billing: $2,223 a year + GST (you save $117). Paid yearly in advance and non-refundable.
Fully looked after · per month · + GST · no lock-in
$242 a month including GST
The only plan for online stores and websites with advanced functionality
Save 10% on annual billing: $2,376 a year + GST (you save $264). Paid yearly in advance and non-refundable.
✓ Premium plugin subscriptions we use to update, back up, manage and secure your site
✓ Uptime monitoring
✓ SSL and security-certificate check
✓ Your client dashboard: monthly reports, updates, work log, issues found and fixed
Online stores and websites with advanced functionality are covered on Daily Watch only: online stores and payment checkouts, bookings and appointments, member logins or customer accounts, online courses, and custom features or integrations with other systems such as a CRM or stock system. These sites handle payments or customer data, rely on more plugins that update more often, and lose sales or bookings the moment something breaks. Standard websites with pages, a blog and enquiry forms can choose any plan.
On Monthly, Fortnightly and Weekly Watch, anything urgent that has to be fixed before your next scheduled check is quoted and only done once you approve. Urgent fixes are included on Daily Watch. How urgent fixes work
Monthly Watch
$90
Fortnightly Watch
$150
Weekly Watch
$195
Daily Watch
$220
Website type
Monthly WatchStandard websites
Fortnightly WatchStandard websites
Weekly WatchStandard websites
Daily WatchAll, including online stores and advanced functionality
Offsite backups
Monthly WatchMonthly
Fortnightly WatchFortnightly
Weekly WatchWeekly
Daily WatchDaily
Core, plugin and theme updates
Monthly WatchMonthly
Fortnightly WatchFortnightly
Weekly WatchWeekly
Daily WatchDaily
Security scans (malware, backdoors, hidden admins, spam pages)
Monthly WatchMonthly
Fortnightly WatchFortnightly
Weekly WatchWeekly
Daily WatchDaily
Fix round for anything found
Monthly WatchMonthly
Fortnightly WatchFortnightly
Weekly WatchWeekly
Daily WatchDaily
Staging site for testing updates
Monthly WatchNo
Fortnightly WatchNo
Weekly Watch✓
Daily Watch✓
Urgent fixes before the next check
Monthly WatchQuoted
Fortnightly WatchQuoted
Weekly WatchQuoted
Daily WatchIncluded
Website updates and changes
Monthly WatchQuoted
Fortnightly WatchQuoted
Weekly WatchQuoted
Daily WatchUnlimited, next business day, fair use
Small development tweaks
Monthly WatchQuoted
Fortnightly WatchQuoted
Weekly WatchQuoted
Daily WatchUp to 1 hr a month
Speed optimisation
Monthly WatchNo
Fortnightly WatchNo
Weekly WatchNo
Daily WatchIncluded
Firewall
Monthly Watch✓
Fortnightly Watch✓
Weekly Watch✓
Daily Watch✓
Uptime monitoring
Monthly Watch✓
Fortnightly Watch✓
Weekly Watch✓
Daily Watch✓
SSL and security-certificate check
Monthly Watch✓
Fortnightly Watch✓
Weekly Watch✓
Daily Watch✓
Premium plugin subscriptions
Monthly Watch✓
Fortnightly Watch✓
Weekly Watch✓
Daily Watch✓
Client dashboard and monthly report
Monthly Watch✓
Fortnightly Watch✓
Weekly Watch✓
Daily Watch✓
Support
Monthly WatchEmail
Fortnightly WatchEmail and phone
Weekly WatchEmail and phone
Daily WatchEmail and phone
Annual billing saving
paid yearly in advance, non-refundable
Monthly WatchNone
Fortnightly WatchNone
Weekly Watch5%
Daily Watch10%
If something can’t wait for your next scheduled check, such as a security issue, a site that is down, or an urgent change, we’ll still help. We quote the work first and only start once you approve it.
Issues are fixed daily and urgent problems are handled as they happen, at no extra cost.
On every plan, uptime monitoring alerts us if your site goes down, and we’ll tell you straight away, whichever plan you are on.
Every care plan includes the premium plugin subscriptions we use to update, back up, manage and secure your site, licences, updates and support all covered. No separate invoices, no expired keys, no chasing renewals.
We’d rather be upfront than have you sign up for the wrong thing. Here’s who gets the most from a care plan, and where the line sits on what a monthly plan covers versus what’s quoted as a separate project.
Need more than maintenance? We’re a full-service agency, see all WebGlobals services or just ask, and we’ll point you to the right team.
[ Common questions ]
Everything you need to know, if your question isn’t here, just ask.
Book a free site health check. We’ll connect, run an initial audit, and tell you honestly what your WordPress site needs to stay secure, fast and backed up, no obligation.
No obligation. Report within 24 hours.