Most website maintenance in Singapore stops the day the site goes live.
- Website maintenance is the work that keeps a live site secure, current and reachable after the build is finished: hosting, software and plugin updates, tested backups, uptime and certificate monitoring, and someone to call when something breaks. Any business running a content management system needs it, because the software underneath the site keeps changing whether or not the business does. We maintain 40 sites, and the failure is rarely dramatic. It is usually an update that was available and never applied, or a certificate that expired without anyone noticing.
Nothing breaks on the day you launch.
A site does not decay on a schedule anyone can see. Of 39,594 websites cleaned by Sucuri’s incident response team, 39.1% were running an outdated CMS at the point of infection, and Sucuri states plainly that this is its own client base rather than the whole web. In Singapore, the Cyber Security Agency reported ransomware cases rising from 159 in 2024 to 165 in 2025, and states that SMEs continued to be disproportionately affected due to comparatively lower cybersecurity maturity and limited resources. None of that is a question about your design.
The holes are in the plugins
Patchstack recorded 11,334 new WordPress ecosystem vulnerabilities in 2025. Of those, 91% were in plugins, 9% in themes, and 6 were in WordPress core. The platform is not usually the exposure. The things bolted onto it are.
The window is hours, not weeks
Patchstack puts the weighted median time from public disclosure to first exploitation at 5 hours, with roughly half of high-impact vulnerabilities exploited within 24 hours. The same report found 46% of 2025 vulnerabilities received no fix from the developer in time for disclosure. A quarterly check does not meet either number.
Knowing is not the same as fixing
Verizon's 2025 report, covering 22,052 incidents and 12,195 confirmed breaches, found organisations fully remediated only about 9% of the vulnerabilities their own scans identified. Even on the edge flaws they worked hardest on, 54% were fully remediated, at a median of 32 days. The scan is the easy half.
What happens to a site nobody is watching.
This is the shape of the year after a launch. It is not dramatic, which is exactly why it goes unnoticed. Two points on it fail silently, meaning nothing on the site looks any different on the day the failure happens. Both are the ones we get called about afterwards.
When it is worth paying for, and when it is not.
Maintenance is the item most often cut, and sometimes cutting it is the right call. If the site is not what is losing you work, maintaining it more carefully will not change anything, and we would rather say so than sell you a monthly line item.
Worth doing when
- Your site runs on a CMS and nobody currently has the job of updating it.
- The site takes enquiries, logins or payments, so an outage costs you something that week.
- Whoever built it has moved on and nobody can say where the hosting, domain or licences sit.
- A renewal or certificate has already lapsed once because it was tied to a personal email.
Worth postponing when
- Your site is a few static pages on a hosted platform that patches itself.
- You have in-house IT who apply updates and have restored a backup to prove it works.
- The site is being replaced within months. Buy cover to the launch date and sign nothing longer.
- Nothing on the site takes a submission, a login or a payment, and a day offline costs nothing.
What actually moves the cost.
We do not publish a figure for this, because the same site can be a light job or a heavy one and the difference is not visible from the outside. What we can tell you is which four things decide it, so you can work out roughly where you sit before you speak to anyone, including us.
A ten-page brochure site and a hundred-page site with four custom templates take different amounts of time to check, and the gap is not proportional to the pages. Custom code is the part that breaks when something updates underneath it, so a heavily customised build costs more to hold still than a standard one. Patchstack found 91% of the 11,334 WordPress vulnerabilities disclosed in 2025 were in plugins, which is why we count those rather than pages.
Maintenance is priced on movement more than size. A site where someone adds a project or publishes a post every week needs a staging environment, a review step and more frequent backups than one untouched since launch. If your own team edits the site, we are maintaining a platform underneath people who are actively changing it. Tell us honestly how often it will move, because guessing low is what makes a plan feel expensive six months in.
A site we built is one we already understand. Taking on a site built by someone else begins with an inventory: what is actually installed, who holds the licences, whether backups exist, whether they have ever been restored, and what will break the first time anything is updated. That first pass is the expensive part and it happens once.
A brochure site down for six hours is embarrassing. A quotation form, a client portal or a payment page down for six hours costs money, and most of the cost of maintenance is the cost of how quickly a person has to be awake and looking. Hosting sits inside this too, and it moves with traffic, storage and whether you need a staging environment.
What we maintain, and what we find.
There is no case study on this page, because maintenance has no launch date to point at. What we can show you is the number of sites we are currently responsible for, and what we found when we went and looked at other people’s.
Forty sites, still ours after handover
Creatif Work maintains 40 sites in total under its umbrella. We have delivered over 100 projects across more than 70 clients since 2023. What matters on this page is not how many we have built. It is that we are still running 40 of them rather than having handed them over and left.
Our own stack tops the vulnerable-plugin list
Sucuri's 2023 report, based on 39,594 cleaned websites, names Elementor Pro as the most frequently detected out-of-date plugin with a known vulnerability. Elementor is our default build stack, so we will say it rather than let you find it: the plugin is not the risk, the absence of anyone updating it is. On the 40 sites we maintain, that sits on our licence and our update schedule, not on a client's to-do list.
What 54 Singapore B2B sites looked like
In August 2026 we reviewed 54 Singapore B2B websites. 12 were running an outdated or end of life CMS or plugin, 7 had a contact page or navigation link returning an error, and 5 failed their certificate outright, showing every visitor a full-page security warning. Not one of those businesses knew, because nothing on their site told them.
Clients who have never been to the office
We have worked with clients outside Singapore since 2023. Calls happen on video, documents are signed electronically, and the process is the same one we run with a client down the road. Maintenance is the service least affected by distance.
What people ask before they commit.
The six below are the ones that actually come up, including the two nobody likes asking out loud.
You keep everything. The hosting account, the domain, the licences and the backups are yours, held in your name where the provider allows it, and we document where each one sits and who controls it. If we stop, you hand that document to whoever comes next and they carry on from it. We would rather write it down at the start than have you discover the gaps during a bad week.
He can almost certainly click Update. The job is knowing which update will break the site, taking a restorable backup before it does, and being reachable on the day it does. Patchstack put the weighted median time from disclosure to first exploitation at 5 hours, and found 46% of 2025 vulnerabilities had no developer fix at disclosure, which means part of the work is mitigating things that have no patch to apply yet. That is a standing arrangement, not a favour.
Nothing breaking is the product. In a quiet month the work is updates applied and verified, a backup taken and test-restored, certificates and renewals watched before they expire, and performance measured so drift gets caught while it is still small. Sites generally get slower after launch rather than faster, because launch is when the images and the extra plugins start arriving. You get the record of what was done, so a quiet month is auditable rather than assumed.
Yes. The site, the content, the domain and the hosting account are yours. Any licence bought under our account is named and listed so it can be transferred, and we tell you which ones are ours and which are yours before you sign anything. There is no arrangement here where leaving costs you the website.
Ask them what they update. Managed hosting patches the server, the PHP version and sometimes the CMS core, which is real work and worth having. But Patchstack found only 6 of the 11,334 WordPress ecosystem vulnerabilities disclosed in 2025 were in core, against 91% in plugins, and the plugin layer is the one most hosts explicitly will not touch. A host will also never tell you that your contact form stopped sending mail.
Usually, and we start with an inventory rather than a plan. What is installed, what is out of date, who holds the licences, whether a backup exists and whether anyone has ever restored it. Sometimes that inventory says the site is not worth maintaining, because the theme is abandoned or every update is a gamble. We will tell you that, and we will not sell you a plan to keep alive a site that should be replaced instead.
- A written answer, not a sales proposal
- What is wrong, and what to fix first
- Yours whether or not you build with us