Websites almost never break loudly. There is no bang, no dramatic morning where everything has gone. A site that nobody looks after fades, and it fades in a fairly predictable order. By the time anyone notices, the process has usually been under way for months.
We know the order well, because businesses arrive with sites at every point along it. So here is the honest timeline of a website left to fend for itself.
The first three months: nothing looks wrong
This is the dangerous stage, and it is dangerous precisely because everything still works. The pages load. The phone rings. Nobody is thinking about the website at all, which is rather the problem, because underneath it two things have started building.
Updates come first. Patchstack, who track WordPress security for a living, logged 11,334 new vulnerabilities across the ecosystem in a single year. Nearly all sat in plugins rather than WordPress itself, and around half of the serious ones were being probed by attackers within a day of becoming public. Miss one month of updates and your site is almost certainly fine. Miss six and it is carrying a growing list of published, documented ways in, each one written up helpfully for anyone who cares to look.
Then there is the backup question, which is really two questions wearing one name. Does a backup exist? Usually, yes. Has anyone ever tested restoring it? An untested backup is a guess about whether you can restore your site if you lose it.
Three to six months: the quiet failures begin
Nothing announces itself in this stage, but small failures are starting to happen behind the scenes.
The contact form is the classic. Leadferno tested 225 real small-business contact forms and found one in twenty broken in some way, sitting on the page, accepting messages, delivering them nowhere. A dead form looks identical to a working one, which is the whole trouble with it.
Certificates have joined the risk list in a way they had not a few years ago. The padlock in the address bar comes from a certificate, and an industry rule change in March capped their lifetime at 200 days, dropping to 100 next year and just 47 days from March 2029. Renewals are automated, mostly. But automation is one more thing that fails without a sound when nobody checks it. When a certificate lapses the failure is anything but silent for your visitors however, who meet a security warning instead of your homepage.
Meanwhile the update debt from the first stage compounds quietly in the background. Six months of plugin updates applied in one nervous batch is a much riskier event than the same updates applied monthly, which is how the sentence "we finally ran the updates" so often ends with the day the site broke.
Six to twelve months: now the visitors notice
Somewhere around the half-year mark, the decay stops being a technical matter and becomes something customers can feel. The site is slower than the ones they were on five minutes ago, because the platform and plugins beneath it have aged while browsers and devices moved on. The content has drifted out of true: last year's prices, a team member who left in the spring, opening hours that no longer match the door. Small things. But every one of them teaches a visitor to trust the site a little less, and trust is the only currency a business website deals in.
The foundations shift in the same season. PHP, the language most business websites run on, retires its versions on a published schedule, and everything up to 8.1 is already end-of-life, with 8.2's security support finishing this December. W3Techs counted 28.6% of PHP-based sites still running version 7 this September, years after its last security fix. From October, Chrome starts asking visitors for permission the first time they open any public site still on plain HTTP. And search engines, watching a site where nothing ever changes, respond the way anyone would: they call round less often, and they trust it less when they do.
Past a year: the cliff
The rescue calls we take tend to come after the first birthday nobody celebrated, and they rhyme.
There is the expired domain, where a renewal notice went to an email address nobody reads any more and the first sign of trouble was the website and email dying together. A .uk domain gets suspended about thirty days after expiry. It can still be renewed for up to ninety. At ninety-five it is released for anyone in the world to register, and the countdown does not pause while you find the right login.
There is the unreachable developer, the person who held every key and has moved on, leaving nobody who knows where the site lives. We wrote a whole guide on what to do when your web designer disappears because this happens far more often than you would think.
And there is the saddest one: the rebuild that upkeep would have prevented, where a site has fallen so far behind on platform, plugins and content that bringing it up to date costs more than starting again. Almost every site in that state was healthy two years earlier. It needed an hour a month, and nobody gave it one.
None of which is meant to leave you checking your certificate at midnight. The care a website needs is modest and boring: updates monthly, a restore properly tested, the form submitted end to end now and again, renewals watched, the content read through with fresh eyes a few times a year. Some owners handle all of it themselves and do it well. Our guide to what website maintenance costs lays out both that route and the paid one, and for owners who would rather never think about any of this again, ongoing support exists so that someone else does the thinking. If you suspect your own site has been fending for itself a while, an honest look at where it sits on this timeline takes very little arranging.
The comparison we find ourselves offering clients is a shopfront rather than a poster. A poster gets printed once and does its job until you take it down. A shopfront needs sweeping, the window needs changing, the lock wants oiling, and in return it earns for you every single day it is open. Websites are shopfronts that look deceptively like posters. Everything in the timeline above is just what happens to a shopfront nobody sweeps.
Sources
- Patchstack: State of WordPress Security in 2026
- DigiCert: TLS certificate lifetimes reducing to 47 days
- Google Security Blog: HTTPS by default in Chrome
- PHP: supported versions
- W3Techs: PHP version usage statistics
- Leadferno: contact form and lead management research
- Nominet: .uk renewal and expiry procedure
Get in touch - we're happy to chat.



