Skip to content
WhatsApp Call Quote

What breaks on a website after launch, and what an AMC covers

Domains lapse, SSL expires, plugins break forms. Here is what actually fails on a website after launch and what a maintenance agreement should cover in writing.

What breaks on a website after launch, and what an AMC covers

A website is not a physical object. It is a set of moving parts that depend on other people’s software, someone else’s server, a payment for a domain name, and a certificate that expires on a fixed date. Launch day is the moment all those parts happen to be working at the same time. Six months later, without anyone touching the site, several of them will have quietly stopped.

This post covers what actually breaks, why owners usually find out from a customer rather than from their own monitoring, and what a maintenance agreement should say in writing before you sign it.

The things that break on a schedule

Some failures are not random. They are scheduled, and you can see them coming a year in advance.

Domain expiry. Your domain name is rented, not owned. It renews annually or in multi-year blocks. If the renewal notice goes to an email address belonging to a developer who left, or to a Gmail account nobody checks, the domain lapses. The site goes down. Worse, after a grace period the domain can be picked up by someone else, and getting it back becomes a negotiation rather than a payment. This happens to established businesses more often than you would think, usually because the domain was registered in the vendor’s name during the first project and never transferred.

SSL certificate expiry. The padlock in the browser comes from a certificate with an expiry date, often ninety days for free certificates and a year for paid ones. When it expires, visitors do not see a small warning. Chrome shows a full-page red screen saying the connection is not private. Most people close the tab. If you sell anything online, or even take enquiries through a form, that screen costs you every enquiry until it is fixed. Auto-renewal exists for most certificates but it fails silently when server configurations change.

Hosting renewal. Same story as the domain. The invoice goes somewhere, nobody pays it, and the account is suspended. Some hosts delete data after suspension. If your only copy of the site was on that server, the site is gone.

The fix for all three is boring: a shared calendar, renewal alerts going to two people at your company rather than only to the vendor, and confirmation in writing about whose name the domain and hosting account are registered under. Ask for that during the build, not after.

The things that break because software moves underneath you

If your site runs on WordPress, or any CMS, it is built from a core platform plus plugins written by different developers. Those developers release updates. Some updates patch security holes. Some change how the plugin works. Occasionally two plugins that worked fine together stop working after one of them updates.

What this looks like in practice:

  • The contact form plugin updates, and the form now submits but sends mail to nobody.
  • The page builder updates, and your homepage layout shifts on mobile.
  • The gallery plugin is abandoned by its developer, stops receiving security patches, and becomes the way someone injects spam links into your site.

Unpatched plugins are the most common way small business websites get hacked in India. The attacker is usually not targeting you specifically. Automated scripts crawl the internet looking for known vulnerable plugin versions. Your site is a match, and suddenly you are hosting pharmacy spam pages that Google indexes. Cleaning that up is more expensive than a year of maintenance, and your search rankings take months to recover.

The reasonable approach is updates applied on a regular cycle, tested on a staging copy first for anything significant, with the site backed up before each round. Not automatic updates applied blind at 2 AM with nobody checking the result.

The things that break because nobody tested them

This is the category that costs the most money and gets noticed the least.

Contact forms. A form can look like it is working. You fill it in, you see “Thank you, we will get back to you,” and everything seems fine. Meanwhile the email is landing in spam, or being rejected by the receiving mail server, or going to an address that was correct two years ago. Businesses have lost months of enquiries this way and assumed the market had gone quiet.

Test your own form once a month. Fill it in as a customer would, from a phone, on mobile data, not from your office Wi-Fi. See if the email arrives, and see how long it takes. Better still, have form submissions saved into the site’s database as well as emailed, so there is a record even when mail fails.

WhatsApp and call buttons. Many Indian sites have a floating WhatsApp button. If the number changes, or the link format breaks after a plugin update, the button still appears and does nothing useful. Same for click-to-call links on mobile.

Payment and enquiry flows. If you take payments, the gateway integration depends on API keys and credentials that can expire or be rotated. Test a small live transaction periodically.

The things that go stale

Nothing technically breaks here, but the damage is real.

Phone numbers change. Branch addresses change. The team page shows three people who left. The Diwali offer banner is still up in March. The price list is from two years ago and a customer arrives expecting the old rate.

Your Google Business Profile and your website should agree with each other on name, address and phone number. When they disagree, local search results get weaker and customers call a disconnected number. If you have moved office, changed your GST registration address, or added a second location, both need updating on the same day.

Content freshness also affects how the site performs in search. A site that has not changed in three years reads as abandoned to visitors even when the business is thriving. This connects directly to whatever you are spending on digital marketing, since ads and SEO both send traffic to pages that need to be accurate to convert.

Backups and uptime

Backups. Ask two questions: how often, and where. Daily backups stored on the same server as the site are not backups. If the server is compromised or the account is suspended, both copies are gone together. You want off-server storage, a retention period of at least a few weeks so you can go back past a problem you did not notice immediately, and, critically, a restore that someone has actually tested. Untested backups fail at the worst moment.

Uptime monitoring. A basic monitor checks your site every few minutes and alerts someone when it stops responding. Without it, you find out your site has been down since Friday night when a customer mentions it on Monday. Monitoring is cheap and should be standard on any hosting arrangement you pay for.

Performance. Sites slow down over time as content, images and plugins accumulate. Slow sites lose mobile visitors, and a large share of your traffic in India is on mid-range Android phones on patchy 4G. A periodic check on page weight and load time belongs in maintenance, not in a separate project quote.

What to ask for in the maintenance agreement

Most website AMC proposals are one page of vague promises. Push for specifics on these points:

Scope in plain language. What is included each month, and what is billed separately. Content updates, new pages, new features, and design changes are usually separate. Get the boundary written down so you are not arguing about it later.

Response and resolution times. Distinguish between site down, which needs a response in hours, and a typo fix, which does not. Ask what happens on weekends and during festival holidays.

Update cadence. Monthly, quarterly, or as-needed. Whether updates are tested on a staging copy before going live.

Backup specifics. Frequency, storage location, retention period, and who can trigger a restore.

Monitoring and reporting. Do you get a monthly summary showing uptime, updates applied, backups taken, and anything fixed. A one-page report is enough, but its absence usually means nothing is being tracked.

Included hours. Many plans include a number of hours for small changes. Ask whether unused hours carry forward and what the rate is beyond them.

Access and ownership. You should hold the domain registrar login, the hosting account, and admin access to the site, even if your vendor manages day to day. If a vendor resists this, that is the answer to a different question.

Exit terms. What you receive if you end the agreement: a full site backup, database export, and credentials handed over cleanly.

For anything built as custom software rather than a standard website, add version documentation and a named point of contact who understands the codebase.

What to do next

Start with a fifteen-minute audit of your own site today. Check the padlock and click it to see the certificate expiry. Find out when your domain renews and in whose name it is registered. Submit your own contact form from your phone. Call the number listed on the site. Compare your website details against your Google Business Profile.

Whatever is wrong after fifteen minutes tells you how urgently you need a plan. If you would like someone to look at your existing site and tell you plainly what is at risk, get in touch with Spier Infotech and we will go through it with you.