WordPress is the most popular website platform on the planet (with good reason!), but this also makes it one of the biggest targets for hackers. It’s not unusual for an average WordPress website to have hundreds of hacking attempts per week – so it’s essential to have a security and maintenance plan in place to keep your website safe.
We have a range of plans to suit different types of website and budgets – talk to us today about what plan best suits your website.
If you’re on Security+ or Ultimate, hack repair assistance is included. We’ll get in, clean the infection, restore from a clean backup where needed and close the hole that let them in. Most hacks we see are resolved inside three hours, so that’s what your plan covers, separate to your monthly work allowance. Some are messier: infections that have sat undetected for months, sites hit through something outside our control, or damage that needs pages rebuilt. If yours looks like it will run past three hours, we stop and tell you what we’ve found, then quote the rest before we go any further. You’ll never get a surprise invoice for work you didn’t approve.
WordPress runs about 41% of the web, which makes it a very popular target. The core software itself is generally quite solid, however the plugins that it uses are not: in 2025 there were only six vulnerabilities reported in WordPress core, compared with more than 11,000 across the wider ecosystem, and 91% of those came from plugins. Two things have changed recently. The volume is climbing fast, up 42% in a year, and the gap between a vulnerability going public and bots exploiting it has collapsed to a matter of hours. Nearly half of vulnerabilities are now public before the developer has released a fix. That’s why ExciteCare is built around proactive scanning and rapid-response patching.
Your plan includes free access to over $1,000 a year of premium plugin licences, covering the tools we use and support across our client sites. The exact list changes as plugins come and go, so get in touch and we’ll send you the current one. If you’re already paying for a licence that’s on our list, that’s a saving you can drop straight away.
That’s completely fine, and plenty of sites do. We’ll still keep an eye on it as part of our monitoring and let you know if it becomes a problem, but plugins outside our supported list aren’t covered by your plan, and we can’t take responsibility for what an unsupported plugin does to your site. If one is abandoned by its developer, becomes vulnerable, or breaks after a WordPress update, we’ll tell you as soon as we spot it and quote the development hours to either find a supported replacement or rebuild that functionality another way. If you’d rather avoid that scenario, ask us to review your plugin stack and we’ll tell you where the risks are before they bite.
Almost always on purpose. An available update isn’t the same thing as a needed update, and updating everything the moment a new version becomes available can break a site. Here’s how we split it:
Security patches get treated as urgent. If a vulnerability is disclosed in something on your site, we patch it as fast as we can rather than waiting for your scheduled update run, because exploitation now starts within hours of a flaw becoming public.
Everything else gets batched into your regular update cycle, where we can update, test and check the site properly. Some updates we deliberately hold back: a major version that would break a page builder, a plugin that other parts of your site depend on, or an update the developer has just shipped and is already patching bugs in. Waiting a fortnight on a cosmetic update is usually the safer call.
Occasionally a plugin stays behind because it can’t safely move forward at all, which is the sort of thing we’ll flag with you along with what it would take to replace it. If you ever see something sitting on an old version and want to know why, just ask and we’ll tell you.
Yes, it’s your website. Once it’s on the site we’ll include it in our monitoring, so if it turns out to be vulnerable, abandoned or conflicting with something else, we may flag it. Monitoring isn’t the same as full support though. Plugins outside our supported list aren’t covered by your plan, and if one needs replacing or rebuilding, it may be quoted as development work. Tell us before you install something and we can usually save you the trouble by pointing you at an alternative we already support.
Small jobs: content and image updates, tweaking a form field, fixing a layout issue, that sort of thing. Just email us and we’ll get it done for you. Unused time rolls over for up to three months, so a quiet couple of months can fund a slightly bigger job later. Anything beyond that, like a new feature, a redesign or a custom build, we’ll scope and quote separately.
Not a problem. ExciteCare covers your WordPress site, not your hosting, and part of the plan is us liaising with your host on your behalf. Worth knowing though: hosting-level security does less than most people assume. Recent testing found typical host and firewall setups blocked only around 12% of actively exploited WordPress attacks. Good hosting matters, but it isn’t a maintenance plan.
One thing that really helps: give us access to your hosting account. We don’t need them to look after your site day to day, but when something goes wrong we can get straight in and fix it instead of having to lodge a ticket with your hosting provider and waiting.
These plans are built for WordPress. If you’re on Webflow or our own ExciteCore platform, the risks and the maintenance are different, so we have separate plans tailored to those platforms.
We aim to respond to critical vulnerabilities as soon as we become aware of them rather than waiting for your next scheduled update. This is important as exploitation can begin within hours of a vulnerability becoming known.
A WordPress site without a maintenance plan means that important updates aren’t being applied, and this almost always leads to a site becoming compromised at some point. Backups and monitoring are other important parts of a maintenance plan that will be missed. If you do cancel, we’ll leave you with a final backup and let you know what needs attention, and what premium plugin licences we were paying for on your behalf that you would need to purchase directly from the plugin providers.
We love to talk with business owners about achieving incredible returns on the web. To find out if we’re a good fit for each other, the best next step is to have a short discovery call with one of our digital experts.
200+ 5-star reviews
5.0
5.0
© 2026 Excite Media. All rights reserved.
Web Design & Digital Marketing, Brisbane Queensland Australia | Privacy Policy