Key facts
- Every plugin added to a WordPress site is a piece of third-party code that needs updates and can introduce security holes if abandoned by its developer, so this pack asks each bidder to name every plugin on their list up front and confirm it is still being actively maintained.
- A popular SEO plugin handling technical basics like meta tags and an XML sitemap does not by itself mean a site's SEO is finished; site structure, page speed, and content quality still have to be built well, and a bidder should be asked what SEO work they do beyond installing a plugin.
- WordPress core, the theme, and every plugin need regular updates to stay secure, and outdated WordPress sites are a common target for automated hacking attempts, so the RFP should state clearly who is responsible for updates after launch.
- A page builder plugin (used to visually design pages without code) can make a site easy for you to edit yourself, but heavy page builder use is a known cause of slower page load times, so a bidder should be asked how they balance ease of editing against site speed.
- Hosting for a WordPress site is a separate decision from who builds it, and shared, low-cost hosting is a common cause of a slow site regardless of how well the site itself was built, so the RFP should ask what hosting the bidder recommends and why.
Scope boundaries
Name every page type up front, home, service or product pages, a blog, any tools like a quote form, matching the structure you actually run your business on rather than a generic template count.
State whether the build uses a page builder plugin for easy self-editing, a block-based approach using WordPress's native editor, or a fully custom-coded theme. Each has different tradeoffs between how easily you can edit the site yourself later and how fast the site loads, and the bidder should recommend one and explain why for your specific needs.
State whether hosting is included in the quote or is a separate decision you will make. If the bidder is recommending their own hosting, ask what it is and what you are paying for it separately from the build, since bundled hosting costs are sometimes marked up without being stated plainly.
What the vendor must be given
Give the developer an administrator account on WordPress created under your own hosting account, rather than building the site on hosting only they control, so you are not dependent on them to access your own website later.
Supply your brand assets, any existing content you want kept, and a way to point the domain at the new site once it is ready, whether that means DNS access or just a login you can hand over temporarily.
Give the developer access to any third-party tools the site needs to integrate with, a CRM, a booking system, an email platform, and your GA4 and Search Console if this is a rebuild of an existing site.
Ownership and exit clauses
State that you own the site outright, its theme, its content, and every plugin license purchased for the site, and that any paid plugin or theme license is registered to your name and email, not the developer's account.
State that hosting, if the developer set it up, is billed under your name on your own payment method, or that you receive full login access to whatever hosting account was used, so you are never locked out of your own site over a billing dispute.
Add a clause requiring a full site backup, database and files, handed to you at project completion and again on request at any point later, since a WordPress site's database holds content that is not always obvious to export without the right tool.
Milestones and acceptance tests
Set a design milestone: page layout or theme customization approved before content is loaded across every page.
Set a staging milestone next, with its own pass-or-fail test: every page loads without errors, every form submits and is received correctly, the site passes a basic security check (no exposed admin paths, no default passwords left in place), and page speed on a mobile connection is within a stated range.
Set a launch milestone tied to a written test: the live domain loads correctly with SSL (the padlock security indicator) active, all plugins are updated to their current versions at launch, and a backup of the finished site is confirmed to exist and to have been handed to you. The last invoice should wait on this checklist, not on the site merely being visible in a browser.
Scoring rubric
Weight plugin and maintenance transparency the most here: give price and payment terms 30 percent, the specificity of the plugin list and who maintains updates after launch 25 percent, relevant past work 20 percent, timeline realism 15 percent, and hold the last 10 percent for actual references.
Score the plugin list on whether the developer names specific, actively maintained plugins for each function (forms, SEO, security, page building) rather than a vague promise to add whatever is needed as the project goes.
Ask references specifically whether their site has had any security issues or an update-related outage since launch, since outdated WordPress installs and plugin conflicts are among the most common ongoing problems, and a developer's past client history on this is informative.
Questions every bidder must answer
Make every bidder answer in writing: Which plugins will you install, and are they all actively maintained by their developers? Who is responsible for WordPress core, theme, and plugin updates after launch, and is that included in your price or a separate ongoing fee? What hosting do you recommend, and what does it cost separately from the build?
Also ask: Will the site be built under my own hosting account, or yours? How do you keep the site fast if a page builder is used? What is your process if a plugin update breaks something on the live site?
A bidder who names specific plugins, states clearly who owns update responsibility after launch, and recommends hosting with a reason attached is describing a maintainable site. A bidder who is vague about post-launch responsibility is setting you up for a surprise the first time something breaks.
Related questions
No. An SEO plugin handles technical basics like meta tags and a sitemap, but site structure, content quality, and page speed still need real work. Treat the plugin as a tool, not a finished SEO strategy.
Someone needs to be, in writing. Whether it is the developer under an ongoing maintenance fee, you, or a third party, an unmaintained WordPress site is a common and avoidable security risk, and this RFP asks you to settle that before launch, not after.
It depends on how much you want to edit the site yourself later versus how important page speed is to you. A heavy page builder can slow a site down; a lighter, block-based approach is often a better balance for most small business sites.
A well-chosen, customized template is often the more cost-effective choice for most small businesses, and a fully custom design makes more sense once your needs go beyond what any template can flex to fit.
Yes. A WordPress build sits inside the same website packages we quote everything else from, roughly $1,500 on the low end and $20,000 or more for a large site. Nobody pays to get set up, the first 30 days are guaranteed, and every plugin's cost gets named up front.
SearchPod is a vendor for this kind of work and would answer this RFP; the acceptance tests here are the ones we agree to.
Want this scoped and priced for your business?
Get a free, no-obligation proposal within one business day. We look at your site and your market and tell you plainly what we would do, and what we would not.
Get your free proposal