Why nonprofits need a plan at all
A nonprofit needs a maintenance plan because the person who built the site is rarely the person who looks after it a year later. Staff change, volunteers move away, and the one login that matters lives in a personal inbox. A written plan replaces that one helpful person with a process that keeps going when people leave.
WordPress itself is part of the reason. Core, the theme and every plugin release updates, and some of those updates close security holes. A site that takes donations or collects volunteer details holds personal information, so an unpatched site is a risk to the people who trust you, not only to your search rankings. Our WordPress security guide explains the most common ways sites are broken into, and nearly all of them come down to software nobody updated.
There is also a plain fundraising reason. If the donate page is down during a campaign week, you do not get those gifts back later.
What the plan should include
A complete plan covers six areas: hosting, updates, backups, security, monitoring and a way to request changes. If a quote is missing one of these, ask who is responsible for it, because the answer is usually "you".
| Area | What good looks like | What to ask |
|---|---|---|
| Hosting and SSL | Managed hosting sized for your traffic, with the SSL certificate renewed automatically | Whose name is the hosting account in? Where is the data stored? |
| Updates | WordPress core, theme and plugin updates, tested on a copy of the site before they go live | How often? What happens if an update breaks the donation form? |
| Backups | Daily backups kept off the web server, with a restore that has been tested | How long are backups kept? When did you last restore one? |
| Security | Monitoring, malware scanning and clean-up if something goes wrong | Is clean-up included, or billed separately? |
| Uptime monitoring | Automatic checks on the home page and the donation page | Who gets the alert, and what do they do at the weekend? |
| Support | A named person to email and a set amount of small edits | What counts as a small edit? How fast is a reply? |
Two extras matter more for charities than for most businesses. The first is a regular test of the donation flow: a real gift, a real receipt, and a check that the confirmation email arrives. The second is a form check, because a volunteer sign-up form that silently stops sending email can sit broken for months. If you want the technical detail behind the backup rows, read how to back up a WordPress website.
What should be in writing
Everything you would argue about later should be written down before you sign: the price, what is included, how fast someone responds, who owns what, and how either side can end the agreement. A friendly verbal promise is worth very little after the board changes.
- The fee and what it covers. One figure for hosting and one for maintenance and support, or one combined figure with both listed.
- The included work. The amount of small edits in the plan, and the rate or process for anything larger.
- Response times. One for ordinary requests and one for "the site is down".
- Ownership. Your organisation owns the domain, the content and the donor data. The plan should say so.
- Exit terms. The notice period, and a commitment to hand over the site files and a current backup when you leave.
- Third-party costs. Domain renewal, premium plugin licences and payment processing fees are normally yours. They should be listed so nothing arrives as a surprise.
This is how our own free website offer for nonprofits works. We design and build the WordPress site at no charge, and the organisation pays for hosting and a maintenance and support plan. That plan is quoted in writing before any work starts, the quote is free, and the terms, including how either side can end it, are set out in the written agreement. If you move on, we hand over the site files and a current backup.
What drives the price of a plan
The price of a plan depends on the size of the site, how much traffic it gets, how many plugins and integrations it runs, and how much hands-on support you want. We do not publish one number because a five-page community group site and a large charity with events, a shop and a donor database are not the same job.
- Hosting needs. A site with a busy campaign season or large media files needs more server resources than a small brochure site.
- Number of moving parts. Each plugin, payment connection, CRM link or email tool is one more thing to update and test.
- How updates are tested. Testing on a staging copy first takes longer than pressing "update all", and it is the part that protects your donation form. See how a WordPress staging site works.
- Support time. A plan with a block of content edits each month costs more than one that only covers updates and backups.
- Response commitments. Faster guaranteed replies cost more to provide.
When you compare two quotes, line them up against the table above. The cheaper plan is often cheaper because it leaves out tested restores, security clean-up or any human support.
Questions for the board to ask
A board does not need to understand WordPress to approve a plan. It needs clear answers to a short list of questions, and any provider should be able to answer them in plain language.
- If our site is hacked, who fixes it, and is that inside the fee?
- If the donation page stops working on a Saturday, who finds out and when?
- Are all accounts (domain, hosting, donation platform, analytics) registered to the organisation and not to a person?
- Can we see what was done each month?
- What happens to the site if we cancel?
- Who is our named contact, and who covers when they are away?
Record the answers in the board minutes. It takes ten minutes and saves the next treasurer a long search.
What staff and volunteers can do themselves
Staff and volunteers should handle content, and leave software and servers to the plan. Writing news posts, updating program pages, adding events and swapping photos are safe jobs for an editor account. Updating plugins, changing themes and editing code are not.
A simple split works well:
- In house: news, events, program details, staff and board lists, annual reports, photos with alt text.
- With your provider: updates, backups, security, new forms, anything that touches donations, and layout changes.
Give each person their own login with the lowest role that lets them do their job, and remove accounts when people leave. Shared admin passwords are a common way nonprofit sites get into trouble.
Next step
If your organisation needs a new site as well as someone to look after it, read the details of our free WordPress website for nonprofits and charities and use the form on that page. If you already have a WordPress site you are happy with, our WordPress maintenance and support service covers the same areas as the table above. You can also see how we work with charities on our nonprofit WordPress page.