Skip to content

Business

WordPress Maintenance RFP Checklist: 25 Questions to Ask

Use this WordPress maintenance RFP checklist to compare providers on scope, updates, recovery, security, SLAs, reporting and commercial terms.

Quick answer: a useful WordPress maintenance RFP should test how a provider works, not how many generic features appear on a pricing card. Ask for evidence of the update, backup, recovery, access, escalation and reporting processes that will protect the websites placed in their care.

This checklist is designed for businesses, SaaS teams and agencies comparing ongoing WordPress support. Use it as a formal request for proposal or as a structured agenda for a vendor call.

Define the requirement before contacting providers

Start with an inventory. For each website, record its business purpose, owner, hosting, WordPress and PHP versions, critical plugins, integrations, transaction volume, support history and recovery access. A provider cannot price or design an appropriate service level from a site count alone.

Separate the work into three categories:

  • Maintenance: recurring updates, backups, monitoring and routine checks.
  • Support: investigation, small fixes, content changes and vendor coordination.
  • Projects: migrations, redesigns, custom features and major integrations.

The official WordPress site maintenance guidance treats maintenance as recurring work and recommends a schedule for updates, backups and site checks.

Questions about portfolio fit and onboarding

  1. What types of WordPress sites do you support?
    Ask about WooCommerce, memberships, LMS platforms, multilingual setups, custom themes and legacy builders relevant to your portfolio.
  2. What information do you require before accepting a site?
    A serious onboarding process should request ownership, hosting, access, plugins, integrations and known risks.
  3. How do you identify inherited technical debt?
    Look for an audit that records unsupported software, duplicate tooling, missing licenses and fragile customizations.
  4. How do you handle sites with different risk levels?
    The answer should allow different update, testing and escalation requirements rather than one identical routine.
  5. What happens during the first 30 days?
    Request concrete outputs: inventory, access review, backup verification, baseline checks and prioritized risks.

Use the WordPress portfolio maintenance audit to prepare the information a provider will need.

Questions about updates and quality assurance

  1. How do you decide whether an update can be automated?
    The provider should consider complexity, release risk, available rollback and the importance of affected workflows.
  2. When do you use staging?
    Ask which changes require a non-production test and how production data is protected.
  3. What is tested after an update?
    Expect a defined smoke test for login, forms, checkout, accounts, search or other critical journeys.
  4. How are update failures recorded and escalated?
    The process should identify an owner, the failed component, user impact and next action.
  5. Can we see an example update report?
    Evidence is more useful than a promise that updates are fully managed.

WordPress recommends creating a backup before updating because the process changes application files. Compare the official WordPress update guidance with the provider’s approach and our guide to safe updates across client sites.

Questions about backups and recovery

  1. What exactly is backed up?
    Confirm that both the database and required files are included.
  2. Where are backups stored?
    Look for storage independent from the production server and clear access ownership.
  3. How are schedules and retention chosen?
    A store receiving orders may need a different recovery point than a rarely edited brochure site.
  4. How do you verify that backups can be restored?
    Uploading an archive is not the same as completing a restore test.
  5. Who may authorize a rollback?
    For transactional sites, restoration can discard recent orders, accounts or form submissions.

The proposal should distinguish the recovery point from the recovery process. If the provider cannot explain how it would restore the site, backup frequency alone is not enough.

Questions about security and access

  1. How are credentials stored and shared?
    Ask whether staff use named accounts and how access is protected.
  2. How often is access reviewed?
    Former employees, old agencies and unused integrations should not retain access indefinitely.
  3. Which security events do you monitor?
    Clarify the difference between uptime, vulnerability information, malware detection and log review.
  4. What is your incident communication process?
    The provider should define notification, containment, evidence preservation and recovery responsibilities.
  5. How is access removed at offboarding?
    Request a checklist covering WordPress, hosting, DNS, repositories, monitoring and third-party services.

WordPress describes security as risk reduction supported by limited access, monitoring, backups and recovery planning. Its hardening guidance also explains that hosting and application responsibilities are different.

Questions about support, SLA and commercial terms

  1. Which channels are approved for requests?
    A clear system of record prevents work from disappearing across personal email and chat.
  2. How do you classify severity?
    Business impact should determine priority: a failed checkout is not equivalent to a cosmetic spacing issue.
  3. What do response targets mean?
    Confirm whether the promise covers acknowledgement, investigation, workaround or resolution.
  4. What work is excluded or quoted separately?
    Ask for examples of a small task, a maintenance task and a project.
  5. How can we expand or exit the agreement?
    Understand notice periods, site additions, data export, credential return and open-ticket handoff.

Use the website support SLA guide to turn these answers into measurable service language. For budget preparation, compare the models in the WordPress maintenance cost guide.

Before scoring providers, use the WordPress WebOps vs maintenance guide to decide whether the requirement is recurring care or a broader operating model for releases, incidents and cross-team requests.

A simple provider scoring matrix

Area Weight Evidence
Update and testing workflow 20% Checklist and sample report
Backup and recovery 20% Restore procedure and ownership
Security and access 15% Access and incident process
Support and escalation 20% SLA with severity examples
Portfolio fit 15% Relevant operating examples
Commercial clarity 10% Scope, exclusions and exit terms

Score each area from one to five and multiply it by the weight. Keep price visible, but do not let a small monthly difference outweigh an absent restore process or unclear escalation ownership.

Evidence to request from shortlisted providers

  • a redacted onboarding checklist;
  • a sample maintenance report;
  • an update and post-deployment test checklist;
  • a backup and restoration procedure;
  • severity definitions and response targets;
  • a list of standard exclusions;
  • an access-removal or offboarding checklist.

You can also ask the provider to review a Site Health export. WordPress explains that the Site Health screen reports configuration details, critical issues and recommended improvements, although it does not replace a full operational audit.

Warning signs in a proposal

  • Unlimited work is offered without a task or concurrency definition.
  • Backups are promised but restoration responsibility is unclear.
  • The proposal lists update frequency but no testing workflow.
  • Every incident has the same priority.
  • Several technicians share one administrator account.
  • The provider cannot explain larger-work estimates.
  • Reporting shows activity but not failures, risks or next actions.
  • There is no practical offboarding process.

Run a controlled pilot

Before moving a full portfolio, select a representative group of sites. Include one simple site and one with an important integration or recurring support workload. Agree on the pilot scope, success criteria and access-removal date.

Measure request classification, communication quality, testing evidence, completed work, rework and the internal time required from your team. A successful pilot should prove the operating model, not merely complete a list of easy tasks.

Frequently asked questions

Do small businesses need a formal RFP?

Not always. The same 25 questions can be used as a structured comparison checklist during provider calls.

How many providers should we compare?

Three credible providers are often enough to reveal differences in scope, ownership and pricing.

Should the cheapest provider be eliminated?

No. A lower price may suit a simple site. The concern is a low price combined with missing testing, recovery or support definitions.

Should hosting be included?

Include hosting responsibilities even when hosting is purchased separately. The proposal should say who handles server incidents, DNS, SSL, PHP changes and host coordination.

Can an agency use this checklist for white-label support?

Yes. Add questions about branding, client communication, approval authority and subcontractor access. See the white-label WordPress support guide.

Choose evidence over feature counts

A maintenance provider becomes part of the operating system behind the website. Choose recoverable processes, clear ownership and evidence that the team can protect the customer journey, not the longest list of generic features.

Review CodaStudio WordPress maintenance services, the agency maintenance model or current plans and pricing.

Done reading?

Let us handle the website.

Updates, fixes and ongoing care from real WordPress experts.

Choose your plan →