Short answer: when the person who built your website moves on, the website doesn’t stop needing care — updates, backups, security patches, expiring certificates and renewals all keep coming. Someone has to keep it alive. Your three realistic options are: do it yourself, put a developer on call, or hand the running of it to a managed host. For most small businesses without an in-house techie, managed hosting is the calm default — the site, the server and the email looked after in one place.
We run managed hosting and regularly inherit exactly these sites — built well, then left to drift — so here’s the practical version.
A finished website is not a finished job
The project has an end date. The website doesn’t. From day one, everything the site is built on keeps moving: WordPress and its plugins ship updates, PHP versions (the language your site runs on) reach end-of-life, SSL certificates expire, the framework your developer used gets security releases. The site sits still while the software it’s built on keeps moving — and the gap between the two is where problems grow.
This is the part nobody quotes for, because it isn’t building anything. It’s just the work that keeps an already-working site from quietly breaking.
What “nobody’s watching it” actually costs
Left unattended, a site fails in the same predictable ways:
- Outdated plugins get exploited. On WordPress the holes that get you are almost never in the core. Of the more than 11,000 WordPress vulnerabilities Patchstack tracked in 2025, 91% were in plugins and themes — and just six were in the core itself. The plugin you installed two years ago and forgot is the classic way in.
- Certificates and domains expire. An SSL certificate (it encrypts the connection to your site) lapses and browsers show a red “not secure” warning; a domain auto-renewal fails on an old card and the whole site — and the email on it — goes dark.
- PHP reaches end-of-life. The host upgrades the server, the old code isn’t compatible, and the site white-screens. With no one watching, you hear about it from a customer.
- Backups that were never tested. “There are backups” is not the same as “we restored one and it worked.” Most orphaned sites have never had a restore tested — so nobody knows if the safety net holds.
- Email drifts to spam. SPF, DKIM or DMARC records go stale or a sending key expires, and the invoices you send stop arriving — see why mail from your own domain lands in spam.
None of this announces itself. It surfaces as a hack, a blank page, or a customer asking why your site is down.
Why it happens — and it’s usually not your developer’s fault
This isn’t a story about a bad freelancer. It’s a structural gap. Agencies and freelancers are paid to build; maintenance is a separate, ongoing job that’s rarely in the original contract. The freelancer takes on new clients. The agency’s attention moves to the next project. The in-house person who “handled the website” leaves. None of them was contracted to watch your site for the next three years — so nobody is.
The site keeps working right up until the day it doesn’t, which is exactly why the gap is so easy to miss.
Your three real options
| Option | Who watches it day to day | When it breaks at 2am | Server + email too? | Cost shape |
|---|---|---|---|---|
| Do it yourself | You — when you remember | You, Googling under pressure | You are the sysadmin | ”free” until it costs you a weekend or a breach |
| Developer on call | Sometimes; depends on their availability | If they reply | Usually just the code, not the server or mail | Hourly, unpredictable; can leave you ghosted again |
| Managed hosting | The host, continuously | The host, on watch | Yes — server, updates, backups and email in one place | Flat monthly, predictable |
The honest trade-off: doing it yourself is free until a weekend disappears into a hacked site. A developer on call is flexible but only as reliable as their availability — and you can be left ghosted a second time. Managed hosting trades a flat monthly fee for someone whose actual job is to watch the site so you don’t have to.
What to hand over so the next person can take it on
If you’re moving an orphaned site to someone new, this is what they need. Gather it once and the handover is painless:
- Domain registrar login — whoever controls the domain controls everything.
- DNS access — often the registrar, sometimes separate.
- Hosting / server login.
- CMS admin account — a WordPress admin account, or equivalent.
- Code repository (Git) if the site is custom-built.
- The stack, written down: CMS and version, active plugins and themes, PHP or Node version.
- Where the backups live — and whether a restore was ever tested.
- Third-party keys: SMTP (email sending), the payment gateway, any API keys (access to outside services).
If you can’t get some of these from the developer who left, a competent host can usually recover the rest. Don’t let a couple of missing logins stop you — adopting a neglected site is routine. (Worried about what’s already exposed? Here’s where to check for free which holes threaten your site.)
The calm version
A website is not a one-time purchase; it’s something that needs a steady pair of hands after launch. That’s the whole point of managed hosting: you own the site, someone else keeps it patched, backed up, monitored and online.
That’s us. On our managed hosting we adopt sites built by someone else — WordPress, Astro, Next.js, plain PHP or Node, it doesn’t matter — and take over the updates, backups, security and the email, on EU servers, billed by one EU company. Included hours on the Standard and Pro plans cover the small changes, so next time something needs doing there’s someone to do it. If your developer has moved on, your site doesn’t have to be on its own.