Spayne Studio – Website Care Scope & Disclaimer

Plain-language terms covering website care, security, and maintenance work.


What I do

  • Manage WordPress core, plugin, and theme updates as part of agreed work.
  • Apply basic hardening steps: password resets, admin user review, and removing unnecessary access.
  • Act on findings from security scanning tools (such as MalCare, Sucuri, or Wordfence), and escalate to a specialist when a serious compromise is identified.
  • Coordinate with hosting providers and security vendors when issues arise, within the hours agreed for the project.
  • Take reasonable care and follow current best practice for WordPress site management.

What I don’t do

  • I am not a 24/7 security operations centre, and I don’t monitor your site around the clock unless that’s specifically agreed as part of an ongoing arrangement.
  • I don’t guarantee that your site will never be hacked, compromised, or affected by malware. No one can promise that.
  • I don’t provide legal advice, data-breach notification advice, or formal forensic investigation. If a compromise requires that level of specialist work, I’ll recommend a suitable provider.
  • I don’t take responsibility for issues caused by third-party plugins, themes, hosting infrastructure, or actions taken by other people with access to your site.

Your responsibilities as the client

  • Maintain your own legal policies (privacy policy, terms and conditions, disclaimers) — I’m happy to point you toward tools that can help with this.
  • Let me know promptly if you notice anything unusual or suspicious on your site.
  • Approve any significant changes before I make them: installing new plugins, removing staging environments, deleting user accounts, and similar.
  • Keep your own account credentials (hosting login, domain registrar, etc.) secure on your end.

Limitation of liability

I’ll take reasonable care and follow current best practice in everything I do, but I can’t guarantee your site will never be compromised, and I can’t be held responsible for losses beyond the amount you’ve paid me for the specific service in question.

A note on incident response

If your site is compromised, there’s a difference between:

  • Routine care — updates, monitoring, basic hardening — which is covered under an ongoing arrangement where one exists.
  • Active incident investigation and coordination — deep log review, liaising with removal specialists, and managing a security incident from end to end — which is treated as separate, billable work unless otherwise agreed in writing.

I’ll always tell you clearly which category a piece of work falls into before I start it.


This document sets out my working terms in plain language. It isn’t a substitute for formal legal advice, and either of us can raise questions about it at any time.

Spayne Studio spaynestudio.com