Skip to content
Get a quote

Web & Development

The website that no longer maintains itself

Performance, security and maintenance for websites that already bring in business. We do not let them degrade quietly until the day they go down.

  • You have a working site, built by us or by someone else, that generates revenue, leads or brand presence
  • Nobody in the company knows who has kept the updates current since the agency last delivered
  • An hour of downtime means lost money or customers who never come back

01 · What it costs you today

  • You have been hacked and you do not know for how long

    The most expensive scenario: you find out from Search Console or from a customer calling to ask why the site redirects to suspicious ads, not from an internal alert.

  • You lost Google positions without changing anything

    The cause is often gradual performance decay, accumulated plugins, unoptimised images, old code, invisible because nobody is monitoring it.

  • You do not know whether you have a backup, or where it is

    There is often a backup, but it is months old, or it is stored on the same server that has just gone down.

  • You think premium hosting covers you

    Hosting guarantees the server and the network, not the CMS, the plugins or the custom code, the area that produces the vast majority of real incidents.

02 · What you get

  • An initial Core Web Vitals audit on real traffic

    Not a lab simulation. A report on LCP, INP and CLS with a diagnosis of the causes: images, blocking JavaScript, the server, fonts, unstable layout.

  • Security hardening

    Removing unused plugins, application-level firewall rules, forced HTTPS, scheduled updates for the CMS and the libraries.

  • Automated 3-2-1 backups, tested regularly

    Three copies, two types of media, one off site. A backup that has never been tested is not a backup, it is an assumption.

  • Uptime monitoring, with an immediate alert

    We detect an outage before your customers do, not after they call to ask what happened.

  • An incident response protocol

    Response times set in the contract, by severity level, not “we will call you if something comes up”.

  • A monthly report a decision maker can read

    What was done, what was detected, what comes next. Not just a technical log nobody reads.

03 · How we work

  1. 01

    Initial audit

    3 to 5 working days. We assess performance on real traffic and security across versions, plugins, SSL and signs of compromise.

  2. 02

    Hardening and optimisation plan

    Discussed and approved with you, not imposed. We prioritise whatever blocks conversion or exposes the biggest risk.

  3. 03

    Implementation

    1 to 2 weeks, depending on the complexity of the site: technical optimisation, security rules, backups put on proper foundations.

  4. 04

    Monthly maintenance

    Continuous monitoring, a recurring report, and included intervention hours for routine changes, with no separate invoice for every minor request.

04 · Results

  • finebar.roFineBar

    Ongoing maintenance of the online store, alongside performance optimisation.

  • horus-center.roHorus Center

    Maintenance and monitoring after taking over the platform.

These are the figures reported by the clients themselves, for their own accounts, over the periods shown. We do not turn them into derived percentages and we do not present them as reproducible.

05 · What people usually ask us

“It is expensive, we already pay for hosting.”
Hosting covers the server, it does not install plugin updates, it does not test restoring a backup, and it does not spot a known vulnerability before it gets exploited. The right comparison for the cost of maintenance is the cost of an incident avoided: recovering a hacked site typically costs 500 to 3,000 USD, plus emergency hours at over 200 USD an hour, often the equivalent of 1 to 3 years of contract.
“We have tried maintenance before and did not feel the difference.”
Usually because the package bought previously meant only automatic updates, with no monitoring, no report and no written SLA. Our difference is visibility: you see monthly what was done and what was prevented, not just the invoice.
“We handle it in-house.”
That works if the company has a dedicated IT or DevOps role with time consistently allocated. At firms without that role, “in-house” maintenance means nobody is explicitly responsible, which is exactly the scenario that produces updates left undone for years.

06 · Frequently asked questions

What happens if our site is already hacked?
We clean and restore the site, identify the entry point and close it, then propose a hardening plan so it does not happen again. Full recovery, including search engine reputation, can take a few months if there was a penalty.
How is this different from what the hosting company offers?
Hosting is responsible for the server, the network and infrastructure-level uptime. We are responsible for the application: CMS, plugins, code, content, tested backups and monitoring of how the site actually behaves.
How long until we see results on speed?
The basic technical work is implemented in 1 to 2 weeks. A visible improvement across all traffic usually appears in 4 to 8 weeks, because Google reports on a rolling 28 day window.
What happens if we end the contract?
You get full, documented access: credentials, code, the last valid backup. We lock nothing down, the contract rests on the value delivered, not on forced technical dependence.
Can you take over maintenance of a site you did not build?
Yes, subject to an initial audit that establishes the real state of the code. If the audit shows the foundation is too degraded to maintain efficiently, we honestly recommend a rebuild rather than a maintenance contract on a structure that has to be redone anyway.

Shall we talk about your project?

Tell us where you stand. If we are not the right answer for you, you will hear it in the first conversation.

Request a quote