The website is running ads but suddenly "collapses"? The old dev "disappeared", no one is responsible? At Tan Phat Digital, we operate maintenance according to a clear SLA, prioritizing P1 response within 2 hours, safe recovery via staging, 1-click backup/rollback, and post-processing reports so you understand all the changes.
Before starting, you can view the pillar article that describes the entire rescue and prevention process. of us at Website maintenance service in Ho Chi Minh.
1) What is “proper” maintenance?
Maintenance is not just “patching errors when broken”. A systematic program must cover prevention - detection - correction - improvement, bound by SLA, have safety processes and transparent reporting.
Three operating principles at Tan Phat Digital:
Fast but not reckless: all repairs take place on staging first, through inspection test, then deploy to production with rollback plan ready.
Prioritize by severity: P1 (loss of revenue/security) → P2 (impact on experience) → P3 (technical improvements).
Absolute transparency: each intervention has a ticket, change record, diff code (when applicable) and post-processing report.
Need to balance risk – cost? Refer to the response time and scope of each package in HCM website maintenance price list 2025.
2) Where is “reputation” shown? (SLA, case P1, 4 processing steps)
With P1, we always apply 4 fixed steps:
Quick isolation & diagnosis
Temporarily close the error point (turn off module, purge cache, transfer static page if necessary). Check uptime, web/app/DB log, WAF/CDN.Temporary restore to minimize damage
Turn on static site/maintenance for a few minutes when required. 1-click rollback to the most recent snapshot if the new version causes a crash.Fix root errors on staging
Security patch, fix 500/404, handle plugin/payment conflicts, optimize heavy queries... Regression testing: home page, category, cart, checkout, form.Deploy safely & according to Monitor
Deploy according to checklist, monitor closely every 24–48 hours. Send post-mortem: causes, impacts, timeline, prevention recommendations.
3) Fast but safe: staging, backup, rollback
“Speed” without a safe fulcrum is very risky. At Tan Phat Digital, all risky changes go through:
Staging like production (CMS version, theme/plugin, PHP/Node config...).
1-click Backup before deploying; Can rollback immediately if errors arise.
Testing process: core functions (login, cart, checkout, payment), technical (Core Web Vitals, 404/500, canonical, robots, sitemap), security (permissions, firewall, reCAPTCHA, rate-limit).
Want to understand specifically the cyclical prevention work period? See monthly website maintenance process to know how we periodically clean up techniques, update and control risks.
4) Group of “all the time” errors (and how we handle them). handle)
500/Timeout: heavy DB queries, queue congestion, plugin conflicts.
How to handle: isolate faulty modules, optimize query/index, expand log view, rollback stable version.404/Redirect string: change URL/slug without 301 map; canonical wrong; theme changes link structure.
How to handle: create 301 map, edit canonical/robots/sitemap, check Search Console.Hack/insert malicious code/strange redirect: implanted into theme/plugin/upload file; expose token/API key.
How to handle: quarantine, scan & clean, change key/secret, patch vulnerabilities, deploy WAF & hardening, monitor after recovery.
If you are in this situation, before hitting production, read quarantine & safe recovery checklist.Broken interface/JS error: incompatible theme/plugin update; CSS/JS minify is wrong.
How to handle: Test on staging, turn on compat mode, pin version, reconfigure bundler/minifier.Payment error: 3D Secure, webhook failed, port conflict.
How to handle: test sandbox, log request/response, resynchronize single state, test performance below download.
5) Security: close the "back door", lock the "front door"
Hardening: change DB prefix, block user listing, hide CMS version, limit upload of standard MIME, CSRF/JWT.
Permissions & logs: “least privilege” principle, log login/change password/edit code, audit accordingly schedule.
WAF/CDN: bad bot blocking, Geo/IP rate-limit, application firewall, anomaly alerts.
Controlled updates: minor by schedule, major via staging, battery dependent.
Multi-layer backup: snapshot hosting + off-site backup, encryption, scheduled restore check period.
6) Reporting & transparency: you understand all changes
After each P1/P2/P3, you receive:
Post-mortem: root cause, impact (downtime, impact URL), timeline, measures.
Diff/Changelog: file/area of code changed; server configuration; rollback category.
Prevention recommendations: Limit permissions, standardize releases, optimize cache/CDN, monitor CWV, maintenance schedule.
7) Onboarding process within 24 hours: fast - compact - professional
First day of cooperation:
Security: sign NDA, create support channel, guide Guide to secure credential handover.
Technical collection: infrastructure (hosting/CDN/WAF), CMS, theme/plugin, integration.
Free 60’ Audit: scan display errors, highlight log, CWV, 404/500, robots/sitemap, canonical.
Recommendation package & SLA:match business risk (ads, seasonality) with appropriate response level.
8) Quick FAQ
P1 is running Ads – will it be up again in 2 hours?
SLA target is response within 2 hours and restore service as soon as possible (static page/rollback if necessary), then fix the original above staging.
Committed to confidentiality?
Yes. Sign NDA, manage standard credential, remove rights when project ends or personnel change.
Is malicious code inserted completely clean?
The process of quarantine – clean – patch – monitor brings the site to a clean state; Need to change passwords, keys, tokens and strengthen WAF to avoid re-infection.
Are there periodic reports?
Yes. Report after each incident and periodically report according to the package (updates, backlog, CWV/uptime, recommendations).
9) When should you sign an SLA instead of “calling the fire department by case”?
Website has direct revenue (e-commerce, lead B2B).
Has season/advertising – downtime burns money books.
Multiple integrated system (CRM, ERP, payment gateway).
Need continuous improvement roadmap: speed, technical SEO, security, release process.
If website maintenance wants to be fast, it must have discipline: clear SLA, staging–backup–rollback mandatory, P1→P2→P3 priority, and transparent reporting. From real-life experience in HCM, the Tan Phat Digital team has standardized the playbook to reduce downtime, close security holes, and optimize performance sustainably for businesses.
Ready to put your website in a safe zone? Schedule a free 30-minute consultation & audit at Tan Phat Digital website maintenance service.
Share








