Picture this: your website grinds to a halt on a busy Monday morning, leaving customers stranded and your inbox flooded with complaints. For many small businesses, this scenario isn’t hypothetical it’s an expensive reality. According to recent industry figures, UK SMEs lose thousands each year through downtime, security breaches or outdated content, all because essential website maintenance falls by the wayside.
Website maintenance isn’t just a technical chore it’s the ongoing discipline of keeping your online presence secure, high-performing and ready to convert visitors into customers. For business owners, marketers and decision-makers in Surrey and beyond, understanding what to maintain (and when) can mean the difference between a thriving digital storefront and a costly digital liability.
This guide is tailored for those who want clarity, not jargon. Whether you’re running a local shop, managing an e-commerce site, or leading a growing team, you’ll find practical value here. We’ll walk you through ten essential website maintenance tasks each with straightforward explanations, recommended tools, and clear guidance on how often to tick them off your list.
Here’s what you can expect: actionable steps for backing up your site, applying critical software updates, scanning for security threats, monitoring uptime, squashing broken links, refreshing your content, managing security certificates, staying compliant with data protection law, checking browser compatibility and structuring your ongoing maintenance calendar. Each section is designed to help you avoid headaches, protect your reputation, and make every visit count.
Ready to safeguard your website’s future? Let’s get started with the first essential task.
1. Backup Your Website Regularly
Backing up your website is the single most reliable way to protect against data loss, service interruptions and costly recovery efforts. Whether you’re hit by a server crash, a rogue plugin or a targeted malware attack, having a recent copy of your files and database can be the difference between minutes of downtime and a business-critical outage.
Why Backups Matter
Imagine a routine theme update that silently corrupts your database, or a hacker who wipes your homepage just when traffic is peaking. Without a backup, you’re scrambling to piece together lost content, rebuild configurations and answer irate customer queries. In contrast, a solid backup strategy lets you restore your site in moments, preserving user trust and keeping your brand reputation intact. Regular backups aren’t just insurance they’re a commitment to continuity and peace of mind.
How Often to Back Up
For most small and medium-sized business websites, a full backup once a week strikes a good balance between safety and storage costs. If you run high-traffic e-commerce or membership platforms, consider daily or even real-time incremental backups. Full backups copy every file and database table, while incremental backups capture only the changes since your last snapshot saving space and reducing server load. Aim to retain at least four to six weeks of backups, so you can revert to the exact version you need.
Recommended Backup Methods and Tools
You have two main routes: self-hosted solutions or host-provided services.
- Self-hosted plugins: Tools such as CodeGuard, UpdraftPlus or BackWPup (for WordPress) automate scheduled full and incremental backups. They often include options to push copies to remote storage like Amazon S3, Dropbox or FTP.
- Hosting control panels: Most cPanel and Plesk installations feature built-in backup schedulers. You can define what to back up, how often and where to store it, without needing extra plugins.
- Managed backup services: If you prefer a hands-off approach, professional services take care of setup, monitoring and off-site retention for you. They’re ideal if your team lacks technical resources but still needs rapid recovery guarantees.
No matter which method you choose, test your restoration process at least once a quarter. A backup that can’t be restored is as good as no backup at all.
2. Apply Software Updates and Patches
Unpatched software remains the single biggest gateway for hackers to exploit websites. Whether it’s a forgotten security hole in an old plugin or a critical vulnerability in your content management system (CMS), failing to stay current can open the door to data breaches, site defacements and even SEO penalties. In this section, we’ll cover the essentials of keeping your core CMS, plugins, themes and server components up to date without bringing your site down.
Core CMS and Plugin Updates
- Check your dashboard
Log in to your CMS (for example, WordPress, Joomla or Drupal) and head to the Updates page. Take note of any core, plugin or extension updates that are pending. - Review changelogs
Before clicking “Update”, read the changelog to understand what’s fixed or improved. Minor version bumps (e.g. 5.8.3 → 5.8.4) typically include security patches and bug fixes, while major releases (e.g. 5.x → 6.0) may introduce new features or breaking changes. - Test on staging
If you have a staging environment, apply updates there first. This safe replica of your live site helps you spot conflicts perhaps a plugin no longer works with your theme before you push changes to production. - Roll out to production
Once you’re confident everything runs smoothly on staging, update your live site. Always keep a recent backup on hand in case you need to roll back.
Theme and Extension Maintenance
Themes and third-party extensions can be just as vulnerable as your core software. To stay on top of security and compatibility:
- Monitor developer channels
Subscribe to theme-author newsletters or follow their GitHub repositories. If a theme developer issues a security notice, you’ll want to act fast. - Audit for abandoned code
Plugins without updates for 12+ months often lack current security support. Remove or replace any extensions that show no signs of active maintenance. - Minimise plugin footprint
Fewer plugins mean a smaller attack surface. Consolidate overlapping features (for instance, combine SEO and sitemap plugins) wherever possible.
Automating Update Notifications
Keeping manual tabs on dozens of plugins can be tedious. The good news is you can automate alerting:
- ManageWP or WP Remote
These services scan all your WordPress sites from a single dashboard and send weekly email digests listing available updates. - Built-in CMS alerts
Many platforms (including Drupal and Craft CMS) allow you to configure update notifications by email or Slack. - Hosting-provided notifications
Check if your host offers automated patch reports. Some control panels can notify you the moment a new PHP, MySQL or server-level security update is released.
By combining manual best practices with automated notifications, you’ll never miss a critical update and your site will stay both secure and stable.
3. Conduct Daily Security Scans
Even the most robust website is only as strong as its weakest link. Daily security scans help you spot malware, suspicious file changes or newly discovered vulnerabilities before they escalate into full-blown breaches. By automating routine checks and combining them with occasional manual reviews, you can turn defence into a proactive habit rather than a last-minute scramble.
Types of Security Scans
- Malware scanning
Signature-based scanners compare your files against a database of known threats. They quickly flag common infections such as backdoors, phishing scripts or hidden iframes so you can remove malicious code before visitors encounter it. - Vulnerability scanning
These scans follow industry standards (for example OWASP Top Ten) to probe for weak spots like SQL injection, cross-site scripting (XSS) or outdated libraries. Vulnerability scanners often include automated checks of server components, CMS plugins and third-party APIs. - File-integrity monitoring
By creating hashes of your core files and regularly re-calculating them, file-integrity tools highlight any unauthorised modifications. If a hacker replacesfunctions.phpor injects code into a template, you’ll see precisely which files have changed.
Recommended Security Tools
- Sucuri
A cloud-based service that runs daily scans, monitors your IP reputation and offers automatic malware removal. Higher plans add a Web Application Firewall (WAF) to block attacks in real time. - SiteLock Prevent Plus
Builds on the free SiteLock Lite scanner by including a WAF, two-factor authentication and priority support. It also schedules hourly checks of your sitemap and blacklist status. - Acunetix
Delivers an in-depth crawl of your site’s pages and forms, identifying code-level vulnerabilities and configuration issues. Suited for larger sites or bespoke applications where custom code requires thorough testing. - Free options
If budget is tight, start with SiteLock Lite for daily malware sweeps or an open-source file-integrity tool like OSSEC. Even a simple daily report will highlight glaring issues before they go unnoticed.
Responding to Scan Alerts
- Triage and prioritise
Assign each alert a severity level. A critical vulnerability in your login page trumps a low-risk outdated JavaScript library. Focus on high-severity alerts first. - Isolate and investigate
Quarantine affected files on a staging copy of your site. Review the scan report, examine timestamps and compare with known backups to understand how the breach occurred. - Restore and patch
If files are corrupted beyond quick repair, restore from your most recent clean backup. Then apply the necessary patches upgrade plugins, update server software or tighten file permissions—to close the loophole. - Document remediation steps
Record the incident, your analysis and the fixes applied. This not only helps with compliance but also means your team can respond faster if a similar issue arises in future.
By weaving these daily scans into your maintenance routine, you’ll catch threats early, reduce risk and demonstrate to your customers that security isn’t an afterthought but an integral part of your online promise.
4. Monitor Uptime and Performance
Even a few minutes of downtime or sluggish pages can sabotage your search rankings, erode customer trust and drain conversions. Google experiments indicate that each extra second of load time can cut conversion rates by up to 7%. Aiming for at least 99.9% uptime and sub-three-second load times isn’t overkill it’s essential. By actively monitoring both availability and site’s speed, you’ll spot issues before your visitors do.
Uptime Monitoring Tools
Uptime monitoring services continuously ping your site from multiple global locations to ensure it’s reachable. Tools like UptimeRobot and Better Uptime offer free plans that check your site every five minutes and send instant email or SMS alerts if they detect downtime. For mission-critical platforms, AlertSite provides one-minute interval checks, regional testing and detailed incident reports. Consider running two services in parallel if one triggers a false alarm, the other will confirm whether your site really is offline.
Performance Testing and Load Time Checks
Tracking uptime alone isn’t enough. You also need to test your site’s speed to make sure pages load swiftly and smoothly. Solutions such as GTmetrix, WebPageTest and Google PageSpeed Insights analyse key metrics, including:
- Time to First Byte (TTFB): How quickly your server responds.
- Largest Contentful Paint (LCP): When the main page content finishes loading.
- Cumulative Layout Shift (CLS): How stable elements remain during rendering.
Run these checks weekly or after a major update new plugins, theme tweaks or traffic surges can all introduce hiccups. Chart your results over time to spot performance trends and nip emerging slowdowns in the bud.
Setting Thresholds and Alerts
Effective monitoring relies on clear thresholds. For uptime, 99.9% tolerance equates to around 8.8 hours of downtime per year any dip below that should push an immediate alert. On the performance side, set LCP warnings at three seconds and TTFB at 200 milliseconds. Configure your monitoring tools to forward critical notifications to a shared Slack channel or a dedicated email alias, so your web team can respond at once. By defining actionable thresholds, you’ll turn raw data into rapid fixes keeping your site fast, stable and ready for every visitor.
5. Check for Broken Links and 404 Errors
Even the smallest oversight a mistyped URL or a page that’s been moved can leave visitors staring at an unfriendly 404 error page. Both internal links (those pointing to your own content) and external links (pointing off-site) play a vital role in guiding users and search engines through your website. When those links break, you risk higher bounce rates, lost credibility and poorer crawlability, all of which can dent your SEO performance and frustrate would-be customers.
Impact of Broken Links on SEO and UX
A shopper arriving at a dead link may assume your site is unmaintained and click away in seconds search engines notice too. Broken links interrupt the natural flow of navigation, sending visitors back to their search results and signalling to Google that your content isn’t as reliable. Over time, a high volume of 404 errors can erode the authority you’ve worked hard to build, pushing your rankings down. In contrast, a smoothly linked site keeps users engaged, lowers exit rates and helps search bots index your pages more effectively.
Tools for Broken Link Detection
Catching broken links manually on every page is impractical; it’s far better to automate monthly scans. A few trusted tools include:
- Ahrefs Broken Link Checker: A free, browser-based tool that crawls both internal and external links on a URL of your choice.
- Dead Link Checker: Offers a site-wide scan and email reports of any missing pages.
- Screaming Frog SEO Spider: A desktop application that performs in-depth crawls, flags 404s and lets you export all findings in CSV format.
Set these tools to run at least once a month or after every major content update and review the reports to pinpoint problem URLs swiftly.
Fixing or Redirecting Broken Links
Once you’ve identified broken links, you have a few options:
- 301 Redirects
Use a server-level rule or a CMS plugin to point old URLs to their new locations. For example, in your.htaccessfile you might add:Redirect 301 /old-page-path https://www.yoursite.co.uk/new-page-pathThis ensures both users and search engines are forwarded seamlessly.
- Update or Remove Links
If a target page no longer exists, edit your content to link to an alternative resource. For off-site links, consider finding a fresh reference or deleting the link entirely. - Custom 404 Page
A well-designed 404 page can guide lost visitors back to key sections of your site such as your homepage or popular categories reducing frustration when a link does slip through the cracks.
By scheduling regular broken-link audits and applying immediate fixes or redirects, you’ll protect both user experience and your search-engine standing. Keeping your links in working order is a quick win that pays dividends in trust, engagement and rankings.
6. Audit and Update Website Content
Keeping your website’s content current does more than inform it signals to search engines and visitors that you’re still active, credible and invested in delivering value. An audit uncovers outdated statistics, stale offers and broken references that can erode trust, while thoughtful updates give you a chance to repurpose evergreen material and improve your SEO footprint.
Reviewing Outdated Information
Start by scouring your pages for old data points, expired promotions or products that are no longer in stock. Maintain a list of pages where the information has slipped, then assess their traffic levels to decide which to update first. High-impact pages such as best-sellers or cornerstone blog posts should top your list. If a page hasn’t been touched for 12 months or more, it’s prime for fresh copy or a complete overhaul.
Content Analytics and Engagement Metrics
Numbers don’t lie. Use analytics platforms to uncover which pages attract visitors yet struggle to keep them engaged. Key metrics include:
- Bounce rate: a sudden rise often hints at misleading titles or link errors.
- Average time on page: low dwell time can mean the content fails to meet reader expectations.
- Conversion rate: if a landing page’s form fill-rate dips, it may need clearer calls to action.
Heat-mapping tools reveal scroll depth and click patterns, while session recordings show real-time user journeys. Armed with these insights, you can trim or expand sections, rephrase headings and reroute calls to action where they’ll make the most impact.
Incorporating Visual Updates
A wall of text can overwhelm, and low-resolution images can chip away at your site’s perceived quality. Refresh your content by adding or replacing visuals screenshots, infographics, charts or short videos that illustrate key points. Always compress images with tools like TinyPNG before uploading; a crisp image that loads in under 200 KB preserves both design appeal and performance. When you inject fresh visuals, your page not only looks modern but reaps SEO rewards by signalling active upkeep to search engines.
Updating content isn’t a one-off task but an ongoing habit that keeps your site vibrant, trustworthy and competitive. Make it part of your quarterly routine to ensure every word, image and data point continues to pull its weight.
7. Review Security Certificates and TLS/SSL Configuration
Insecure connections erode visitor confidence faster than any typo or broken link. Enabling HTTPS isn’t just about the little padlock icon it’s a signal to customers (and search engines) that their data is safe and that you take privacy seriously. As browsers increasingly flag non-HTTPS sites as “not secure”, a sound TLS/SSL configuration has become essential for trust, compliance and SEO.
Importance of SSL/TLS
HTTPS encrypts the data travelling between your server and a user’s browser, safeguarding credentials, payment details and personal information against eavesdroppers. Beyond privacy, Google gives a slight ranking boost to HTTPS sites, making secure certificates a two-fold win for UX and search visibility. In the UK, GDPR also requires you to protect personal data in transit without a valid TLS certificate, you risk non-compliance and potential fines.
Best Practices and NCSC Guidelines
The National Cyber Security Centre lays out clear recommendations for modern encryption standards. Key points include:
- Adopt TLS 1.3
The latest protocol version offers stronger security and faster handshakes. If your hosting doesn’t support TLS 1.3 yet, ensure at least TLS 1.2 is enabled with up-to-date cipher suites. - Disable obsolete protocols
Switch off SSL 2.0, SSL 3.0 and TLS 1.0/1.1 these legacy versions have known vulnerabilities. Also remove weak ciphers like RC4, 3DES and EXPORT variants. - Use strong cipher suites
Prioritise AEAD ciphers (for exampleTLS_AES_128_GCM_SHA256) that combine encryption and integrity checks. Avoid block-cipher modes prone to padding or oracle attacks.
For a deeper dive, see NCSC’s guidance on using TLS to protect data.
Managing Certificate Lifecycles
TLS certificates typically expire every 90 days to a year, so staying ahead of renewal deadlines is crucial:
- Automate renewals
Tools like Certbot let you schedule daily checks and automatic renewals. A command such as:certbot renew --quiet --deploy-hook "systemctl reload nginx"ensures your server always presents a valid certificate without manual intervention.
- Monitor expiry dates
Add calendar reminders 30 days before a certificate’s expiry date. Alternatively, services like Let’s Encrypt or your hosting control panel may email you alerts. - Revoke and reissue compromised certs
If you suspect a private key has been exposed, revoke the affected certificate immediately and issue a new one. Document the incident and update any pinned configurations.
By following these steps, you’ll maintain an up-to-date, secure TLS/SSL setup that protects your visitors, boosts SEO and keeps you in line with best practices from the NCSC.
8. Ensure Data Protection Compliance and Breach Reporting
Data protection isn’t just a box-ticking exercise it’s a legal obligation under UK GDPR, and failing to comply can lead to hefty fines and reputational damage. Any incident that leads to loss, unauthorised access or corruption of personal data must be assessed promptly. A clear breach-reporting process not only keeps you on the right side of regulation but also shows customers that you take their privacy seriously.
Overview of Legal Requirements
Under UK GDPR, a “personal data breach” occurs when personal information names, email addresses, payment details or any other identifying data is accidentally lost, stolen, altered or disclosed without permission. Once a breach is suspected, you must:
- Conduct a rapid risk assessment to evaluate the likelihood and impact on individuals.
- Determine whether the breach poses a risk to people’s rights and freedoms.
- Decide if the breach is “notifiable” (i.e. serious enough to report to the regulator).
If your assessment shows a risk, you have 72 hours from the moment you become aware of the breach to notify the Information Commissioner’s Office.
How to Report Personal Data Breaches
When reporting a breach to the ICO, gather the following information:
- A description of the breach, including the date and nature of the incident.
- The categories and approximate number of individuals affected.
- The type of personal data involved (for example, names, contact details or payment information).
- Measures you have taken (or plan to take) to contain and rectify the breach.
- Contact details of your data protection officer or relevant point of contact.
Submit your report through the ICO’s online portal at https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/. If you cannot provide all details within 72 hours, supply the missing information as soon as possible.
Record-Keeping and Documentation
Even if a breach isn’t notifiable, you must log every incident for accountability:
- Maintain an internal breach register with dates, descriptions and affected data categories.
- Document your risk-assessment process and the rationale behind your decision to report or not to report a breach.
- Record remediation actions and follow-up measures to prevent recurrence.
Good record-keeping not only demonstrates compliance during an audit but also helps you refine your response plan, making your next breach (hopefully) even less impactful.
9. Test Browser and Device Compatibility
Even the most polished design can falter if it doesn’t render correctly on someone’s device or browser. With a growing portion of traffic coming from smartphones, tablets and a variety of desktop browsers, it’s vital to ensure your site delivers a smooth, consistent experience everywhere. By verifying compatibility proactively, you’ll catch layout glitches, broken scripts or font issues before they frustrate visitors and potentially deter them from returning.
Why Cross-Browser Testing is Essential
Browsers interpret HTML, CSS and JavaScript in subtly different ways. A button that looks crisp in Chrome might shift out of place in Safari, while a feature that works in Firefox could break entirely in an older Internet Explorer or Edge build. These inconsistencies can disrupt navigation, distort images or even hide crucial calls to action. Given Google’s mobile-first indexing, any hiccup in a mobile browser can also harm your SEO. Regular testing guards against these surprises and helps you present a polished site to every user no matter their choice of browser or device.
Tools for Browser and Mobile Testing
Rather than scrambling to borrow devices, use cloud-based testing platforms that simulate a wide range of environments:
- BrowserStack lets you interact with real browsers and mobile devices in the cloud. You can test on the latest iOS Safari, Android Chrome, and more—all without maintaining your own device lab.
- LambdaTest supports cross-browser screenshots and live testing, along with automated testing workflows you can schedule daily or weekly.
- Browserling offers quick checks for common browsers, making it easy to spot glaring issues before they reach production.
These tools also allow you to record sessions, capture screenshots and log console errors information you can share with your developer or design team to expedite fixes. Automating compatibility checks on a weekly basis ensures that new code or plugin updates won’t introduce regressions.
Using Staging Environments Safely
Testing directly on a live site can be risky. Instead, clone your production environment into a staging area where you can trial updates without affecting real users:
- Duplicate your site: Use your host’s one-click staging feature or manually copy files and the database to a subdomain or separate folder.
- Sync data: Pull the latest content and database changes from production, so your staging site reflects real-world conditions.
- Run tests: Navigate through key pages—homepage, product listings, forms and checkout across browsers and devices. Look for layout shifts, JavaScript errors or broken media.
- Push live: Once you’ve confirmed everything renders and functions correctly, deploy your changes to the live site. Most systems allow you to merge code without overwriting new content.
By combining cloud-based browser testing with a secure staging workflow, you’ll catch compatibility issues early and maintain a consistent experience for every visitor—wherever they browse.
10. Plan and Review Maintenance Schedules
A maintenance routine only works if it’s structured and repeatable. By mapping out your tasks on a clear calendar and revisiting that plan regularly, you’ll ensure nothing slips through the cracks. A well-defined schedule lets you spread out the workload, align tasks with business rhythms and even delegate or outsource where needed.
Creating a Tiered Maintenance Calendar
Not every task needs the same frequency. Breaking downtime checks, content audits and legal reviews into weekly, monthly, quarterly and annual buckets helps you focus on what matters at the right time:
- Weekly
- Back up your site
- Apply minor software updates and patches
- Run security scans
- Monthly
- Test performance metrics (load times, uptime)
- Crawl for broken links and fix any 404s
- Review analytics (bounce rates, conversions)
- Quarterly
- Audit and refresh top-performing content
- Check cross-browser and mobile compatibility
- Update visuals and review design trends
- Annual
- Renew domains, SSL certificates and hosting plans
- Review privacy policy, terms of service and data-protection logs
- Conduct a full site health audit (security, performance, accessibility)
Use shared calendars or project-management tools Google Calendar, Trello or Asana to assign owners, set reminders and link to detailed checklists. Colour-coding each tier can make it easy at a glance to see what’s coming up next.
Prioritising Tasks Based on Website Type
Every site has different needs. A simple brochure site can get by with a lean schedule, while e-commerce or membership platforms demand more intensive checks:
- Brochure sites
Focus on quarterly content reviews and monthly uptime checks. - E-commerce stores
Add daily inventory backup, weekly cart-checkout tests and hourly uptime alerts. - Membership platforms
Include weekly user-data exports, monthly access-control reviews and quarterly GDPR audits.
Align your calendar with peak trading periods. If you run a Christmas promotion or a Black Friday sale, schedule extra performance testing and support in the lead-up to avoid downtime at critical moments.
Budgeting and Outsourcing Options
Allocating time is one thing budgeting for it is another. If you try to DIY everything, expect hosting-and-tool costs of roughly £50–£200 per year. But when your business grows, or you’d rather focus on sales and marketing, outsourcing becomes a smarter choice:
- Freelance or small agency (£300–£1,000/year)
Ideal for ongoing backups, updates and basic monitoring. - Full-service maintenance packages (£500+/year)
Include priority security support, on-call fixes and detailed performance reporting.
Before you decide, list the tasks you’re comfortable handling versus those you’d rather hand off. Even a partial outsourcing model say, an agency handling security and uptime while you take care of content can free up internal resources and guarantee expert attention when problems arise.
By putting your maintenance schedule on paper (or in a shared dashboard), tailoring it to your site’s complexity and matching it to your budget, you’ll build a disciplined process that keeps your website secure, fast and aligned with your business goals.
Ensuring Your Website’s Long-Term Security
Website security isn’t a one-and-done job it’s a continuous cycle of protection, performance and compliance. By following the ten tasks outlined above, you’ll build a robust defence against data loss, downtime and compliance pitfalls. Think of your website maintenance checklist as an ecosystem: regular backups and updates feed into automated security scans, which in turn support uptime monitoring, link checks and content audits. Layering TLS configuration, GDPR breach processes and cross-browser testing ensures that every angle is covered, from technical hardening through to legal accountability and user experience.
Of course, every business has its own priorities. You might ramp up update frequency during a high-traffic sales period or tighten your breach-reporting process when handling particularly sensitive data. Whether you run a simple brochure site or a complex e-commerce platform, adapt this framework to match your team’s capacity and your customers’ expectations. Colour-coded calendars, shared checklists and clear ownership make it easier to stick to the routine and spot any gaps before they turn into crises.
If you’d rather focus on growth and leave the technical heavy lifting to a specialist, GFC Tech can help. Our Surrey-based digital marketing agency combines data insights with proven security best practices to keep your site safe, fast and compliant. Partner with us for bespoke website maintenance packages, ongoing support and peace of mind so you can spend less time troubleshooting and more time serving your customers. Reach out at gfctech.co.uk to find out how we can secure your website’s future.
Adam is a Founder of GFC Tech, a company dealing in SEO and website design and development services. Adam has been an SEO expert for the past 8 years and has been working with different companies in this field. He is an SEO consultant and a marketing strategist and works closely with his clients to ensure that his marketing plans and strategies provide them with the marketing advantages they need to grow their business. Adam’s main role is an SEO consultant, but he is also involved in all technical aspects. Adam also develops WordPress websites, designs them professionally and performs SEO for them so they can rank on the first page of google.
