The challenge
Twelve location sites had been built at different times by different people, and no single person owned upkeep for any of them. That's a process problem before it's a technical one: everyone assumed someone else was applying updates, so nobody was. The estate had drifted to 31 distinct plugins doing broadly the same jobs, several sites were multiple major versions behind on core, and a couple were running PHP versions no longer receiving security patches. Nobody could answer basic questions — which sites had backups, where DNS was managed, who held the hosting logins — which meant that in an incident, the first several hours would have gone on finding out.
Inventory at the start: 12 sites across 4 hosting providers, 31 distinct plugins, 3 sites more than two major WordPress versions behind, 2 running end-of-life PHP, 5 with no verified backup, and no monitoring on any of them. Hosting credentials were held across three former suppliers.
The approach
Twelve sites drifting out of date isn't twelve small problems — it's one process problem wearing twelve hats. Nobody owned updates, so everybody assumed someone else had done them. Fixing the process had to come before fixing any individual site.
The results
All twelve sites have stayed current on core, plugins and PHP, with updates verified on staging before reaching production. The consolidation matters more than the update cadence: standardising to 14 plugins means a vulnerability disclosure now requires checking one shared stack rather than auditing twelve different ones, which turns a day of work into an hour. The monthly restore test has caught two backups that would have failed when needed — which is the entire point of testing them.
What this didn't cover
Care and maintenance only — no new features, no redesigns, no content updates and no SEO work; those get quoted separately as they come up. Clinical systems and patient records were never in scope and sit entirely outside the websites, on separate systems I have no access to. The plan covers WordPress, plugins and hosting; it does not cover the group's email, phone systems or third-party booking software, all of which are managed by other suppliers. A care plan also reduces risk rather than eliminating it — no monitoring catches a zero-day on the day it drops, and I'd distrust anyone claiming otherwise.
Services used on this project
Want the same for your site? Start here:
