Should you outsource WordPress maintenance? A decision guide for agencies and freelancers
Outsource WordPress maintenance when the work is routine, repeats across many client sites and does not need what you know about the client. Keep the relationship, the decisions about each site and anything the client expects from you in person.
- By
- WP Ministry
- Published
In short
- Hand over what is routine and the same on every site. That is updates, backups, monitoring, scanning and the figures for the report. Keep the client, the decisions and the conversations.
- Do the sums before anything else. If a plan's price leaves nothing after a partner's fee, change the price or keep the work.
- Try a partner on two or three sites, one of them your own, and ask for a restore before you move the rest.
- Give each person at the partner a WordPress account in their own name. Never hand over yours.
- Updating needs an Administrator account, so the role cannot narrow a maintenance login. Limit it by person and by time.
- Read what your client agreements say about subcontractors before any login changes hands.
Outsource WordPress maintenance when the work is routine, repeats across many sites and does not need what you know about the client. Updates, backups, monitoring, scanning and reports are that kind of work. Keep what does need you: the relationship, the decisions about each site, and anything the client expects from you in particular.
Three ways to get the work done
Every client site needs the same round, which the WordPress maintenance checklist lists. As the list of sites grows, there are three ways to get through it.
| Do it yourself | Hire someone | A white-label partner | |
|---|---|---|---|
| What it costs you | Your own time, which grows with every site | A fixed cost every month, whether or not the sites fill it, plus the time to recruit and train | A fee per site, which rises and falls with the number of sites |
| What it does to your capacity | Each new site takes hours from project work | Adds a block of hours at once: idle until the sites fill it, short again when they outgrow it | The routine stops taking your hours. Checking the partner takes some of them back |
| Where quality is controlled | In your own hands | In your process, your training and your review | In the partner's process. You see it through reports, the sites themselves and what your agreement lets you check |
| When someone is ill or leaves | The work waits, or goes on vacation with you | The work stops, and what they knew leaves with them unless it was written down | The partner's to cover. Ask how many of its people know your sites |
| The main risk | You become the limit on your own business | A cost you must keep fed, and one person who holds everything | A company you do not control holds logins to your clients' sites, and its mistakes reach clients under your name |
Which is cheapest depends on your own numbers. The care plan margin calculator works out what your agency keeps each month from the care plans it sells: what clients pay, less what the work costs you. Run it once with your own hours as the cost, and once with a partner's fee.
When outsourcing is the right choice
- The work is the same on every site. Standard themes and well-known plugins, updated in the same order and checked the same way.
- Maintenance takes hours you could sell as projects, and you have the projects. If nothing fills the freed hours, you have swapped your time for a fee.
- You are the only person who can do the round. It waits when you are ill and comes with you on vacation.
- The price of your plans covers a partner's fee and the time you will spend checking the work, and still leaves a margin.
- You are about to hire only for maintenance, and the sites do not yet fill a job.
When it is the wrong choice
- You have a handful of sites and enjoy the work. There is no problem to solve. A partner adds a fee, and someone to manage.
- The sites are heavily custom and nothing is written down. On a site it does not know, a partner cannot tell which update is the dangerous one. Document those sites first, or keep them and hand over the standard ones.
- Clients were promised that you personally do everything. Change the promise openly, or keep the work.
- The plan's price leaves no margin after a partner's fee. That is a pricing problem, and outsourcing does not fix it.
- You will not check the work. Outsourcing moves the doing. The client still holds you responsible for the result.
- A client's agreement rules it out. Some bar subcontracting, or name the people who may have access.
What to hand over and what to keep
Hand over work that is routine, the same on every site, and leaves a result you can check from outside.
- Updates to WordPress, plugins and themes, with a look at the site afterward and a way back.
- Backups. WordPress's documentation says a backup has two parts, the database and the files, and that you need both to fully restore a site.
- Uptime monitoring.
- Security scanning. WordPress's hardening guide says prevention is sometimes not enough, and calls monitoring for intrusions very important.
- The figures for the monthly report.
- Small edits against a written brief: swap this image, change this sentence on this page. Not every partner's plan includes them. WP Ministry's white label plan, for one, has no edit time, and a block of agency hours each month can be added to it.
What WordPress maintenance includes describes each of these jobs and the trace it leaves on a site.
Keep whatever depends on knowing the client.
- The relationship. The calls, the renewal and the bad news.
- Decisions about the site. What to build next, which plugin to replace, whether to move host.
- Design decisions. Anything where the brief would be "make it look better".
- Anything that needs a conversation with the client. A vague request becomes a clear one because you asked.
- Emergencies in which you decide what the client is told. A hacked site, lost orders, personal data exposed. A partner can do the technical work. What the client hears, and when, is yours.
- The accounts. Hosting, the domain and plugin licenses stay in the client's name or yours. A partner gets access to them, not ownership.
How to judge a partner without taking their word for it
Each question below comes with a way to check the answer. A site owner choosing a service for one site has a list of their own, in how to choose a WordPress maintenance service, and most of it applies to a partner too.
A sample report
Ask for a real report from a recent month with the client's name removed, not a designed sample.
Check that every line is something you could verify on a site: a version number, the date of a backup, an uptime figure with its period. The monthly maintenance report template shows a report in which every figure comes from a record.
A trial on two or three sites
Ask to start with two or three sites before you move the list.
Check by making one of them your own agency's site, where you will notice everything and no client is exposed. After each round, open Dashboard, then Updates. Nothing should be waiting, and the screen reads "Your plugins are all up to date." Under Tools, then Site Health, the Info tab gives the version of every active plugin. Compare it with the report.
How updates are tested, and what happens when one breaks a site
WordPress's own instructions for upgrading say to back up the database and the files first, and then: "Verify the backups you created are there and usable. This is essential."
Ask. Is a backup taken before every round? Are updates tried first on a staging copy, on every site or only on some plans? Who looks at the site afterward? When an update breaks a site, is it rolled back, is that part of the price, and who is told?
Check. Ask for the address of the staging copy of one trial site, and open it. Ask for the record of one round: when the backup was taken, what was updated, which pages were looked at.
Where backups are kept, and a restore you watch
WordPress's documentation says to keep at least three to five recent backups, with copies stored in different locations.
Ask. Where are backups stored, and in whose account? How long is each kept?
Check. Ask for one trial site to be restored to a private copy, and for its newest backup as a download. A partner that has never restored one of your sites has shown you nothing about its backups.
Who exactly will have access
Ask for names, not "the team". How many people will be able to log in, and which country do they work from? Does each log in as themselves? Where are credentials stored? What happens to a person's access when they leave the partner?
Check against the accounts. If you create one account per named person, as the next section describes, the Users screen is the list of who can log in.
The hours actually staffed
Ask. On which days, between which hours, in which time zone, does a person read requests? When an alert arrives outside those hours, does a person see it, or does a monitor record it until morning?
Check. During the trial, send a request at a time when you would really need an answer, and note when a person replies.
Whether they ever contact your clients
Ask. Does any email, alert, report, invoice or screen in the dashboard show the partner's name to a client? Which address do reports come from? What do the partner's staff do if a client writes to them directly? Does the agreement say the partner will not approach your clients, during the arrangement and after it?
Check. On a trial site, put an address of your own where the client's would go, and read everything that arrives, including the sender's domain. Then look at the dashboard as a client would. Branding on a report does not reach the Plugins screen, which names every plugin installed, or the Users screen, which shows each account's username, name and email.
How you leave
Ask. Is there a minimum term? How much notice ends it? What is handed back, and when are the partner's copies of backups and credentials deleted?
Check. Read it in the terms before you start. Keep hosting, domains and licenses out of the partner's name. Leaving is then a matter of deleting accounts, with no sites to move.
Put the answers in a written agreement, because a conversation is not something you can hold a partner to. At the least it should settle who may contact your clients, who holds access and how it is removed, what the partner does when its work breaks a site, confidentiality, the notice period, and what is returned or deleted at the end.
Handing over access safely
WordPress's hardening guide warns that someone who gets into an administrator account can install malicious scripts that may compromise the entire server. Two of its general ideas are limiting access and containment. For a partner, that means every login belongs to one named person, does no more than the job needs, and can be removed without touching anything else.
Step 1: List what the partner needs, and what it does not
For updates, backups and monitoring a partner needs a WordPress account on each site, and often a way into the hosting account for restores and staging. It does not need the domain registrar, your billing, the client's email or your own login.
Step 2: Create one account per person, in their own name
In WordPress, go to Users, then Add User. Use the person's own work email address. Leave "Send the new user an email about their account" checked, beside "Send User Notification". WordPress then emails that person a link to set their own password, so no password passes through you or sits in a message.
Do not hand over your own account, and do not make one account for the whole company. With a shared login you cannot tell people apart, and you cannot remove one of them without changing the password for all.
Step 3: Give the least role that does the job
The job Role What its documentation says the role can do Updating WordPress, plugins and themes Administrator On a single site, the only role that can update WordPress, plugins and themes. It can also install plugins, and create and delete users Editing pages and posts against a brief Editor Publish and manage posts and pages, including other users'. It cannot update or install anything, or manage users Changing products, orders and coupons in a store Shop Manager A role WooCommerce adds, to manage a store without full Administrator access. It can view and edit customers and orders So a maintenance login cannot be narrowed by role. Updates take an Administrator, and an Administrator can do everything on the site. Narrow it by person and by time instead, and give people who only make edits an Editor account. On a multisite network, updating and installing belong to the Super Admin, not to a site's Administrator.
Step 4: Require two-factor authentication on every account
WordPress's hardening guide calls two-step authentication a good idea on top of a strong password, and its documentation says this currently requires a plugin. How to set up two-factor authentication in WordPress has the steps, and how to get every administrator to use it.
Step 5: Add the partner to hosting and other accounts as a user
Do not share the hosting login if the host lets you add a person. Some hosts do: WP Engine documents account users with roles that include or leave out billing, and Kinsta documents roles for a whole company and for a single site. Google Search Console works the same way. You add a user with a permission level, and remove them later.
Where files must be reached directly, WordPress's hardening guide says to use SFTP if the host provides it, so that the password is encrypted on its way.
Step 6: Share what must be shared through a password manager
Some things have only one password, such as a license account or an old hosting panel. WordPress's documentation says to avoid using the same password on more than one site, and describes a password manager as a vault for keeping track of them. Give the partner that one entry through the password manager, not by email or chat, and change the password when the arrangement ends.
Step 7: Know what an application password is before a tool asks for one
A partner's dashboard may connect to each site through WordPress's REST API with an application password. WordPress has had them since version 5.6. Each one belongs to a single user and is made on that user's Edit User screen, under Application Passwords. It is for programs, and cannot be used to log in to the dashboard. The screen lists each one with the columns Created, Last Used and Last IP, and a Revoke button of its own.
Have it made under the partner's named account, never under yours.
Step 8: Keep a record
One line for each thing you hand over: the site, the account, the person, the date and what it is for. At the end, that record is the list you work through.
Taking access back when it ends
Step 1: Ask for the last backups first
Before you give notice, ask for the newest backup of each site. Check that each holds the database and the files.
Step 2: Delete each account, and keep what it wrote
On the Users screen, hover over the account and choose Delete. WordPress asks "What should be done with the content owned by this user?" Choose "Attribute all content to another user." and pick one, then press Confirm Deletion. The other choice, "Delete all content.", removes every page and post that person created.
Deleting a user removes that user's sessions and application passwords too.
Step 3: If an account stays, cut it down
Someone who goes on making edits does not need to stay an Administrator. On the Users screen, select the checkbox beside the account, choose Editor under "Change role to…" and press Change. Then open the account. Under Application Passwords, revoke each one. Under Sessions, press "Log Out Everywhere".
Step 4: Close the other ways in
Change every password that was shared through the password manager. Remove the partner's users from the hosting account and from Search Console.
Then remove what the partner installed: a plugin that connects the site to its dashboard, a backup plugin that sends copies to its storage, a monitor. Put your own backups in place before you remove theirs.
Step 5: Look for accounts you did not create
An Administrator can create users. On the Users screen, click Administrator above the table. Every account listed should be on your record.
What your clients need to be told
Start with your own agreement with each client. The agreement decides this, not the name on the report. Look for a clause on subcontractors and whether it asks for notice or consent, any promise that the work is done by you or by named people, and what it says about keeping logins and data confidential. White label means the partner's name is not on the report. It does not mean your agreement lets you keep the arrangement to yourself.
An Administrator account can read whatever personal data a site holds, such as customers, orders and form entries. GDPR and WordPress lists what a site collects. Where the GDPR applies, it has rules for exactly this chain. Article 3 applies it to an organization established in the European Union, and to one outside it that offers goods or services to people in the Union or monitors their behavior there.
The regulation calls whoever decides why and how personal data is processed the controller, and whoever processes it on the controller's behalf a processor (Article 4, points 7 and 8). If your client is the controller and you handle its site's data on its behalf, a partner you bring in is, in the regulation's words, another processor. For that case:
- Article 28(2). A processor may not engage another processor without the controller's prior written authorization, which may be specific or general. Under a general one, the processor must tell the controller of any intended change, so that the controller can object.
- Article 28(4). The same data protection obligations that are in the contract between controller and processor must be put on the other processor by contract. If the other processor fails in them, the first processor remains fully liable to the controller.
So where the regulation applies, a subcontractor who handles personal data is a matter for both agreements: yours with the client, and yours with the partner. The European Data Protection Board's guide for small businesses puts it in one line: a sub-processor can only be appointed if the controller authorizes it in writing.
Running it once it has started
- One channel for requests. Clients write to you, or to an address in your name that you can read. The partner gets requests from one place.
- A written brief for each edit. The page's address, what is there now, what it should say instead in the exact words, who approved it, and when it is needed.
- Check the first months' reports yourself. Take two or three sites. Compare the versions in the report with the Info tab of Site Health, look at the Updates screen, and ask for a backup the report names. After that, check one site a month.
- Send the report yourself, with a line of your own. It is the client's evidence that the site is looked after, and your regular reason to be in touch.
- Agree the emergency route before the first emergency. The partner tells you, and you tell the client.
- Review access every quarter. Compare the Users screen with your record. People leave the partner too.
- Keep a page of notes per site: the host, what is custom, what must be looked at after an update. It makes the partner replaceable.
What you sell must fit what you buy. The care plan proposal template is the offer you put to a client. Before you send it, check that it promises no more than the partner has agreed to give you, in hours, in reply times and in who does the work.
Common questions
Will my clients find out that another company does the work?
They can. Branding covers the report and the support address. A client with an Administrator account on their own site sees every user on the Users screen, with name and email, and every plugin on the Plugins screen. Decide what to tell clients from what your agreement with them says, not from the hope that nobody looks.
Is it safe to give a partner administrator access to client sites?
It is a risk you can reduce and cannot remove. WordPress's hardening guide describes security as risk reduction, not risk elimination. An Administrator can do anything on a site, so what protects you is an account for each named person, two-factor authentication, a record of what you handed over, and removal on the day the arrangement ends.
What happens if the partner breaks a client's site?
The client holds you responsible, because the agreement is with you. Settle three things before you start: whether a restore is included, how quickly you are told, and that you are the one who speaks to the client. Asking for a restore during the trial shows whether the first answer is true.
Can I outsource some sites and keep others?
Yes, and it is the sensible way to start. Hand over the standard sites. Keep the heavily custom ones until they are documented, and any where the client was promised that you do the work.
- ResourceTaking over a client's WordPress site: a checklist to run before you change anything
- ResourceWhite label maintenance agreement: a checklist of what it has to settle
- ResourceMonthly WordPress maintenance report template
- ResourceWordPress care plan proposal template for agencies
- GuideHow to price WordPress care plans: find your floor, find the ceiling, then build tiers
- GuideHow to sell WordPress care plans: when to offer one, what to say and how to answer objections

