Maintenance plans all describe themselves the same way. Updates, backups, security, monitoring, support. Four words that can mean a script running unattended or a person actually looking at your site.
Here is what to hold a plan to, in the order that matters.
Updates, and what happens when one goes wrong
Every plan does updates. WordPress core, plugins, themes. That is table stakes and it is not where the difference is.
The difference is the question underneath: what happens when an update breaks something? Most budget plans push updates straight to your live site, unattended. That works right up until a plugin ships a bad version and your checkout throws a fatal error at 3am on a Sunday.
Ask three specific things:
- Are updates tested before they reach the live site, or applied blind?
- Is there a rollback if one fails, and who triggers it?
- Does anyone actually look at the site afterwards, or does "success" just mean the update command returned no error?
The fix: a plan that applies updates automatically with no testing and no rollback is not reducing your risk, it is automating it.
Backups, with the details filled in
"Backups included" is not enough information to be useful. Get four numbers.
- Frequency. How often, on what schedule. Daily is not the only acceptable answer, but you should know the real number rather than assume.
- Location. Off-site or on the same server as your site? A backup stored next to the thing it protects is not a backup, it is a copy.
- Retention. How far back can you go? Malware often sits undetected for weeks, so a 7-day window can mean every restore point is already infected.
- Restore. How fast, and has anyone verified the backups actually restore? Untested backups fail exactly when you need them.
Up Speed runs scheduled off-site backups on every plan, roughly four times a month, with 30-day retention on Starter and one-click restore. Backups are tested quarterly, because a backup nobody has ever restored is a hope.
Security that names what it does
"24/7 security" is marketing. Ask what it consists of, and expect a list of components rather than an adjective.
Malware scanning and detection should be on every plan. That is the baseline: something is watching for injected code and flagged files.
The harder layer is prevention and hardening. A firewall, brute-force protection, two-factor authentication on admin logins, blacklist monitoring so you find out if Google flags you before your traffic vanishes. That layer is not standard on entry tiers anywhere in this market, including ours. On Up Speed it sits on the Professional plan: Wordfence firewall, iThemes hardening, two-factor login and blacklist monitoring.
Then the question everybody forgets to ask: if malware is found, who removes it? Detection and cleanup are different services and plenty of plans quietly only include the first one.
Monitoring, and the line between alerting and fixing
This is the most important paragraph on the page, so here it is plainly.
Your host's uptime SLA covers the server. Only the server. Read one and you will find application errors, plugin conflicts, theme code and software-caused database problems excluded by name. Those are exactly what takes WordPress sites down in practice. Hardware rarely fails. Software fails constantly. So your site can be broken while your host's uptime for the month reads 100%, and everyone is technically correct.
A maintenance plan should close that gap, and most do not. They monitor, and when something goes wrong they email you. You now know about a problem you still have to solve.
What you want is a care SLA: a commitment that if the site breaks, somebody fixes it. Up Speed's SLA is written that way. Plugin and theme conflicts, malware, failed updates and performance regressions are covered work, not carve-outs. Uptime is 99.9%, monitored on 60-second checks, which is about 8.7 hours of unplanned downtime a year at the outside, and if we breach it in a billing month you get a service credit.
It has honest limits. Third-party outages outside our control, like your registrar or a paid API, stay outside it. Direct code changes we were not told about may be billable to untangle. New features are development work, not maintenance. A plan with no exclusions at all is either lying or has not thought about it.
The fix: ask one question of any provider. "If a plugin update breaks my checkout on a Tuesday morning, do you fix it or do you tell me about it?" The answer sorts the market in half.
A report, and a human
You should get a plain-English monthly report showing what was updated, that backups ran, and what the scans found. Not a dashboard you are expected to log into and interpret. Every Up Speed plan includes that report.
And support should mean a person replying, with a stated time. Ours is 48 hours on Starter, 24 hours on Professional, and a 1-hour emergency response on Premium. A vague "fast support" with no number attached is not a commitment.
If the checklist above describes work nobody is currently doing on your site, the Starter plan covers the baseline: tested updates, scheduled off-site backups, malware scanning, 24/7 monitoring, the monthly report and the care SLA. One plan covers one site, flat monthly price, no contract.