WordPress client reporting
Maintenance work is invisible when it goes well, which is a commercial problem: the month nothing broke looks identical to the month nobody did anything. SiteVigilante builds your client's report from the work it actually recorded, puts your agency's name on it, and sends it on the cadence you set for that client.
Most maintenance reports are generated from a template and filled in with whatever the tool happened to have. When a dimension is missing, the template does the natural thing and prints a zero — no incidents, no findings, nothing to report.
That is the worst thing a document like this can do. It is signed by your agency, it is handed to somebody who cannot check it, and it says a month nobody observed was a month nothing went wrong.
A zero and a blank are different answers, and only one of them is a measurement.
What is in the report
Ten dimensions, in the order the document reads them. Every one appears in every report for every website, always — a dimension cannot vanish because a query found no rows or because somebody edited a template.
Monitored state
Whether each of the client's websites was actually being watched over the period, established before anything else is counted.
Updates applied
Every core, plugin and theme update run in the period, the versions it moved between, and how each one ended.
Incidents
What went wrong, when, and whether it was resolved — counted only where something was observing.
Security findings
What was raised in the period and what was closed. The security page covers what a finding is.
Component actions taken
Plugins and themes held, rolled back or deactivated, with the reason each action was taken.
File-level remediation
Not built. It prints as not measured for every website rather than being folded into a section that looks answered.
Uptime
Observations over the period, with the coverage figure beside the percentage. See monitoring.
Performance
Whatever speed measurements were actually taken in the period — and nothing if none were, because they run when you ask.
Assurance checks
The outside-in checks: certificates, domain expiry, indexability, mail path, and the rest of the daily timetable.
Currently unresolved
What is still open at the moment the report was built, so the document ends on the present rather than the past.
“Not measured” is a real answer, printed in full
Every dimension establishes that something was observing before it counts anything. Where nothing was, it says so, names why, and carries no figure at all — not a zero with a footnote.
Uptime — not measured for this website in this period. Observations began part way through, so no percentage is given for the full period.
Performance — not measured. No speed test was run against this website during the period.
File-level remediation — not measured. This product does not perform file-level remediation, so no work of that kind is recorded for any website.
It costs something to publish a document that admits what it does not know. What it buys is the only thing that matters about a report an agency signs: when it does say something, the client can rely on it.
And nothing in the report scores a website or combines the dimensions into an overall verdict. A client whose five websites each fail a different check is not “80% healthy”; that number would be manufactured, and the document would be inviting a conclusion the measurements do not support.
Your name on it, your schedule, your recipients
Your branding
Your logo and your accent colour, set once for the account and applied to every report. The document is your agency's work, and it reads as your agency's work.
A cadence per client
Monthly or quarterly, chosen for each client rather than globally, with the day of the month you want it anchored to. One client's board meeting is not another's.
Recipients you nominate
Record the client's contacts, then choose which of them actually receive a report. Knowing who somebody is and subscribing them to a mailing are two different decisions, and they are two different controls.
Download or send
Every report can be read in the dashboard, downloaded as a PDF to attach to your own invoice or email, or delivered to the nominated contacts automatically when it falls due.
And whether it actually went out
The failure mode of automated client reporting is silence: something stops sending and nobody finds out until a client asks why they have not heard from you since spring.
So delivery has its own state, per client, and the states are deliberately not collapsed into a tick. “Nobody is subscribed” and “sending is failing” are different problems with different fixes, and a single green checkmark would hide both.
Delivery states
- Delivering — scheduled, subscribed, going out.
- Waiting — scheduled, not yet due.
- Not scheduled — no cadence set for this client.
- Nobody receives — a cadence, but no subscribed contact.
- Failing — it is due and it is not arriving.
Build one for a client you already look after
14 days, no card required. Connect a client's websites, let a cycle run, and read the document they would have received.
Read next
WordPress monitoring
Where dimensions 01, 03, 07 and 09 come from: the full timetable of what is checked and how often.
Update management
Where dimensions 02 and 05 come from: what happens when an update runs, and what happens when one breaks a website.
WordPress management for agencies
Clients, contacts, team access and the estate view the reports are assembled from.
Data Processing Agreement
Your client's contact details are personal data. This is how they are processed, and it is incorporated into the Terms.