CMS, module, plugin, and dependency updates
We track core releases, add-ons, themes, PHP/runtime compatibility, package dependencies, and security advisories. Updates are backed up, applied in a test environment, checked, then deployed.
Atomic Design keeps existing websites secure, backed up, monitored, and moving. Requests go through a ticket system, changes are tested on a staging copy first, and live updates are published only after review or direct client approval.
Maintenance is not one task. It is a repeatable operating system for security, uptime, recoverability, compatibility, and support.
We track core releases, add-ons, themes, PHP/runtime compatibility, package dependencies, and security advisories. Updates are backed up, applied in a test environment, checked, then deployed.
We monitor whether the site is reachable, whether SSL is valid, whether forms still submit, and whether critical errors appear after updates or hosting changes.
We confirm database and file backups, keep restoration steps documented, and preserve a recovery path before changing code, modules, templates, or configuration.
Covered maintenance can include text edits, image swaps, staff updates, landing-page edits, phone-number changes, form field adjustments, and small page additions.
Bug fixes, display issues, form logic, redirects, tracking-code repairs, accessibility corrections, and minor feature requests can be handled through tickets when scope is clear.
Reports summarize work completed, updates applied, risks found, uptime events, open requests, recommendations, and any work that should be scoped separately.
Stable maintenance depends on the same principles across platforms: back up first, test away from production, document changes, verify forms and core pages, then publish only after approval.
| Area | What we handle | How it is controlled |
|---|---|---|
| Security updates | CMS core, plugins, modules, themes, libraries, frameworks, and urgent security advisories. | Back up first, update staging, run required database or cache steps, test public and admin paths, then publish. |
| Add-on compatibility | Conflicts, deprecated plugins or modules, PHP compatibility, package constraints, and update blockers. | Document blocker, recommend patch/update/replace path, and quote larger remediation before work expands. |
| Site configuration | Menus, blocks, views, content types, fields, permissions, redirects, forms, and tracking scripts. | Move configuration through the test server when possible; capture screenshots or notes for approval. |
| Hosting coordination | PHP version, database health, disk space, cron, cache, CDN, SSL, and server warnings. | We can coordinate with hosting support when access is provided; hosting invoices, domains, and billing remain client-owned unless separately assigned. |
| Legacy risk | Old CMS versions, unsupported plugins or modules, unmanaged patches, or admin workflows that create security risk. | We separate normal maintenance from upgrade projects and give a written path before touching fragile production systems. |
Clear boundaries keep support fair, fast, and predictable. Small defined changes move through tickets. Larger work gets scoped before it burns hours.
When you have an SEO engagement with Atomic Design, we do not charge website maintenance time for routine SEO review. We separate marketing analysis from website labor so the maintenance plan is not consumed by reports, rankings, or strategy conversations.
A response is the first qualified review, not a guaranteed resolution. Turnaround depends on access, approvals, third-party systems, and the size of the change.
| Priority | Examples | Target response | Typical turnaround |
|---|---|---|---|
| Emergency | Site down, checkout/form unusable, security compromise, public error blocking core business. | 0-4 hours when emergency coverage is active. | Triage immediately; restoration or containment first, full fix after cause is known. |
| High | Admin inaccessible, key page broken, lead form degraded, update conflict, visible functionality failure. | Same business day when submitted with complete details. | 1-2 business days for common fixes; more if third-party access or development is required. |
| Standard | Content edits, new supplied copy, image swaps, non-critical bugs, minor layout changes. | 1 business day. | 2-5 business days depending on queue, review cycles, and request size. |
| Planned | New sections, added functionality, larger page builds, integrations, templates, or migrations. | 2 business days. | Scoped separately with schedule, estimate, staging link, and approval step. |
Email threads are useful, but an official ticket system gives every request an owner, status, priority, approval trail, staging link, and deployment record.
Clients submit tickets, attach screenshots, select priority, enter affected URLs, see open work, approve staging links, and request revisions from one place.
Codex-style AI can read new tickets, classify impact, request missing details, inspect the staging codebase, propose fixes, draft work notes, and prepare safe changes for developer review.
AI can accelerate diagnosis and implementation, but production updates stay gated by credentials, backups, staging proof, approval, and an Atomic developer or client-directed live action.
The live site is protected by process. Requests are reproduced, fixed, reviewed, and approved before production changes are made.
Client provides URL, request, priority, screenshots, error text, deadline, and any content or files.
Atomic confirms scope, priority, needed access, estimate, and whether the work is maintenance, SEO, or a separate project.
We clone or use a test server, take a backup, make the change, and test the affected pages, forms, and admin paths.
Client receives a staging link or proof notes, then approves, rejects, or submits revisions inside the ticket.
Approved changes move live with notes, backup reference, deployment record, and a final verification check.
Complete intake prevents back-and-forth and helps us reproduce the problem before touching code.
Maintenance coverage depends on access, current condition, hosting limits, licensing, and whether the software is still supported. We identify risk during onboarding before routine work begins.
We reviewed current agency maintenance plans, support providers, and update guidance before defining this structure.
Send us the site, the risks, and the request list. We will map the maintenance plan, support workflow, staging process, and approval path.