Website maintenance Singapore, with the response times written down.
Updates, backups, monitoring and a named person who answers when it breaks. Any platform — WordPress, Shopify, Wix, or something your last developer built. From S$150/month. Same-day response on urgent issues.
A website is not a purchase, it is a set of subscriptions and certificates that all expire on different days. Click one — this is what actually happens when it lapses.
Severity: total outage
Domain expires
Website and company email both stop. Not slow — gone. Recovery can take days, and during the redemption period the renewal fee is far higher than the normal one.
How most people find out: a customer says “your site is down”. The renewal reminder went to a staff member who left.
Severity: browser warning
SSL certificate expires
Every browser shows a full-page security warning before your homepage. Forms stop being trusted, and paid traffic bounces immediately. Free certificates renew automatically — until the automation quietly fails.
How most people find out: an angry screenshot from a client. Monitoring catches it days earlier.
Severity: total outage
Hosting lapses or the card fails
Site suspended. Some hosts delete data after a grace period. An expired company card that nobody updated is a surprisingly common cause of a dead website.
How most people find out: the invoice was going to an inbox nobody reads any more.
Severity: silent decay
Plugin, theme or app licences expire
Nothing breaks today. Updates simply stop arriving, so the component sits frozen while vulnerabilities are published against it. Six months later it is the way in.
How most people find out: they do not — until something is exploited or a feature stops working after a platform update.
Severity: revenue stops
Payment or API keys rotate
Checkout fails, or the form stops reaching the CRM. The page still looks perfect, which is why this one can run for weeks. Every day it runs is a day of orders or leads you paid to acquire and did not receive.
How most people find out: reconciliation at month end. Monitoring plus a scheduled test transaction catches it same-day.
Severity: forced emergency
PHP or runtime version goes end-of-life
The host eventually forces an upgrade. If the site was never kept current, that forced jump breaks things all at once — and it happens on the host's schedule, not yours, usually with short notice.
How most people find out: an email from the host giving 30 days. Staying current turns a crisis into a routine update.
Severity: the one that ends companies
The backup that was never tested
Backups do not announce failure. They stop running, or run on the same server that later gets compromised, or produce files nobody has ever tried to restore. You find out on the single day it matters.
How most people find out: during the disaster. This is why we restore one to staging every quarter and record the result.
01
S$150
Where care starts, per month
02
Same-day
Response on a site that is down
03
Daily
Off-site backups
04
Quarterly
Restore actually tested
Chapter 01
What “we’ll get back to you” should actually mean
Most maintenance pages in Singapore promise support without ever defining it. Here is our severity scale, what qualifies, and what happens next.
Severity
What qualifies
First response
What we do
P1 — Down
Site unreachable, SSL warning, checkout failing, site defaced or flagged by Google
Same day, in SGT business hours
Stop the bleeding first — restore, roll back or take a holding page live — then diagnose
P2 — Broken
Forms not delivering, a key page erroring, payment or CRM integration silently failing
Within one business day
Reproduce, fix on staging, deploy, then test the whole path end to end
P3 — Degraded
Something looks wrong on one browser, a slow page, a layout issue on one device
Within two business days
Queued into the next maintenance window unless you say it is urgent
P4 — Change request
Update a phone number, swap a photo, add a team member, publish a post
Same week
Included in the plan up to the monthly allowance, no separate invoice
The honest small print
What we are not promising
A response time is only worth something if the exceptions are stated up front. Ours are short, and we would rather you read them now than discover them at 11pm.
Business hours are Singapore business hours. Monday to Friday, 9am to 6pm. If you need genuine 24/7 cover, that is a different arrangement and a different price — and we will tell you rather than implying we are always awake.
Response is not resolution. We commit to answering and starting within the window. A complex data-loss recovery can take longer than a plugin rollback, and pretending otherwise helps nobody.
Things outside our control are outside our control. A host-wide outage or an expired domain registered in someone else's name have to be escalated to that provider. We handle the escalation; we cannot invent access we do not have.
We need the access to fix it. Credentials sit in your company's name, and we hold delegated access. Sites where we are told to work without proper access get a worse response time and we say so at the start.
A backup you have never restored is a hope, not a plan.
Chapter 02
What a maintenance month actually contains
Not a list of adjectives. A schedule, by asset, with who is responsible for each line.
Asset
What gets done
How often
What you see
Files & database
Off-site backup with rolling history
Daily
Backup status in the monthly report
Uptime & SSL
Monitoring with alerting to a person, not a dashboard
Continuous
Any incident and how long it lasted
Core, plugins, apps
Updates applied on staging first, with a rollback path
Weekly
What was updated, and anything deliberately held back
Forms & checkout
Live test submission or test transaction
Weekly
Pass or fail, with the fix if it failed
Security
Malware and file-integrity scan, login hardening reviewed
Monthly
Clean report or the remediation done
Performance
Core Web Vitals and page weight checked against the budget
Monthly
The numbers, and what moved them
Content
Small edits — phone numbers, hours, staff, a post
On request
Included up to the plan allowance
Expiries
Domain, SSL, hosting and licence renewal dates tracked
Ongoing
Advance warning, not an outage
Restore
A backup actually restored to staging and confirmed working
Quarterly
Dated evidence that recovery works
The whole thing
A written report you can forward to your boss
Monthly
One page, in plain English
If your site runs on WordPress specifically, the plugin-level detail — which plugins we allow, how we audit them, what we remove — sits on our WordPress developer Singapore page. This page is the platform-agnostic version.
Chapter 03
We maintain it whatever it was built on
Most maintenance pages in Singapore quietly mean WordPress. Ours does not — but what needs doing genuinely differs by platform, so pick yours.
WordPress
The most maintenance-hungry of the four, because the plugin ecosystem that makes it flexible is also its attack surface. Core, theme and plugin updates on staging first, licence renewals tracked, and a quarterly audit to remove what is no longer used.
Weekly updates with a rollback path
Plugin licence expiry tracked before it lapses
File-integrity monitoring for injected code
PHP version kept in a supported range
The real risk
Not being hacked by someone clever — being out of date. An unpatched component with a published vulnerability is how almost every compromised site we inherit got in.
Shopify
The platform patches itself, which removes one whole category of work — and creates another. Your apps, your theme customisations and your integrations are still yours to maintain, and a Shopify platform update can break a customised theme without warning.
App subscriptions audited — you are usually paying for two you stopped using
Theme customisations re-tested after platform updates
Checkout and payment tested with a real transaction
Speed work: apps are the usual culprit, not the theme
The real risk
App creep. Every installed app adds scripts to every page and a monthly fee, and nobody ever goes back to remove the ones that were a two-week experiment.
Wix & Squarespace
Less to break, and less you are allowed to touch. Maintenance here is mostly about the things the platform does not do for you: content accuracy, forms actually delivering, SEO basics, and knowing when you have outgrown it.
Form delivery tested — the most common silent failure on builder sites
Content and contact details kept current
Speed within the limits the platform allows
An honest read on whether it is time to move
The real risk
Outgrowing it without noticing. When you start paying for three add-ons to work around one limitation, the platform has become the constraint — and we will say so rather than billing you to maintain a dead end.
Custom builds and applications
No update button. Dependencies, the runtime and the server all need someone who understands the codebase. This is where inherited sites most often have no documentation and no repository access — so the first job is finding out what actually exists.
Dependency and runtime versions tracked
Repository and deployment path documented
Server patching and certificate renewal
An access audit before anything else
The real risk
A single point of failure who left. If one former developer is the only person who ever understood the deployment, you do not have a website — you have a countdown.
Chapter 04
Backups are not recovery
Two questions decide whether a bad day is an inconvenience or an incident. Almost nobody can answer them about their own website.
Question 1
How far back would you go?
If the site had to be restored right now, how much recent work would vanish — an hour of orders, or a month of blog posts and product edits? Daily backups mean up to a day. Hourly means up to an hour. There is no correct answer, only the one you have decided on deliberately instead of by accident.
Question 2
How long would it take?
Not how long the file takes to copy — how long from “the site is down” to “the site is back and correct”, including finding the right backup, restoring it, checking it and repointing DNS if the host is the problem. If nobody has ever done it, the honest answer is that you do not know.
The test
So we actually do it
Every quarter we restore a backup to a staging environment, confirm the site loads and the database is intact, and record the date and the elapsed time. It is unglamorous and it is the only part of a backup policy that proves anything.
Scenario
What most SME sites have
What we put in place
Bad edit or failed update
Hope the host keeps something
Roll back from yesterday's off-site copy, usually within the hour
Site compromised
Backup lives on the same compromised server
Off-site copies untouched by the incident, plus credential reset and hardening
Host outage or suspension
Wait, and hope
Portable backup that can be stood up elsewhere; DNS access in your name to repoint
Developer disappears
No repository, no credentials, no documentation
Access register kept current, everything in your company's name from day one
Accidental deletion by staff
Whatever is in the trash
Rolling history, so last week is recoverable as well as yesterday
Chapter 05
The bill for not maintaining it
Skipping maintenance is not free — the cost just arrives later, in one lump, at the worst possible time. These are the invoices we are most often called in to prevent.
01
Cleaning a compromised site
Removing injected files, resetting every credential, checking what was taken, requesting review from Google Safe Browsing, and rebuilding whatever the backup could not restore. Days of work, and it lands as an emergency.
Plus the downtime while it happens
02
Enquiries that never arrived
A form that stopped delivering three weeks ago. The spend continued, the traffic arrived, and the leads went nowhere. This is the most expensive quiet failure on an SME website because nothing looks wrong.
You never see what you did not receive
03
The forced emergency upgrade
Host gives thirty days on a PHP end-of-life. A site that has been kept current takes a routine update. A site three versions behind takes a rushed rebuild, on someone else's deadline.
On their schedule, not yours
04
Search visibility bleeding away
Slower every month, broken links accumulating, an outage Google happens to crawl. None of it is dramatic on any single day, which is exactly why it runs for a year before anyone connects it to the traffic chart.
Recovering rankings costs more than holding them
05
Data you cannot account for
Form submissions sitting in a plugin nobody audits, candidate CVs kept indefinitely, a database nobody has looked in. Under Singapore's PDPA the obligation for that data is yours whether or not anyone is maintaining the site.
An obligation, not an IT detail
06
Rebuilding early
The most expensive outcome. A site that could have run productively for five years gets replaced at year three because it became unmaintainable — and the replacement starts the same clock again.
A rebuild is not a maintenance strategy
Chapter 06
Website maintenance cost in Singapore, stated plainly
Google’s own People-Also-Ask box asks this four different ways on this search. Four of the pages ranking above us do not answer it with a number. Here is ours.
Essential
Brochure & content sites
From
S$150 / month
Daily off-site backups
Uptime and SSL monitoring
Core, theme and plugin updates
Monthly security and speed check
Small content edits included
P1 same-day response
Business
Lead-gen & larger sites
From
Scoped / month
Everything in Essential
Staging-first updates with rollback
Weekly form-delivery testing
Monthly Core Web Vitals pass
Larger content allowance
Priced on plugin count and complexity
Commerce
WooCommerce & Shopify
From
Scoped / month
Everything in Business
Checkout tested after every update
Payment gateway and API watch
App or plugin subscription audit
Priority response
Quoted after a store audit
Why the higher tiers are “scoped” rather than a number
Because a flat number for a WooCommerce store with thirty plugins would either overcharge the simple sites or under-deliver on the complex ones. What drives it is honest and short:
Plugin or app count. Every one is something to update, test and eventually remove.
Transactional risk. If money moves through the site, checkout has to be tested after every update rather than assumed.
Content allowance. Two small edits a month is not the same service as twenty.
Condition on handover. A neglected site is stabilised as a one-off project first — a monthly plan should not start with a backlog it can never clear.
What you are actually buying
Boringon purpose
A maintenance plan that is working looks like nothing happening. No outage, no warning page, no lost enquiries, no emergency. It is the least exciting line on your invoice and the one that prevents the most expensive ones.
And if you would rather do it in-house, we will tell you exactly what to put on the checklist. That advice is free.
01How much does it cost to maintain a website in Singapore?+
Our plans start at S$150 per month for a brochure or content site — daily off-site backups, uptime and SSL monitoring, updates, a monthly security and speed check, and small content edits included. Lead-generation sites and stores are scoped rather than flat-priced, because plugin count, transactional risk and content allowance genuinely change the work. A neglected site is stabilised as a one-off project before any monthly plan begins, so the plan is not starting with a backlog it can never clear.
02What is included in website maintenance?+
Daily off-site backups with rolling history; uptime and SSL monitoring that alerts a person; core, theme, plugin or app updates applied on staging first with a rollback path; weekly form-delivery or checkout testing; a monthly security scan and Core Web Vitals check; tracking of domain, hosting, certificate and licence expiry dates; small content edits; a quarterly restore test; and a one-page written report each month. Anything not on that list, we tell you before you sign rather than after something breaks.
03What is your response time if my website goes down?+
A site that is unreachable, showing an SSL warning, failing at checkout or flagged by Google is a P1 — same-day response within Singapore business hours. The first move is to stop the bleeding: restore, roll back, or put a holding page live, then diagnose properly. Broken forms and failing integrations are P2, answered within one business day. Cosmetic issues are P3, within two. Those are response commitments, not resolution promises — a data-loss recovery takes longer than a plugin rollback, and we would rather say so than promise a number we cannot keep.
04How often should a website be maintained?+
Backups daily, monitoring continuously, updates weekly, security and performance monthly, and a restore test quarterly. Updating “when we remember” is the pattern behind almost every compromised site we are called in to clean, because the window between a vulnerability being published and being exploited is now days rather than months. The cadence matters more than the effort — a small site done weekly is safer than a large one done occasionally.
05Do you maintain sites you did not build?+
Regularly — it is most of this service. We start with an access audit (who holds the domain, hosting, database, repository, licences and Google properties) and a technical audit of versions, plugins, backups, security and performance. You get that as a written document you can act on with us or anyone else. Then we stabilise: backups and updates first, so the risk stops growing while you decide what to do next.
06Do you maintain Shopify, Wix or Squarespace sites?+
Yes. The platform patches itself on those, which removes one category of work and leaves another: app and add-on audits, theme customisations re-tested after platform updates, checkout tested with a real transaction, forms verified as actually delivering, and content kept current. On builder platforms we will also tell you honestly when you have outgrown it — when you are paying for three add-ons to work around one limitation, the platform has become the constraint.
07Can I cancel anytime?+
Yes, monthly with no lock-in period. Your hosting, domain, repository and every credential are in your company's name throughout, so cancelling means the plan stops — not that anything is held hostage. We will hand over the current backup set, the access register and the documentation. A maintenance provider who needs a contract to keep you is telling you something about the service.
08Is website maintenance really necessary if nothing is wrong?+
The whole risk is that nothing looks wrong. A site does not fail on the day it stops being updated — it fails months later, all at once, usually through a component with a published vulnerability that had a patch available. Meanwhile domains, certificates, hosting and licences all expire on their own schedule, and a backup nobody has restored is an untested assumption. Maintenance is what keeps those from becoming simultaneous.
09Does maintenance affect PDPA compliance?+
It touches it directly. Whatever your forms collect — enquiries, applications, orders — is personal data your organisation is responsible for under Singapore's Personal Data Protection Act, and an unmaintained site is where that data quietly accumulates in places nobody audits. We inventory what each form collects, where it goes and how long it is kept, keep access limited to people who need it, and make sure a compromise cannot be the first time anyone looks. We are not lawyers and do not give legal advice — we handle the technical side of what your policy says you do.
10Can we just do it ourselves?+
If you have someone technical with the time and the discipline, genuinely yes — and we will give you the checklist for free. What usually goes wrong is not capability, it is that maintenance is nobody's actual job: it gets done for two months, then a busy quarter arrives and the gap is only discovered during an incident. The value of paying for it is that the boring work happens on a schedule when nobody is thinking about it.
Start here
Send us the URL. You will get the audit before the quote.
What it runs on, what is out of date, who holds the keys, whether the backups are real, and what is expiring in the next ninety days — as a written document. If the honest answer is that your site is in good shape, that is what you will hear.