Your website works. Nobody has logged into it for two years, updated anything or broken anything, and that silence has felt like good news.
"It still works" is not evidence
The answer we hear most often is that the site works. And that is entirely true. The site works.
But "the page opens" is evidence only that the page opens. You cannot see whether the underlying system has a year of fixes waiting. You cannot see whether the author of one of the extensions stopped two years ago. You cannot see when the last backup was taken, or whether it opens at all. You cannot see whose mailbox the domain renewal notice goes to.
Seen from inside the site, all of that is as invisible as a bad roof is from inside the house. Nothing gives any warning until it does, and then it all arrives on the same morning.
What actually ages, and it is not the design
When people say a website is old, they usually mean the way it looks. The way it looks is the least urgent thing on this list. What actually ages is the part nobody ever looks at. Visible ageing is a separate story: every date on the site is a promise, and a three-year-old news item tells a visitor at once when somebody was last in here.
- The system the site runs on. Most sites are built on top of a ready-made system that gets fixes several times a year. Some of those fixes close holes that are publicly documented. If nobody takes them, nothing on your site changes at all: the hole stays open, and the knowledge of it stays public. The same goes for the software on the server underneath, except that you cannot see that from anywhere, not even from the admin side: only whoever runs the server knows.
- The extensions bolted onto it. The forms module, the gallery, the booking widget, the language switcher. Each is a piece of code somebody else wrote, living inside your site. And that somebody else changes it without asking you.
- The security certificate. It is why the browser puts a mark next to the address saying the connection is protected. It has an expiry date like a passport, and most of the time it renews itself, until one day it does not.
- The domain registration. A domain is not bought, it is rented, and the rent has a date on it. When that date passes, it is not only the site that goes, but every email travelling on that domain.
- The backups nobody has ever restored. The only thing here that almost nobody has any evidence for.
What a year of this looks like

The simplest way to explain it is to walk through the time. The order below is one we see often; the months are illustrative rather than measured, and the point is the order, not the calendar. The odds are good that you will recognise one point on the walk, and that point is where you are standing now.
The first months. Nothing happens. The site loads, the form works, enquiries arrive. There are a couple of notices about updates on the admin side, but not taking them does nothing either. This is the most convincing part of it: every month you get fresh proof that no upkeep is needed. The proof is genuine, and it holds for exactly as long as it holds.
About a year in. One extension stops moving. Whoever wrote it has moved on and no more fixes come. Nothing visible changes: the only difference is that one piece of your site no longer travels with everything else that is travelling.
Six months after that. Something half breaks, and half is the important word here. The contact form does not disappear; it still thanks the sender, but the message no longer arrives. Nobody reports it, because the only person who sees it is a visitor, and a visitor does not write to tell you your form is broken. They assume you did not reply.
One night. The certificate expires. From the next morning, every visitor sees a warning before they see your site. You do not see it, because you do not open your own site with a stranger's eyes. You find out when somebody rings to ask whether everything is all right.
Two years. The hole that had been open for a year was found. At the foot of one of your old news items there is now a link to somebody else's product, under your name, and it stays there until somebody happens to scroll that far.
None of those steps was a decision. Nobody decided to neglect the site. There simply was never a day on which a decision had to be made.
Nobody picked your site
This is where the most common belief turns up: we have nothing worth stealing, and nobody is interested in our website.
It is true, and it changes nothing. Small sites are not picked out; they are found by machine. The machine works through addresses one after another: your neighbour's, then yours, then the next one's. On each it tries the same publicly known weaknesses and moves on. No person has read your site or knows what you sell.
There is something oddly reassuring in that: it is not personal, and nobody is annoyed with you. But it is exactly why being small is not protection: protection would require somebody to be choosing and to pass you over. Nobody here is choosing. Everything gets tried, and you are part of everything.
The same logic explains why it does not matter whether your site makes you money: it is a place something can be put into, and for that it does not need to be popular.
What a site that has been broken into actually looks like

In films the front page gets a skull and a large caption. In reality that is rare, and it is also the lucky outcome: you find out within the hour. The ordinary case is quiet, because the quiet is the entire point. A break-in you notice gets stopped. A break-in you do not notice keeps earning.
- Links to somebody else's product on pages you never open. The bottom of an old news item, the foot of a service page, somewhere you do not scroll.
- Phone visitors sent somewhere else while the desktop looks fine. You check from your laptop and everything is in order. A customer taps your result on a phone and lands somewhere entirely different. That split is deliberate, and it exists precisely so the owner does not see it.
- Mail starts going out from your domain. A lot of mail, under your name, to people you do not know. Your real letters stop arriving for months after the problem has been fixed. That damage is repaired by time, not by work.
- A warning appears under your name in search results. Your company name, and beneath it a sentence saying this site may be unsafe. That sentence is there before you know anything at all.
And that is the most uncomfortable part. The visitor finds out before the owner. Your customer sees the warning, your competitor sees the warning, and you see it only when one of them bothers to call.
A ruined domain reputation is the slowest damage on this list to repair, and why your email lands in spam is a story of its own. What to do in the first hours after finding any of this is another job again, and it starts with the backup question at the end of this article.
The certificate that expires overnight
At eight in the morning your visitor no longer sees your site. They see a full-screen warning, with your site nowhere in sight behind it, and near the bottom a button labelled something like "advanced". Your content is behind that button.
A certificate these days mostly renews itself, and "mostly" is the whole of the story. Automatic renewal runs on a configuration somewhere, and that configuration can break quietly, because the server moved, the domain moved or somebody changed one line. Nothing tells you when the renewal has stopped working. The expiry tells you.
Few failures this small are this visible. A visitor does not read it as "somebody forgot a renewal" but as "this company is not safe", and they go back to the results where ten more companies like yours are waiting. They do not come back next week to check.
And then the honest addition that makes the rest bearable: this is also the fastest thing on the list to fix. Usually a matter of minutes rather than days, provided somebody knows it needs doing. Most of the difference is in the knowing rather than in the work, though when the cause was a move, the renewal has to be set up again before it starts working on its own.
A backup nobody has ever restored is a belief
A backup that has never been put back is not a backup. It is a conviction that a file exists somewhere.
Backups fail in ways that show only at the moment of restoring. The job stopped months ago and the error notice went to a mailbox nobody reads. The copy holds the files but not the database, and the database held all the text. The copy sits on the same machine as the site: if that machine is the problem, the copy is the problem too.
For a non-technical owner, testing it means one sentence. Ask the person who holds the backups to restore one of them somewhere safe and show you the result. Not explain it, show it. You do not need to understand how they do it; you need to see your own site, opening, with last week's content inside it.
Do it once, properly and on purpose. After that you know something about your own company that most companies do not know about themselves.
The domain, and the invoice nobody reads
The domain renewal notice goes to the address that was written down at the moment the domain was registered. That moment was frequently a very long time ago: a former employee's mailbox, an agency that no longer exists, or a general address nobody watches any more.
The message is sent. If the address is dead, the failure notice goes back to the registrar rather than to you; if the address is merely unwatched, nothing happens at all. Either way nobody at your company hears anything, and everything looks fine.
The outage itself is not gradual: one morning there is no site and no mail either, because all of the company's post travels on the same domain. Losing the name is slower, because after it goes dark there is a period in which the owner can still take it back. The whole sequence, and what to do on the morning, is in a story of its own, along with the question of whose name the domain is in at all. It is worth reading before the date arrives rather than after.
One piece of it is yours to hold today: the renewal date is a calendar item with no owner. Find out which address the renewal notice goes to. If you cannot answer that, that is your answer.
Twenty minutes a month, done by you

This list does not replace upkeep and it will not find the deep things. It finds the loud things, and the loud things are the ones that cost you customers. Slowness has a price of its own too, with no security problem anywhere in sight.
- Open your site on a phone, the way a stranger would. On mobile data, with the address typed by hand rather than taken from a bookmark. Look at the front page, one service page and the contacts. Whatever feels slow or broken is what your customer sees.
- Check the certificate date. Click the icon immediately left of the address: in some browsers a padlock, in Chrome a small slider icon. Follow it through to the connection details, where the expiry date is. Do this one at a computer rather than on the phone from the step before, because the route is shorter there. If there is less than a month left, say so to somebody today.
- Send yourself a message through your own contact form. A real message with real text in it, and see whether it arrives. Check the spam folder too. A form that says thank you proves nothing yet.
- Search for your company name. Look at what sits under your result, and whether anything is there that you did not put there.
- Log into the admin side of your site. You do not have to press anything, only look at whether something is waiting to be updated and how much. A large number tells you somebody has been away. A small number does not tell you the opposite: updates can be running automatically, and an extension whose author has stopped will never ask to be updated at all. If you do not have the address and the password, that is your answer, and it is the first thing you go and ask somebody for.
- Ask when the last backup was taken. A date, not a reassurance. "Yes, we have backups" is not a date.
Write a date in next month's calendar and note next to it that this takes twenty minutes. A thing in the calendar happens; a thing left to memory does not.
What paid upkeep is, and what it is not
The honest thing to say here is that this is a service we sell. Everything below is therefore useful to us, and you are welcome to read it that way.
A maintenance arrangement is an agreement that somebody is watching. In practice it means four things:
- Updates get taken, and the backup happens before them rather than after.
- Backups get made, and they have a date somebody can tell you.
- The certificate, the domain and the hosting sit in somebody's calendar rather than in somebody's memory.
- When something breaks, there is a person to ring.
And one thing that is not on that list but is worth asking any supplier for, us included: a backup that has been put back at least once.
What it is not is a promise that nothing will ever break. Nobody can promise that. An update itself can break something, because two extensions that agreed with each other yesterday may not agree today, and that is exactly why the backup comes before the update rather than after it. An offer that promises you will have no problems is selling something it does not have.
The honest limit applies to us as well: things happen on maintained sites too. The difference is not whether something happens, but how long it lasts and who notices first. On a maintained site it is noticed by somebody who knows what to do next; on an unmaintained one, by a customer.
If you want to hand this work to somebody else, this is precisely what web management is. The certificate, the server and the backups cannot be done from inside the site, so those sit with hosting.
And if you do not want to buy anything right now, do this one thing: find out today when the last backup was taken and whether anybody has ever put one back. That question is free, and the answer usually decides whether the next bad morning is unpleasant or expensive.
Frequently asked questions
Yes. The fixes that arrive close holes that are publicly documented, so a system nobody updates has known holes and the knowledge of them is public. And you cannot tell from the front page: "the page opens" is evidence only that the page opens. It does not show you whether the author of an extension stopped a couple of years ago, when the last backup was taken, or whose mailbox the domain renewal notice goes to. What ages is the part nobody looks at: the system, the extensions, the software on the server, the certificate, the domain and the backups. The design is the least urgent thing on that list.
Because nobody is choosing. Small sites are found by machine: it works through addresses one after another, your neighbour's, then yours, then the next one's, and tries the same publicly known weaknesses on each. No person has read your site and nobody knows what you sell. There is something reassuring in that, since it is not personal, but it is exactly why being small is not protection: protection would require somebody to be choosing and to pass you over. What the site earns does not matter, because it is a place from which something can be sent or into which something can be put.
Usually not from the front page. The film version, a skull and a large caption, is rare, and it is also the lucky outcome, because you find out at once. The ordinary case is quiet: links to somebody else's product at the foot of old news items and service pages, phone visitors sent somewhere else while the desktop looks fine, unfamiliar mail going out from your domain, and a warning appearing under your name in search results. The most uncomfortable part is that the visitor usually finds out before the owner does.
The visitor no longer sees your site but a full-screen warning, with a button near the bottom labelled something like "advanced". Your content is behind that button. Few failures this small are this visible: a visitor does not read it as somebody forgetting a renewal; they read it as this company not being safe, and they do not come back next week to check. The honest addition is that this is also the fastest thing to fix, usually a matter of minutes, provided somebody knows it needs doing.
Only by having one of them genuinely put back. A backup that has never been restored is not a backup, it is a conviction that a file exists somewhere. Backups fail in ways that show only at the moment of restoring: the job stopped months ago, the copy holds the files but not the database, or the copy sits on the same machine as the site. Ask the person who holds the backups to restore one somewhere safe and show you the result. Not explain it, show it: you need to see your own site opening, with recent content inside it.
Read next

There is a News item in the menu with three posts under it, the newest dated three years ago. A visitor reads the date before the headline, and the date asks a question the page never answers: is this company still there? This is not a Google penalty, it is a signal to a person. Three honest options for a dead news page, and a list of the dates that make promises on your site.