The hidden cost of a cheap website

A cheap website is not one that costs little. It is one where the ongoing work was left out of the quote and quietly transferred to you.
Plenty of inexpensive websites are fine. The distinction is not price — it is whether anybody is looking after the thing after launch.
What actually goes wrong
The security certificate expires and every visitor sees a full-page browser warning telling them your site is not safe. This is a five-minute fix that costs you a week of enquiries, because nobody calls to tell you.

A plugin stops being maintained and becomes the way somebody gets in. Most small-site compromises are not targeted; they are automated scans finding a known hole in software that stopped being updated two years ago.
The contact form silently stops delivering — a mail setting changes, a spam filter tightens — and you spend two months wondering why enquiries dried up.
And the person who built it moves on, and nobody has the login.
None of these are exotic. They are the ordinary failure modes of a site nobody is watching, and they all present at the worst possible moment, which is usually the week you are busiest.
Backups are the one that ends businesses
Everything else on that list is an afternoon of work. Losing the site with no backup is a different category: the content, the customer enquiries, the product data, the years of accumulated search ranking.
Rebuilding from a search engine's cached copy is a genuine thing people have had to do. It is as bad as it sounds.
And a backup you have never restored is not a backup — it is a hope with a filename. Ask your provider when they last restored one and what happened. If the answer is that they have never tried, you have an untested assumption sitting where your safety net should be.
What "managed" should actually mean
Updates applied and checked, not applied and assumed. Certificates renewed automatically, with an alert if renewal fails. Backups taken on a schedule and periodically restored to prove they work. Uptime watched by something that notices before your customers do. And a named person who answers when something breaks.
If a maintenance plan does not include those, it is a hosting bill with a friendlier name.
What a compromise actually costs a small business
The word "hacked" suggests something dramatic. What usually happens is quieter and more expensive.
A vulnerable plugin gets found by an automated scan — nobody chose you. Code is added that serves spam links to search engines while showing your normal site to you, which is why these run for months undetected. Then your search rankings fall, because you now appear to be linking to whatever the attacker is selling. Sometimes the host suspends the account, and the site goes dark with no warning.
Cleaning it is the small part. Convincing search engines the site is trustworthy again takes months, and the enquiries lost in the meantime do not come back. Insurers and payment processors ask questions too, if any customer data was involved.
The mechanism matters here: almost none of this requires anyone to target you. It requires only that something on your site stopped being updated, which happens by default when nobody is responsible for updating it.
Cheap is fine. Unowned is not
None of this is an argument for spending more. It is an argument for knowing who is responsible.
A simple site on decent hosting, updated occasionally by someone who knows they are meant to, will outlast an expensive one nobody owns. The failures above are not caused by low budgets — they are caused by every party assuming another party is handling it. The builder thought the host did updates. The host does servers, not sites. The owner thought it was included.
So the question is not what you paid. It is whether you can name the person who would fix it, and whether they know that is their job. If the answer takes more than a moment, that is the actual finding.
Slow counts as broken
The failures above are visible. This one is not, which is why it goes unaddressed for years.
A neglected site gets slower in ordinary ways: photographs uploaded straight from a phone at full resolution, a stack of plugins each loading its own code, a cheap shared server carrying too many other sites. None of it announces itself. The site works, so nobody looks.
What it costs is measurable in the wrong direction. People on phones abandon slow pages, and they do not tell you — they go back to the results and pick somebody else. Search engines fold loading speed into how they rank pages, so the same neglect that costs you visitors also makes you harder to find in the first place. Both effects compound quietly.
Test it the way a customer meets it: on a phone, on mobile data rather than the office wi-fi, on the page you actually want people to reach rather than the homepage. If it takes long enough that you notice, it takes long enough that they do.
How to audit what you have in twenty minutes
Find out where the site is hosted and who pays the bill — surprisingly often, nobody in the business knows.
Check the domain's expiry date and who the registrant is. A domain registered to a former contractor is a business risk sitting quietly in a database.
Ask when the last backup was taken and where it lives. If it lives on the same server as the site, it is not an off-site backup, whatever it is called.
Submit your own contact form and see whether it arrives.
And confirm you have administrator access to your own website. That last one takes a minute and is the one most likely to fail.
Want this kind of thinking on your project?
Book a free consultation — no cost, no pressure.
Book a Free Consultation