Skip to content

Does your web host maintain your WordPress site? What hosting covers and what is left to you

A host is responsible for the server. What happens inside WordPress is mostly yours unless your plan says otherwise. Managed WordPress hosting covers more than shared hosting, but rarely everything. Your host's own support scope page settles it in about ten minutes.

By
WP Ministry
Published

In short

  • A host keeps the server running. Plugin and theme updates, a plugin that breaks a page and your content are yours unless the plan says otherwise.
  • Read your host's scope of support page. The list of what support will not do is the part that matters.
  • Managed hosts differ on the same job. One updates WordPress core for you, and another says it does not.
  • A host's backup is not a backup you control. Ask how often, kept how long, stored where, who restores and at what cost.
  • Where a host cleans a hacked site, it does so on conditions. Read them before you need them.
  • If your plan covers every job on the list and you have restored a backup once, you do not need a care plan.

Your host is responsible for the server: the hardware, the network, the web server software, PHP and the database server. What happens inside WordPress is mostly yours unless your plan says otherwise. That means plugin and theme updates, checking the site after them, a plugin that breaks a page, and the content itself.

Managed WordPress hosting covers more than shared hosting, but rarely everything, and two managed hosts can answer differently for the same job. Sometimes the host's plan is enough. This page shows how to find out for yours.

Where the host's job ends

WordPress's security documentation draws the line this way: web hosts are often responsible for the infrastructure a site sits on, and not for the application installed on it. It asks site owners to understand where the host's responsibility ends and theirs begins.

Three kinds of service come up on this page.

  • Shared hosting puts your site on a server that hosts other websites besides yours.
  • Managed WordPress hosting is a plan built around WordPress, where the host takes on some of the work inside it. "Managed" has no fixed meaning: each host defines it in its own documents.
  • A care plan is a service, sold apart from hosting, that does the work inside WordPress: updates, backups, checks and fixes.

Who does what

The jobShared hostingManaged WordPress hostingOur care plans
Server software and the PHP versions on offerThe hostThe hostNot included. Hosting is not part of a plan
WordPress core updatesWordPress installs its own maintenance and security releases by default. Beyond that it varies: check your planVaries: check your planWeekly, on every plan
Plugin and theme updatesYou, unless the host's updater covers them: check your planOften you, or a paid add-on: check your planWeekly, on every plan
Checking the site after an updateYou, unless the plan says otherwiseAn automated test where the host applied the update. Otherwise youA visual check, and a rollback if something is wrong
BackupsThe host as a rule, sometimes as a courtesy with no guarantee. How often and for how long variesThe host. How often, how long each is kept, and where, variesDaily and offsite, kept for 30 or 90 days by plan
Restoring a backupYou from the panel, or the host on request, sometimes for a feeUsually you, from the host's panelIncluded when an update breaks the site
Malware scanningVaries: check your planVaries: check your planSecurity scanning on every plan
Malware cleanupUsually youSometimes the host, on conditionsOn the Care plan and above
Uptime monitoringVaries: check your planVaries: check your planOn every plan
Fixing a broken siteThe host for a fault in the server. You for a fault in the siteThe same. Some hosts will find the plugin at fault and switch it offA restore if an update broke it. Other fixes come out of a plan's monthly time, on plans that have it
Small content editsYouYouOut of the monthly time on Care, Business and Store. None on Essential
SpeedThe host for the server. You for the site's own codeThe same, with more help on some plansA quarterly speed tune-up on Business and Store

The last column is what our own plans include, as listed on the WordPress maintenance service page. Another provider's plan will differ, so read its list the way you read your host's.

"Varies" fills much of the table because it is the true answer. The next section shows how far the answers spread.

What hosts say about their own plans

Hosts publish what their support covers, often on a page called "scope of support". Each statement below comes from that host's own documentation as it stood in October 2026, and is about that host only. Plans change, so read the page for your own plan. Where a host's terms are cited, this page reports what they say and is not legal advice.

Updates

WordPress does part of this itself, on any host. By default it installs its own maintenance and security releases in the background, and a site first installed on WordPress 5.6 or later gets major releases the same way. Plugins and themes update on their own only where an administrator has switched that on, one plugin or theme at a time. WordPress's documentation notes that a hosting company can switch those controls off.

Hosts then differ.

  • SiteGround says its managed WordPress service includes automatic updates of the WordPress core and of free plugins. Updating plugins along with WordPress is an option in its updater's settings, and the updater saves a backup of the site each time it runs.
  • WP Engine updates WordPress core automatically. Security and maintenance releases cannot be put off, and a major release can be deferred for 30 days. Its update program requests the site before and after an update and tries to roll back if the site does not answer normally afterward. It leaves plugin and theme updates to the customer's discretion and offers an automated update service for them separately.
  • Kinsta says it does not provide updates for WordPress core, and that customers are responsible for installing, updating and removing plugins and themes. It sells automatic plugin and theme updates as an add-on. The add-on compares the home page and four other pages before and after, and restores a backup taken before the update if it finds a problem.

Where a host tests after an update, the test is automated: whether the site answers, or whether a handful of pages look the same. WP Engine's own page notes that an update can leave a feature incompatible with a plugin or theme without breaking the site. A form that stops sending or a checkout that stops taking payment is still yours to notice. How to safely update WordPress, plugins and themes has the routine.

When the site breaks

Each of these hosts separates a fault in the server from a fault in the site.

  • SiteGround calls keeping its platform running its most essential responsibility. When its servers are up and a website is down, it says it may or may not be able to help. Problems that come from the website itself, such as code that causes errors or a conflict between parts of the site, are outside its support scope.
  • Kinsta will help identify the PHP file behind a fatal error and disable the plugin or theme at fault to get the site back online. Fixing the code is left to that plugin's or theme's developer.
  • WP Engine gives limited support for third-party plugins and themes: it helps identify issues on the server side and reads the logs. Plugin and theme bugs, and conflicts with WordPress core or custom code, are outside its scope.
  • Bluehost says its support does not fix errors caused by third-party plugins or alter custom code. It can help identify the issue, and restore a backup or revert a change if one is available.

So the usual help is finding the fault, and sometimes switching off the plugin behind it. The repair is yours. How to tell whether the fault is the host or the site covers the faults that are the host's to fix.

Malware

  • SiteGround fixes problems that arise from its own maintenance of server security, such as an exploit in the server software. Sites hacked through weak or leaked passwords, old website software or malware, which it places under the owner's full control, are not covered. It advises restoring from a backup and contacting cleanup professionals.
  • Bluehost's user agreement has the customer use best efforts to keep their content free of malicious code. Its help pages say a compromised site may be suspended temporarily to protect the server, and that the owner is given the opportunity to clean the infection.
  • Kinsta has a security pledge: if a site is hacked while hosted there, it works with the owner at no charge to try to undo the damage. The pledge excludes sites with nulled plugins or themes, and the owner must finish the follow-up steps within one business day to stay covered. It inspects only sites that show specific evidence of an infection.
  • WP Engine scans and cleans a site that becomes infected while on its platform. It will not submit a site for a scan without a specific indication of infection, and it does not clean a site that arrived already infected.

Where a host cleans, it cleans on conditions, and it acts once there is evidence. Noticing is still yours. How to check whether your WordPress site has been hacked has the checks you can run yourself.

Monitoring, speed and edits

  • Monitoring. Kinsta checks each site every three minutes. If a site is not loading because of its infrastructure, its engineers respond. If the cause is in the site, such as a plugin conflict or a code error, it notifies the owner, and the fix is outside its scope.
  • Speed. SiteGround says performance problems caused by slow PHP code or database queries are outside its scope. Kinsta investigates a repeatable performance problem to rule out the server and the platform, and lists optimizing a site for speed tests as out of scope. WP Engine lists slow WordPress performance and performance audits among the things its support covers.
  • Edits. Kinsta lists changes to a site's content, appearance and functionality as work for a developer. Bluehost's support does not modify HTML, CSS, JavaScript or PHP.

The WordPress site health check shows what one page answers to a request from outside right now. It is a single look, not monitoring.

A host's backup is not a backup you control

WordPress's documentation says most hosts back up the entire server, that requesting a copy of your site from those backups takes time, and that owners need to learn to back up and restore their own. It recommends keeping at least three to five recent backups in different places: for example one on the hosting server, one in cloud storage and one on your own computer. By that advice, the host's copy is one of three.

Here is what five hosts publish about their own backups, in alphabetical order.

Host and planHow oftenKeptStoredRestoring and downloading
DreamHost, sharedNot statedOn average two weeks of files and five days of databases, not guaranteedNot statedYourself, from the panel. Restoring the files does not restore the database
DreamHost, DreamPressDailyUp to two weeks, or four on DreamPress Pro. Up to ten manual backups, never removedNot statedYourself, from the panel
Hostinger, web hostingWeekly. Daily on plans that include it, or as a paid add-onDaily backups for 7 daysDaily backups apart from the hostingYourself: files, the database or both. Downloadable. Mailboxes are not included
KinstaDaily14, 20 or 30 days by planOn the same host machine as the siteYourself. One downloadable backup a week
SiteGround, sharedDailyUp to 30 daily copiesOn a different server, for most sites in a different locationYourself: everything, or files, databases or email alone. Downloading depends on the plan or a paid backup service
WP EngineDaily30 daysOffsite on Amazon S3, in the same region as the site, encryptedYourself. Downloadable as a ZIP archive

A sixth host, Bluehost, describes its backups as a courtesy and says it is not liable for the data on an account. Its user agreement makes backing up the customer's sole responsibility.

What to check about yours

  • How often. A weekly backup can cost you up to a week of orders, posts and form entries.
  • Kept how long. A problem found after the oldest copy has gone cannot be undone from the host's copies.
  • Both parts. WordPress's documentation says a full restore needs the database and the files. DreamHost's file restore on shared plans, for one, leaves the database as it is.
  • Stored where. A copy on the same machine as the site shares that machine's fate. Kinsta says its backups sit on the same host machine as the site, and sells copies to your own cloud storage as an add-on.
  • Who restores, and at what cost. Most of the plans above let you restore from the panel. One restores on request, for a fee.
  • Whether you can take a copy away. WP Engine says its backups cannot be sent to another service automatically, though you can download one. Kinsta and WP Engine both disallow some backup plugins, and both allow tools that send backups to storage elsewhere.
  • What happens when the account is the problem. Bluehost says backups are not given to accounts that have been suspended or terminated, unless it agrees otherwise in writing. SiteGround says deleting a site ends access to its backups. Kinsta keeps a deleted site's backups for 14 days.
  • Whether a restore was ever tested. WordPress's documentation recommends making a manual backup once in a while to be sure the automatic ones work. Hostinger's own documentation advises downloading a copy and testing restores occasionally.

A backup you control is one you hold a copy of, outside the host, and have restored once. How to schedule automatic WordPress backups shows how to prove that a backup restores, and WordPress backup plugins compared covers the tools that send copies to storage of your own.

The ten-minute check

WordPress's guidance for a hacked site tells owners to ask the host what its backup policy is. Ask before that day, and ask about the rest at the same time.

  1. Step 1: Find the name of your plan

    It is on the host's billing screen or your last invoice. Hosts answer differently for each plan, so every question below is about that plan.

  2. Step 2: Read the host's scope of support

    Search the host's help pages for "scope of support" and for "backup". Read the list of what support will not do. Look for the words "add-on" and "fee".

  3. Step 3: Look at what is waiting inside WordPress

    Log in and open Dashboard, then Updates. Plugin updates that have been waiting for weeks mean nobody is applying them. Then open Tools, then Site Health, select the Info tab and expand Server to find "PHP version". The WordPress and PHP end-of-life checker says whether that version still gets security fixes.

  4. Step 4: Send the host these questions

    Paste this into a support ticket. Replace the words in capitals.

    text
    Subject: What my plan covers for DOMAIN
    
    I am on PLAN NAME for DOMAIN. Could you answer these for my plan,
    or point me to the page that does?
    
    Updates
    1. Do you update WordPress core on my site? Minor releases, major
       releases, or both?
    2. Do you update plugins and themes? Does that include plugins I
       paid for?
    3. After an update, is the site tested? What does the test look at,
       and what happens if it fails?
    
    Backups
    4. How often is my site backed up? Does each backup hold both the
       files and the database?
    5. How long is each backup kept?
    6. Are backups stored on the same server as the site, or elsewhere?
    7. Can I restore a backup myself? Can I restore the files or the
       database alone? Is there a fee?
    8. Can I download a backup to keep?
    9. What happens to the backups if the account is suspended or closed?
    
    Security
    10. Is my site scanned for malware routinely, or only when I report
        a problem?
    11. If the site is hacked, do you clean it? On what conditions, and
        is there a fee?
    
    When something breaks
    12. If a plugin or a theme breaks the site, what will support do?
    13. Is my site monitored for downtime? Who is told, and what do you
        do when the fault is not the server's?
    14. Which PHP versions does my plan offer, and who changes the
        version?

An answer that does not name your plan, or does not say who does the job, is not an answer yet. Ask again, or ask for the page it comes from.

What to conclude

When the host's plan is enough

You do not need a care plan if the answers come back like this:

  • the host updates WordPress core, plugins and themes, including the plugins you paid for;
  • something tests the site after each update, and you are willing to look at the pages that earn you money yourself;
  • backups are daily, hold both parts, are kept for weeks, sit away from the site's server, and can be restored by you;
  • the host cleans a hacked site, on conditions you can meet;
  • you have someone to call when a plugin breaks a page.

Add two things and you are covered. Download a backup once a month and keep it somewhere else. Restore one to a staging copy once, so you know it works.

What is left over when it is not

Going by the hosts' own documents, these are the jobs that most often stay with the owner:

  • plugin and theme updates, above all for plugins bought outside WordPress.org;
  • looking at the site after an update, beyond whether it loads;
  • repairing what an update or a conflict broke;
  • a second copy of the backups, outside the host;
  • cleaning up after a hack when the host's conditions are not met;
  • content edits, and speed work in the site's own code.

There are three ways to cover them. Do them yourself, on a schedule. Hire a developer each time something breaks. Or hand the routine to a care plan. Ours is the WordPress maintenance service: a monthly care plan that keeps one WordPress site updated, backed up, monitored and scanned, and restores it if an update breaks it. Hosting is not part of a plan, so it works beside your host and does not replace it.

Common questions

Does managed WordPress hosting include plugin updates?

Not always. Kinsta says customers are responsible for updating plugins and themes, and sells automatic updates as an add-on. WP Engine leaves plugin and theme updates to the customer's discretion and offers a separate update service. SiteGround says its managed WordPress service updates the WordPress core and free plugins. Ask about your own plan, and about plugins you paid for.

Will my host fix my site if a plugin breaks it?

Usually it will help find the cause and stop there. The scope of support pages cited here put plugin bugs, conflicts and custom code outside what support does. Some hosts will switch off the plugin at fault to bring the site back, and some will restore a backup. Repairing the code is left to you or the plugin's developer.

Is my host's backup enough?

It can be, if it is daily, holds the database and the files, is kept for weeks, is stored away from the site's server and can be restored by you. Even then, WordPress's documentation recommends three to five recent backups in different places. Download a copy from time to time, and restore one once as a test.

Will my host clean up a hacked site?

Some do and some do not, and those that do set conditions. SiteGround's scope of support says sites hacked through weak passwords or old software are not covered. Kinsta and WP Engine clean a site that was infected while hosted with them, once there is specific evidence of an infection. Read your host's policy before you need it.

Who keeps PHP up to date?

The host decides which PHP versions are available, and WordPress's documentation says many hosts let you change the version yourself. WordPress recommends PHP 8.3 or greater. Site Health shows the version your site runs, under Info, then Server. Before you change it, take a backup and update your plugins and theme.

More on this subject

Would you rather we looked after it?

The Essential plan is $39 a month. Updates, backups, monitoring and security scanning. No edit time. It starts with a free diagnosis.