What website maintenance should include every month
Almost every maintenance plan sells the same five things: hosting, updates, backups, uptime and fixing what breaks. All five are necessary. None of them would have found any of the four faults below — and all four turned up within a few weeks, by looking somewhere other than the website.
A website does not fail by breaking. It fails by drifting while everything still works.
The failure everyone plans for is the loud one — the site is down, the form is broken, the certificate expired. Those are real, they are worth insuring against, and a competent host handles most of them. They are also not what costs a small business customers, because they are noticed.
What costs customers is the quiet version: a listing pointing somewhere it should not, a page appearing for a search it can never satisfy, three of your own pages fighting each other, tracking that stopped reporting two months ago. Every one of those passes every automated check, because nothing is broken. Something is just wrong.
Uptime tells you the site is running. It tells you nothing about whether it is working.
Half the list is the boring half, and it should still be in writing.
This is what a maintenance contract almost certainly already covers. It is listed here in full rather than dismissed, because a service that will not put its baseline in writing is worse than one that only offers the baseline.
- Hosting, SSL and backups. The site stays up and can be restored. Table stakes.
- Software and dependency updates. Applied and checked, not applied and hoped for.
- Uptime monitoring. Someone other than you finds out first when it goes down.
- Broken links, images and forms. The things that rot silently and are never reported by customers.
- Speed regressions. A site that was fast at launch and is not now.
Judge this half on price, not on promises. It is a commodity, it is largely automatable, and there is no version of it that produces an enquiry. If a plan contains only these five things, it is hosting with a report attached — which is a fine thing to buy, at hosting prices.
The other half is the reason to pay monthly at all.
Six things, and what they have in common is that each requires somebody to look at something and form a judgement. They are the monthly application of the Growth System: find the earliest stage that is broken, fix that, and ignore the rest until it is.
- Someone reads the search queries — the actual words, not the totals. A total tells you how much you were shown. The query list tells you what people thought you were. That is where intent mismatches, self-competition and entirely wrong audiences become visible, and none of the three appear in a traffic number.
- Everywhere your business is listed gets checked, not just your website. The website is one surface. Profiles, directories and map listings are where a large share of high-intent customers actually meet the business, and they drift independently of anything on your server. A maintenance plan scoped to the website cannot see them by definition.
- Enquiries are counted, and someone confirms the counting still works. Tracking is installed once and breaks quietly — a form changes, a script is dropped, a platform updates. If nobody verifies it monthly, the first sign is a report that says the site is doing well and a phone that is not ringing.
- Two improvements actually get made, chosen from the evidence. Not a list of recommendations. Work completed and live before the report describes it. A retainer where nothing visible happens is the default failure mode of this category.
- A person writes the report, and it leads with what did not work. The number that fell should appear at the same size as the ones that rose, and the reason should be in words. A dashboard emailed on a schedule is a data delivery, not a service.
- Predictions are made in advance and marked afterwards. Before a change is made, what it is expected to do is written down. Next month, it is checked. That is the only mechanism that makes a monthly report accountable rather than descriptive.
Four faults from real client work, none of them a broken website.
These are not illustrations. Each came out of work Aroc ran between June and August 2026 — three from one month of client reporting, the fourth from a profile check made separately in the same period — and each is sourced at the foot of the page. Not one of them would have appeared in an uptime alert, a plugin update log or a speed score.
Why three of these are attributed and one is not. Evergreen Spa gave permission on a recorded call on 3 August 2026, and every Evergreen figure below is already published at /work/evergreen-spa where anyone can check it. The profile and directory findings in fault one live only in internal records and are covered by no such permission, so the finding is reported and the business is not identified.
- Fault one · found by leaving analytics entirely, 28 July 2026
The profile's “Website” button sent customers to Facebook.
On a wellness client’s Google Business Profile — the highest-intent surface that business has — the website field returned a Facebook page rather than the site. Confirmed by querying the Google Places API on 28 July 2026 — an incidental finding during a routine profile check rather than part of that month’s reporting, which is itself the argument for checking routinely. Every person who tapped the profile’s main call to action was sent somewhere other than the website that had just been built for them.
It costs twice. Customers land somewhere that was not designed to convert them, and the traffic never reaches analytics — so it is invisible in the monthly report, and the gap between what the profile earns and what the site records has no explanation. No uptime monitor, plugin updater or speed tool can find this, because it is not on the website.
It was also the fourth instance of one underlying fault for that business: three directory listings were recorded pointing at Facebook rather than the website in an internal brief dated the same day. One is an oversight. Four is a pattern, and finding the pattern required checking the surfaces nobody was checking.
Source: Google Places API, 28 July 2026; the three directory findings are recorded in an internal brief of the same date, and no claim is made about which was found first. Still open at publication, blocked on profile manager access — which is itself the point: it is logged, dated and owned rather than forgotten.
- Fault two · found by asking why a number was zero
One page was shown 191 times and clicked zero times — and the right advice was to accept fewer impressions.
Evergreen Spa’s wellness page appeared 191 times in a month and earned no clicks at all, because Google was matching it to people searching for a wellness resort — somewhere to sleep. Evergreen is a day spa. That single search accounted for 256 of the site’s 552 total appearances that month.
Here is why this is the example that matters. An automated system sees “191 impressions, zero clicks” and recommends improving the click-through rate. The correct recommendation was the opposite: change the page so it stops appearing for that search at all, and accept that the headline impressions number will fall. The client was told the number would fall before the change was made.
Two hundred people who might book is worth more than five hundred and fifty who never will. A maintenance service that reports impressions as a score cannot give that advice, because its own headline number punishes it for being right.
Verdict: a copy fix, not a build. Google Search Console, 28 June – 27 July 2026, published in full at /work/evergreen-spa with recorded client permission.
- Fault three · found by cross-referencing query against page
Three of the site's own pages competed for one search, and Google ranked none of them.
For rawai spa — an exact-offer search shown 51 times a month — the wellness page, the home page and the massage page all competed. Google resolved it by ranking all three between position 42 and 55. Nothing was broken. Nothing was down. Every page passed every automated check.
Finding it required reading the query-and-page view together rather than either alone, which is a person’s job. Fixing it is consolidating the three into one page and pointing the internal links at it, so the search has one obvious answer — editing rather than building, and worth more that month than anything else on the site.
Verdict: self-inflicted, resolved by editing. Same Search Console period, same published page.
- Fault four · found because the report refused to guess
Enquiries could not be counted at all, so the report said so.
The first monthly report for that site could state visits but not contacts, because enquiry tracking had never been installed. The honest options were to report a number nobody could stand behind, or to write down that the measurement did not exist and make installing it the first item of the following month. It said so, and it became the first item.
It is a quiet failure rather than a loud one: the site is maintained, the hosting is fine, and there is no way to tell whether any of it produced a customer. How common that is across small businesses generally, Aroc cannot say and does not claim. Measurement that nobody verifies is measurement you find out about at the worst possible moment.
The same month also recorded a device split that no page-level tool surfaces: average position 13 on phones against 46 on computers, with 351 desktop appearances producing zero clicks. Diagnosed in month one, carried into month two, and named rather than quietly dropped.
Verdict: install measurement first, always. Same Search Console period, same published page.
Automate the collection. Never automate the noticing.
Pulling the data is a job for software and should be. Deciding what any of it means is not, and the four faults above are the argument. Two of them required reading two dimensions of the same data set against each other. One required knowing what the business actually sells. One required leaving analytics entirely and looking at somebody else’s platform.
The clearest test is the one in fault two: the automated recommendation and the correct recommendation pointed in opposite directions. A system optimising for impressions would have spent the month trying to win clicks from people who wanted a hotel. The right answer cost the report its best-looking number.
Which is why a report should be allowed to contain a fall. Correcting who finds you can reduce impressions, and that is the improvement working rather than failing. A service that cannot say so out loud will avoid making the change.
Five questions that separate the two halves.
Ask these of any maintenance or management provider, including Aroc. They are answerable in a sentence each, and a provider doing the work will enjoy answering them.
- Which two improvements did you make last month, and are they live now?
- What did you check that is not on my website — profiles, directories, listings?
- How many enquiries did the site produce, and when did you last confirm the tracking works?
- Which number went down this month, and what did you do about it?
- What did you predict last month, and were you right?
The last one is the hardest and the most revealing. A provider that records predictions and marks them is accountable to something other than its own summary. Almost nobody does it, and it costs nothing but nerve.
If you want the second half of the list, that is what Grow is.
Aroc Growis the monthly service built around this argument: the technical baseline included and not talked about, then two improvements chosen from the month’s evidence and made live, two changes you ask for, directory listings checked every month, and a written report a person wrote and approved. The full list — including what it deliberately does not cover — is on that page rather than in a proposal.
Two honest qualifications, since this article set the standard. Google Business Profile work is conditional on you granting manager access — fault one above is still open for exactly that reason, and a service cannot fix a surface it cannot reach. And the sixth item on the list — written predictions, marked the following month — is not yet a standard part of Grow. It is what the service should do, it is being built into the reporting process, and until it is, saying so is better than implying otherwise.
It follows a diagnosis rather than replacing one. Managing a site before knowing what is wrong with it is maintenance with a bigger invoice, which is why Assess comes first and why the redesign-or-fix question is worth settling before anyone signs a monthly agreement.
Sources for every figure above
- A Google Business Profile whose website field returned a Facebook page · three directory listings doing the same — Google Places API query, 28 July 2026, and an internal brief of the same date. Aroc internal records; the business is not named because permission covers the figures already published elsewhere on this site and nothing beyond them. The correction was open at publication, blocked on profile manager access, and is logged with an owner and a date.
- 191 impressions and zero clicks · 256 of 552 appearances · three pages at position 42–55 · “rawai spa” shown 51 times a month · position 13 on mobile against 46 on desktop · 351 desktop appearances and zero clicks · enquiries not counted in month one — Google Search Console, 28 June to 27 July 2026. Published with recorded client permission at /work/evergreen-spa, where every one of these figures already appears and can be checked.
- “An automated system sees 191 impressions, zero clicks and recommends improving CTR” · the three findings absent from every dashboard — Aroc internal operations brief on the reporting product, written before this article as part of deciding what could and could not be automated. The conclusion quoted here is that document’s own. It is an internal recommendation rather than approved policy, and is quoted as reasoning, not as a commitment.
- Search volume for “website maintenance service” — Google Ads Keyword Planner, United States national, pulled 3 August 2026: 2,400 per month, low competition. Recorded in the intent map rather than on this page, because a volume figure is evidence for choosing what to write, not a claim to make to a reader.
Nothing above is estimated. Where a number could not be verified it is absent rather than approximated. All four faults come from one client account: three from a single reporting period, 28 June to 27 July 2026, and the fourth from a profile check on 28 July 2026 that was not part of that reporting. One account is not a sample, and the claim being made is that these faults are findable and were found — not that they occur at any particular rate across businesses generally.