Choosing the Right WordPress Support Company: 7 Questions to Ask

Blog -
Choosing the Right WordPress Support Company 7 Questions to Ask

Quick Summary: When selecting a WordPress Support provider, there are seven key inquiries you should be asking about; Are your Emergency Response Times less than four hours (typically have service level agreements or “SLA” in place of 1 – 4 hours)? Do you Test Updates prior to Deploying them Live? Beyond simply using plugins what Security Measures do you implement? How do you Handle Backups (are they done Daily, Off-Site and can you restore them with testing)? What type of Reporting will I receive? Will I be assigned a Dedicated Team? If one of your updates causes an issue how will it be addressed? Any vague responses to these inquiries are indicators of which companies are Budget Operators vs. Professional Providers.

Deciding on which WordPress support provider to hire is a decision based on trust. You are going to give a group of individuals (that you may have never met) control of your most valuable online resource – your website. Making the wrong hiring choice could mean delayed responses from your provider if your website goes down, careless updates will be made to your site by your provider, and issues with your site could remain unknown to you and your customers until an emergency situation occurs.

On the other hand making the correct hiring choice for a WordPress support provider will allow you to rest assured knowing that your website remains fast, secure and operational so that you can continue to run your business.

The problem however is that all WordPress support providers describe their services using very similar language: “backups,” “security”, “monitoring,” “support” and “updates”. It is how each provider delivers these service offerings that distinguish them from one another. This list of seven questions will help expose those distinctions.

Why All WP Support Companies Are Not Created Equal

The barrier for entry into the WordPress support marketplace is very low. All you need is a ManageWP account and some basic knowledge about how WordPress works. As such there are now many “providers” of maintenance services offering their help. Unfortunately most of them are either extremely good or completely incompetent.

As such the implications of hiring someone who may be bad at what they do are quite real. For example a company which automatically updates your production website without first testing those changes could kill off your checkout process on a Friday afternoon. Likewise a company with an undefined Emergency Response Plan could take up to 48 hours to contact you once your hacked site starts serving malware to visitors. In addition a company which doesn’t check for performance problems could never know if an update to one of your plugins causes it to take three seconds longer to load.

These seven questions will differentiate the professionals from everyone else.

Question 1 — What Is Your Response Time for Emergencies?

The primary concern of any organization’s IT infrastructure is response time. How long does a website take to be restored in case it has crashed, been compromised by hackers, etc.?

Look for this: There should be a Service Level Agreement (SLA). This agreement should have time frames that are specified for the length of time that your service provider should reactivate your website after being taken offline. In cases of extreme urgency, such as hacking, it would be ideal for them to provide response times of less than four hours during their normal business hours. It would also be nice if they were able to offer 24-hour-a-day emergency response services; however, these types of services usually require that you pay extra money for them.

Red flags: “We will try our best to restore access to your site.” “Typically we can resolve your issue within one day.” “No formal Service Level Agreement exists.” All three of these represent a lack of accountability on behalf of the service provider. In other words, they have no real incentive to get your website back online.

Follow-up question: What constitutes an emergency situation? How do you define an emergency versus just another request? An organization that has clearly established different levels of priority (escalation) shows a level of sophistication in its operations.

Question 2 — Do You Test Updates on Staging Before Applying to Live?

The information in this question alone will eliminate a high number of potential providers. The process of testing on a staging area is industry standard when it comes to professional WordPress web development and maintenance.

What to look for: A “yes” answer with an explanation of their staging process – How do you make the staging copy? What do you test? How do you get approved updates from staging to production?

Red flags: “We apply all updates (to our production site) and watch for problems.” This indicates that you are using your customers’ site as your testing ground for WordPress updates. While acceptable for a home based or personal site; unacceptable for a commercial/business site.

Why it matters: WordPress updates can destroy websites. It doesn’t happen often, but often enough to require testing. Example: An update to a Woocommerce extension may alter checkout behavior. Or an update to your theme could cause your header layout to be destroyed. Or a conflict between extensions could disable your contact form. These examples occur too frequently to ignore testing. Testing should occur prior to allowing updates to affect visitors.

Question 3 — What Security Measures Do You Implement?

Security should not be something that can be installed as a module. Security is a fundamental part of all ongoing maintenance.

What to look for: In front of a breach – Web Application Firewall (WAF), Malware Scanning, File Integrity Monitoring, Brute Force Protection, Security Headers, Ongoing Security Audits. Ask them about the procedures they follow once Malware is identified. Ask if there is a Hardening Checklist for each new Client Site.

Red flags: “WordFence” installs in our Wp-Admin. A security plug-in is merely a tool, it is not a method. True professional security includes: Configuration of the system; Constantly watching the logs; Procedures for responding quickly after a breach; Regular auditing – Not simply installing a plugin and letting it sit idle.

Follow-up question: Has one of your Client Sites ever experienced a hacking event while under your supervision? What occurred during this event? How did you respond to this issue? Most honest Service Providers understand that even with the most diligent effort, breaches do occur, but will describe the Incident Response Process they use. Providers who say it has never occurred may have little experience in providing service or are misrepresenting the truth.

Question 4 — How Do You Handle Backups?

Backups are the protective layer that all other maintenance activities have. The importance of backups will only be demonstrated by when it’s needed to restore them.

What to look for: Automated daily backups that are saved to an offsite location (not on the same server where your website is hosted) at least 30 days worth of backups. Test restores of backups in regular intervals to ensure the reliability of your backups. Time commitment for restoring a site from a backup.

Red flags: Reliant solely upon your web host for backing up your files (in many cases these will not be enough to restore in a timely manner). Offsite storage does not exist. There has never been a test restore. “We back up our sites weekly.” Weekly back-ups are too infrequent. One week of missed sales/orders, blog entries, etc., are substantial.

Follow-up question: In what amount of time could you restore from a backup, and for how long would the backups retain history of your site? A service provider capable of restoring your site in under an hour using a backup created no more than 24 hours prior, is a much greater benefit to you than another provider requiring a full day to restore your site with a week old backup.

Question 5 — What Reporting Do You Provide?

Reports show you if the service provider is really working on the project or if they are simply saying they are.

What to look for: There will be monthly reports from the service provider which will detail: What has been updated; What issues have been identified and fixed; Uptime of website; Performance of website (i.e., Page Speed, Core Web Vitals); Results from a Security Scan. The reports should be written so that anyone who does not know anything about technology can easily read and understand them.

Red flags: Regularly requesting reports. Reports which do not provide specific details regarding the work done (“All Updates Applied”, “Site Is Running Fine”). Repeated requests to receive reports.

Why it matters: Clear reporting creates an environment where the service provider is held accountable. Also, by providing a history of each month’s work, these reports help identify problems. For example, when the website begins slowing down in October and you compare this month’s report with last months’ performance report, you now quickly see what caused the slow-down.

Question 6 — Do You Have a Dedicated Team or Rotate Staff?

It’s important to have consistency as far as who will be working on your site — this impacts the quality and speed at which tasks can be completed.

What to look for: A structured team where most or all of the same individuals handle the management of your site and build their knowledge base based on your site-specific configurations, plugin usage, and history. Don’t need a one-person show (which causes a bus-factor risk) just a few that are familiar with your site.

Red flags: “Whomever is around to help when an issue arises takes the ticket.” When using this support model, each time you reach out there is no background information available regarding changes made last month that could impact the solution to the current issue you’re experiencing.

Why it matters: WordPress sites are different. Each site is created with a mix of themes, plugins, custom code, hosting environments, etc. For these reasons alone, having a group of people that know your site well saves time in managing/fixing issues with your site.

Question 7 — What Happens If Something Breaks After an Update?

The ability to quickly roll back changes made by your update process (and have a formalized process in place) is critical to holding providers accountable.

What to look for: The fact that they can revert to the previous version of your system immediately after making an update, as well as a clear definition of how this will occur. Additionally, whether they acknowledge liability for any issues that may arise from their update process. Finally, if there are any additional costs or fees associated with correcting issues caused by their updates.

Red flags: “We apply our updates using industry standard best practices; however, we do not warrant that these updates will not cause a disruption.” This language completely disclaims all liability related to their update process. Providers who test new code in development environments prior to production environments and take full responsibility for what occurs during the update process will not charge for resolving issues caused by their processes.

Follow-up question: I’d like to know when was the last time an update caused a problem with one of your clients. How were those issues resolved?

How Deutrix Care Answers Each Question

Deutrix Care believes in “practicing what you preach,” therefore we have included below, how we respond to each of your concerns:

Response time: The Response Time for all clients is as follows — Emergency Priority Queue is also offered under the Premium Plan, all clients will receive Next Business Day (NBD) response under the standard plan, same Day Response (SDR) is available under both the Plus Plan and the Premium Plan.

Staging: Before making any changes or updates to your website, every update goes through our Staging Environment. First, we visually and functionally test those changes; secondly, they are released into Production only once verified. There are no exceptions.

Security: To provide protection for our clients’ data, we adhere to a comprehensive Hardening Checklist during Onboarding, use Continuous Malware Scanning & File Integrity Monitoring, and keep Web Application Firewall (WAF) Configurations up-to-date. Our security hardening service details the full scope.

Backups: Automated Backups occur daily, are Off-Site Stored with 30-Day Retention. Quarterly Test Restores occur and a site can be restored within one (1) hour of receiving a Restoration Request.

Reporting: Monthly Reports detailing which Updates were Applied to your Site, Security Scan Results, Uptime Percentage, Performance Metrics, and any Issues Detected and Resolved.

Team consistency: Clients are allocated to a small Team familiar with their site’s configuration/history.

Update accountability: If our update process causes an issue, we fix it immediately at no additional charge. Our staging workflow minimizes this risk, but when it occurs, it is our responsibility.


Ready to work with a team that meets these standards? View Deutrix Care maintenance plans →

This article is part of our WordPress Speed Optimization Guide — the complete resource for maintaining a fast, secure WordPress site.

Frequently Asked Questions

Most professional options will cost anywhere from $50-$500 a month based on pricing tiers and services provided. Keep an eye out for companies charging lower than $20 a month. As stated earlier, there is no way a company can provide the level of service described here for this low of monthly charges. On the other end of the spectrum, it is possible for the highest priced option to be not as great as some of the less costly options. Look at what you get for each price point in comparison to the seven questions above.

Yes. A firm specializing in WordPress understands the unique security risks (i.e., known vulnerabilities), update behavior, and performance characteristics inherent in the WordPress environment. Additionally, such firms have experience with the WordPress community, which creates a better understanding of how to address issues related to the WordPress platform. Thusly, firms specializing in WordPress are able to solve WordPress problems both quicker and more efficiently due to their daily exposure to the same types of problems.

Changing providers is simple. The transition typically involves a professional onboarding process that includes a comprehensive review of your site; configuration of monitoring and backup processes; and documentation of your sites’ specifics. The majority of transitions occur within one to three business days without causing any downtime.

Request a free quote

Get a free quote from our specialists on your next project.

Get a Free Quote Get a Free Quote