Updates tested on a copy first.
Core, plugins and templates updated on a staging copy, checked, then pushed to the live site on a date fixed in advance
a current site, and an update that is a scheduled event rather than an incident
Website maintenance · UAE
The person who built it has usually moved on, and the logins went with them. Webzenia takes custody first, then runs the standing work on a schedule.
Get a site health checkWhat the engagement covers
Website maintenance is the standing work that keeps a live site current, recoverable and answered for. Three things change hands at the start: the keys, the schedule and the clock.
Hosting, the domain, the registrar and the CMS, checked against whose name each one is actually in. Custody is settled before any work is scheduled, because a site you cannot log into is not a site anyone can maintain.
Core, plugins and templates updated on a staging copy, then pushed. The date is fixed in advance, so an update is a planned event rather than something a broken page triggers.
A written response window, and the week it is measured against. The working week here is Monday to Friday, so a promise counted in hours has to say which hours it means.
Who owns the site today
Almost every site here sits in one of three arrangements. Two of them look like maintenance on the invoice, and only one is a schedule somebody holds.
| The builder who leftNobody, since handover | A contract on renewalAnswers when you write in | A named ownerA schedule, and a stated window | |
|---|---|---|---|
| Who holds the logins | A personal account belonging to someone who has left the country. | The supplier, usually, with the domain sitting under their registrar. | You do. The first week puts every account back under your entity. |
| What is scheduled | Nothing. The site runs on whatever it was left on. | Whatever the contract lists, whenever someone gets to it. | Updates on a staging copy, on a fixed date, every month. |
| When you find out | When a customer tells you the enquiry form stopped sending. | When you write in, which is the whole design of it. | From monitoring outside the server, usually before anyone else. |
| When it breaks | A search for whoever built it, then a quote to look at it. | A ticket, and no written time it has to be answered in. | A written window, counted against a Monday to Friday week. |
| What arrives monthly | Nothing, until a hosting invoice or a renewal notice. | A renewal reminder, and rarely a record of what was done. | A written report: what was updated, what was watched, what changed. |
Most companies here are on the first, and it is rarely anyone’s fault: the site was built during company setup and the people who set it up moved on. The first thing worth doing is finding out what you actually hold, which is an hour of work and occasionally makes the rest unnecessary. If the site has stopped fitting the company rather than breaking, that is a rebuild question instead. The people who would hold it here are named, with the entity behind them.
From the field · UAE upkeep
Webzenia has worked with Gulf clients since 2018. The same four things separate a site somebody holds from one that is merely still running.
Companies here arrived rather than started: a JLT commodities trader under DMCC had its site built during setup by whoever was available at the time. Nothing was hidden and nobody was careless. Access simply stopped being anyone’s job, and the first sign of it is a change nobody can make.
Read the competing offers and the shape repeats: inclusion lists long enough to cover anything, availability promised as constant, and most stating no response time. A Business Bay brokerage on a DET mainland licence ends up with a support desk that has a renewal date on it.
Constant availability is easy to publish and impossible to check. Two working days means something a client can hold, because both sides know which days count. Where cover extends past the working week, that belongs in the scope rather than on a badge.
Names directly under .ae are open to any registrant worldwide, while a .co.ae asks for a trade licence behind it. So a licence-linked address can sit under a personal email nobody at an Al Quoz F&B producer on a DET mainland licence can open, and nobody finds out until a renewal fails.
The scope
Six pieces of standing work. The fifth is the one every competing page promises and almost none of them writes down.
Core, plugins and templates updated on a staging copy, checked, then pushed to the live site on a date fixed in advance
a current site, and an update that is a scheduled event rather than an incident
Patches applied, scans run, threats found and the certificate checked, reported as four values you can read in a second
the standing security work, counted. Hardening and incident response are separate scope, quoted separately
Daily copies held off-site, away from the host, with a restore actually performed rather than assumed
a recovery you have watched work, which is the only version of a backup worth having
Uptime and page speed checked from outside the server, so a problem is found by monitoring rather than by a customer
a trend across months, not a reading taken the day somebody complained
Content edits, small fixes and new sections handled inside the plan, on a turnaround written in working days rather than promised as availability
a queue with a clock on it, and a record of what shipped
What was updated, what monitoring saw, what changed and what is still queued, on a page a director can read without asking a developer to explain it
upkeep you can see, and a renewal you can judge
Our stack
Five tools, chosen for a site somebody else made. Select one to see why it earns its place, and what we do with it that most do not.
UptimeRobot checks a site from outside the server, which is the only vantage point that sees what a visitor sees when the host itself is the thing that has failed.
We monitor the pages that carry the enquiry, not only the homepage, because a site can answer perfectly on every check and still have a dead form on the one page that earns.
How the engagement runs
The first week is an audit: what you own, and what state it is in. Neither can be assumed on a site somebody else built.
We list every account the site depends on: the hosting, the domain, the registrar, the CMS, the certificate and every paid plugin, with the holder and the renewal date beside each one. Then we take a full backup and read the site as it actually is, including the versions it is running and what data it is still holding, because an out-of-date install sitting on last year’s form submissions is a data question as well as a software one. You get that list whether or not you go further with us.
Every month, on a date agreed in advance: core, plugins and templates updated on a staging copy and checked before anything goes live, backups taken off-site with a restore run to prove they work, and uptime watched from outside the server rather than from inside it. Content edits and small fixes join the same queue, answered inside the window written into the scope.
A written report each month: what was updated, what monitoring saw, what changed on the site and what is still queued. It names the person who did the work and what is due next month, so a renewal is judged against a record rather than a feeling. Nothing in it needs a developer to interpret, which is the test we hold it to.
Response times written in working days against a Monday to Friday week, with the days that count named in the same line.
Our commitment
A maintenance retainer is paid every month and proved once a year, if at all. These four are the parts we put in writing.
A response window you can hold us to.
Changes and fixes are answered inside two working days, and anything that has taken the site down is worked immediately. Both are counted against a Monday to Friday week, and any cover beyond it is written into the scope.
Everything stays in your name.
The hosting, the domain, the registrar and every paid licence sit under your entity, and you hold an administrator account that genuinely is one. Ending the engagement changes who does the work, and nothing else.
The scope says what is excluded.
You get a list of what the plan covers and a list of what it does not, in the same document. A new feature, a redesign or an incident is quoted separately, so a monthly fee never becomes an argument about what it bought.
A named person who knows it.
One person holds your site and signs the monthly report. You are not writing to a queue that reads the history again every time, and when they are away the handover is to a named second rather than to whoever is free.
Common questions
Keep exploring
A design system drawn for both reading directions, not screens.
Builds sequenced around the approvals the launch date waits on.
Flows and states tested with real people before anything is built.
Stores wired for the payment set, the courier and the invoice.
The plan decides more than the theme. We settle that first.
A store you own outright, with the running cost priced first.
Built for the two people who have to publish it, in both scripts.
For content that has to reach more than one surface.
The origin, the scripts and the consent layer, not the network.
Next step
Send us the site and tell us who holds the logins. We will come back with what state it is in, what is missing, and what it would take to hold.
Tell us what you need.