Blog · WordPress maintenance
The monthly maintenance report: how you know you are not paying for nothing

There is a perfectly legitimate fear attached to any maintenance plan: "I pay month after month and… nothing happens. How do I know the work is actually being done?" It is a fair worry, because good maintenance is invisible by its very nature. When everything works, the website "just works" — and that is exactly why it feels like you are paying for nothing.
The antidote is called a monthly report. It is the document that turns "trust us" into "here is exactly what was done". In this article I will show you what a proper report looks like, how to recognise a fake one and how to read it in three minutes, even if you are not technical at all.
Why you need monthly proof, not blind trust
Think of maintenance the way you think of servicing your car. If the mechanic tells you "I checked everything, it's fine" without showing you anything, you have no way of knowing whether they changed the filter or just drank a coffee. The service sheet exists precisely so you can see what was touched. The monthly report is your website's service sheet.
Without it, you are paying for a promise. With it, you are paying for proof. The difference is enormous — and it is exactly why "what report do I get each month?" is one of the most important questions to ask before choosing a maintenance company.
The anatomy of a proper report, section by section
A monthly report worthy of the name contains, concretely, the following:
- What was updated. The WordPress core, the theme and the plugins — with names and versions (from which version to which version). "We ran updates" is not enough; "plugin X from 4.1 to 4.3" is proof.
- The backups taken. How many were made, where they are stored and when it was last verified that they work. If you want to understand why the storage location matters, we have a guide on WordPress backups.
- Security. How many scans were run, how many attack attempts were blocked, whether anything was detected. (Zero attempts reported on a WordPress site is practically impossible — see below.)
- Uptime. The availability percentage and any incidents, along with their duration.
- What was done from the included hours. The content changes or small features carried out that month.
- Recommendations for next month. A plugin abandoned by its author that should be replaced, an SSL certificate expiring soon, a theme that deserves an update.
What a ghost report looks like
At the opposite end is the "report" that says nothing: an email reading "all good, no problems this month" or, worse still, complete silence. The problem? It usually hides exactly what it appears to hide: that almost nothing was done. An "all good" with no numbers, no versions and no detail is not a report — it is a politeness formula.
Warning signs in reports
Even when you receive a document that looks like a report, watch for these signs that it is a façade:
- The same numbers, month after month. If the number of blocked attempts is identical in January and in June, it is copy-paste, not real data.
- Zero attack attempts reported. Any public WordPress site receives automated login attempts every day. Zero reported means nobody is looking.
- No concrete version numbers. "We updated the plugins" without names and version numbers is not verifiable.
- Generic or missing recommendations. A good report looks forward too, not only backwards.
How to read the report in 3 minutes, without being technical
You do not have to understand every line. Just check four things at a glance:
- Is the data from the current month? A report with old data has been recycled.
- Do the numbers differ from last month? Reality varies; copy-paste does not.
- Are concrete versions listed for the updates? Names + numbers = real work.
- Is there at least one recommendation for the future? A sign that somebody genuinely looked closely at the site.
A good report will not make you an expert overnight. What it gives you instead is the peace of mind that somebody competent really did look at your website this month — and written proof that your money did something concrete.
Transparency is our argument
With us, the monthly report is included from the Business plan upwards and contains exactly the sections above: what was updated (with versions), the backups and their verification, security, uptime, the hours worked and the recommendations for next month. Not because "it is expected", but because it is the only fair way to invoice an invisible service. We want you to see in black and white what you are paying for.
The routine behind every report — the weekly and monthly checks, the order of the updates, the tests — is described step by step in the complete WordPress maintenance guide, if you want to see what sits behind every line of the report.
See what you get, on each plan
The monthly report is only one part of what a subscription includes. To see exactly what is in each tier — including from which plan you get the report — take a look at the pricing page. And if you want us to start from a clear picture of your website, we offer a free audit within 24 hours: it is, in effect, your first report, before you are even a client.




