Monthly support of the online store
Monitoring, backups with recovery verification, platform updates and fixed response time. We start with a free technical inspection.
Good maintenance is invisible on an ordinary day: the site simply works. Keeping it that way takes three different kinds of work, and the sections below follow them. Security means backups that have actually been restored from, and closing the holes that bots probe on every site they come across. Monitoring means you hear about an outage from an alert, not from a customer. Maintenance covers updates, tracking domain and certificate expiry, small fixes and server administration. Some of this is a one-off job, some of it runs monthly; a free technical check shows where to start. On 31 July 2026 we took measurements from live online stores: several were running PHP 7.3.33, which has had no security updates since December 2021.
Monitoring, updates, backups with tested restores and a fixed response time for outages. A backup nobody has restored from is not a backup yet.
All 3Monitoring, backups with recovery verification, platform updates and fixed response time. We start with a free technical inspection.
System updates, disk space, SSL certificates, caching, backup checks and predictable rollouts with a way back. We start with a free review of your server.
Platform updates, backups with restore verification, availability monitoring and form checks. Starts with a free technical check.
A store keeps selling whether or not it still gets security updates. The difference shows on the day a known hole starts being exploited.
We update what no longer gets security fixes, close service sections, limit password guessing and verify that backups actually restore.
Copies of the database and files outside the server, with encryption and regular test recovery. We start with a free check of what you have now.
The store or site has been running for years, the developer has vanished or changed, and nobody knows which versions sit underneath. What they need is maintenance: first clearing the backlog, then a regular cycle.
We'll review your situation in a free auditThe site was down overnight, the contact form silently stopped sending leads for a week, and the reports only show a dip that gets blamed on the season. Monitoring checks page content and the cart, not just the status code, and alerts you straight away — with separate rules for night hours.
The hosting provider copies something, but where the files live, how far back they go and whether the site actually comes up from them is anyone's guess. The backups section deals with exactly that: off-server storage, encryption and scheduled test restores.
Sites are rarely targeted one by one: they are found by software that crawls thousands of addresses looking for known vulnerabilities. If the platform and its modules have gone years without updates, protection starts by closing exactly what that software is looking for.
The project has outgrown shared hosting, or the server was left behind by a previous developer. A full disk, an expired certificate and an unsupported PHP version are all predictable months ahead, yet they arrive as a surprise when nobody is watching.
We look at what runs under the site, where the backups are and whether anyone has restored from them, and when the domain and certificate expire. That shows whether you need a one-off job, monthly maintenance or both.
We split the findings into urgent and what can wait, and put the scope in writing. If the site has been neglected, the clean-up becomes a separate piece of work instead of being spread across the retainer.
Step-by-step updates tested on a copy, closing vulnerabilities, setting up backups and monitoring. How long it takes depends on how long the site has gone without updates.
The first test restore shows how long bringing the site back from a backup really takes. We tune the monitoring thresholds until the false alarms stop.
Updates in an agreed window, backup checks, expiry tracking and small fixes. Once a month, a report: what was done, what was found and what is worth doing next.
Hardening against hacks, setting up backups and monitoring, and getting a server in order are one-off jobs with a timeline and a signed acceptance certificate. Maintenance is a monthly cycle that keeps the problems from coming back. The usual order is to get things in order once, then maintain them. We won't charge a monthly fee for watching over a mess — that would be paying for patience, not for work.
In how much has to be checked. In a store, the things that break cost money immediately: payments, the cart, shipping labels, product feeds — and they need checking daily. On a site without a store, failures are quiet: the contact form stops sending leads and the phone simply stays silent. That is why these are two separate pages with different scopes of work.
The hosting provider watches its own server, not your site: the server can be perfectly healthy while the store returns a blank page. Backups are the same — the question is not whether they exist, but where they are stored and whether anyone has ever restored from them. On one of our own projects we went seven months without knowing backups weren't being created, and only found out during a scheduled restore test.
You learn about it from monitoring, not from a customer. Whether to wake someone up at night is a decision made in advance: for a store with night-time orders and active ads the answer is usually yes, for a corporate site a message in the morning is enough. Out-of-hours response is a separate tier, and it is written into the contract.
It can, if you update blindly on the live site. So updates go onto a copy first and the modules are checked there, and when several versions behind, we move one step at a time. Sometimes it turns out a module doesn't work on the new version and its author no longer supports it — better to find that out on a copy than in a customer's cart.
No, and anyone who promises that is not telling the truth. We close what is known today and remove the predictable causes of outages: a full disk, expired certificates, unsupported versions. Tomorrow someone will find a new vulnerability in the platform or a module — which is why protection always comes with a backup that has been proven to restore.
That is a different task with a different order of work, and it isn't part of any service in this section. First you need to establish what was done, when, and whether traces remain — only then close the holes. We take an infected site into support only after it has been cleaned up separately. If we find foreign files during our review, we say so immediately and re-estimate the work.
Yes, but we will honestly split it in two: the first month clears the backlog, then comes the regular cycle. The free check shows how big the first part will be. Rolling both into a single monthly fee would be wrong: they are different amounts of work, and this way you can see what you are paying for.
Describe the task in your own words — we will tell you where to start and whether you need what you came for. If you do not, we will say so.