A simple maintenance plan, apparently
A business approaches the studio: their previous developer has stopped responding, and they need someone to look after their WordPress site. The site looks tidy. The owner agrees a standard maintenance plan at the usual price.
In the first week the developer finds the site running an old PHP version the host is about to retire, a theme with edited core files that cannot be updated, several plugins that were abandoned by their authors years ago, and a premium plugin with an expired licence that was quietly nulled. There are no backups. The first month of maintenance turns into a rescue project, at the price of a routine plan.
Why inherited sites are underpriced
- The front end looks fine, and that is what the prospect and the studio see first.
- Access to the server and admin is often only available after the client signs.
- Checking a site properly takes a developer time, which feels expensive before a sale.
- The client does not know what their previous developer did, so they cannot warn you.
- Studios use a standard plan price for every site regardless of condition.
The studio is pricing a used car by looking at the paintwork. The engine is where the cost is.
What skipping the audit costs
Rescue work is done inside a maintenance fee that was never meant to cover it. Problems found after signing create awkward conversations, as the client feels the price has changed after the deal. Some sites carry risk the studio would not have accepted if it had known, such as nulled plugins or an unsupported server. Developer time goes on sites that do not make money.
The intake audit we build
- A public scan runs first, needing only the URL: platform and version where visible, PHP version where exposed, SSL, plugins and themes detectable from the front end, page speed, obvious errors and mixed content.
- With limited access that the client can grant before signing, such as a read-only admin user, the audit reads the full plugin and theme list, versions and update status.
- Plugins and themes are checked against public vulnerability databases and marked as current, outdated, abandoned or known vulnerable.
- Core and theme files are compared with the official versions to spot direct edits.
- Backup status, hosting environment and PHP version are recorded.
- The results produce a risk summary with a simple rating per area and a list of the work needed before routine maintenance can start.
- The summary feeds your proposal: a standard plan for healthy sites, or an onboarding fix-up quoted separately for the rest.
| Area checked | What raises the risk |
|---|---|
| Plugins and themes | Abandoned, outdated or with known vulnerabilities |
| Core files | Direct edits that block updates |
| Server | Old PHP version or unsupported host |
| Licences | Premium plugins without valid licences |
| Backups | None, or never tested |
| Page builders | Uncommon builders that tie the site to one tool |
The audit reports what it finds. Whether you take a site on, and at what price, is still your decision.
Pricing the next inherited site
A new enquiry comes in for a site whose developer has gone. The studio runs the public scan and asks the client for a temporary read-only admin user. The audit shows several abandoned plugins, a theme with edited files and no backups. The proposal includes a one-off onboarding fix, clearly explained with the audit attached, followed by the standard plan. The client understands why, because the evidence is in front of them.
Do inherited sites surprise you?
- You take over sites built by other developers.
- Maintenance plans are priced before anyone looks inside the site.
- The first month on an inherited site is often a rescue.
- You have found nulled or unlicensed plugins after taking a site on.
- Every site gets the same plan price regardless of condition.