← All posts
16 July 2026 · Updated 23 August 2026

WordPress maintenance services: what a monthly plan should include

What WordPress maintenance services cover: the 8 things a monthly plan should include, who sells them, what they cost, and what the cheap ones quietly skip.

Your WordPress site worked on launch day. Then the agency handed over the keys, the invoices stopped, and nobody has updated anything since.

That is how most WordPress problems start. Not with a clever attack - with a plugin that fell 14 versions behind while nobody was watching. We have handled 5,000+ support tasks for clients and agencies in the last 18 months, and the expensive incidents almost always trace back to the same thing: months of skipped maintenance, invoiced as “peace of mind” by a plan that only ran a backup script.

So here is the actual checklist. What WordPress maintenance services are, who sells them, what a monthly plan should include, what each item protects you from, what it costs, and the items cheap plans quietly leave out.

The short answer

WordPress maintenance services are the recurring work that keeps a live site secure and working, sold as a monthly plan. A complete plan covers eight things: core, theme and plugin updates tested on staging with a rollback path; automated offsite backups with tested restores; uptime, error, form and SSL monitoring; security patching and hardened access; performance checks; a budget of small content changes with a written response time; a monthly report of the work done; and documentation plus a clean exit. Market pricing runs from roughly 20 EUR a month for automated-only plans to several hundred for a business-critical site with a named person and a stated response time. Managed hosting is not the same thing: it runs the server, and on the best-known managed host plugin and theme updates are a paid add-on, with a failed update handed back to you.

The reason the service exists at all is a gap in WordPress itself. WordPress does apply core updates automatically, but the official documentation is explicit about where that stops: “By default, automatic background updates only happen for plugins and themes in special cases, as determined by the WordPress.org API response” - that is, only for critical security patches the WordPress security team pushes out. Everything else waits for a human. And plugins are where the risk lives: 91% of the WordPress vulnerabilities disclosed in 2025 were in plugins (full figures below). So the part of your site carrying almost all of the disclosed vulnerabilities is precisely the part nothing updates on its own.

Who sells WordPress maintenance services, and what each one actually covers

The phrase covers three different products, and most of the confusion in this market comes from buying one while believing you bought another.

  • Managed WordPress hosting. The host runs the server, the PHP version and, usually, WordPress core updates. That is the server half of maintenance and it is real work. It is not the plugin half. WP Engine is the clearest example because its documentation is explicit: plugin and theme updates are a separate product, Smart Plugin Manager, which “can be purchased for Shared and Premium plans” and comes bundled only with certain higher plans. It runs a daily script, tests the result, and “if a plugin fails to update” it sends you a notification “so you can investigate”, after which “you will need to manually update the plugin or theme that causes the failure”. So even there, the update either lands automatically or lands back on your desk. Nobody there knows your site, and nobody owns the outcome.
  • A maintenance company or an agency care plan. The human layer on top of the host: updates tested on staging before production, backups someone has restored, monitoring with a person on the other end, a budget of small changes, and a report. This is what the rest of this article describes, and it is the only one of the three where a named person is accountable for the site working on the first of next month. Agencies also buy this wholesale and resell it; the mechanics are in reselling care plans under your brand.
  • A freelancer or your own team. Exactly the same work, sold as hours rather than as a plan. It works while the person is available and stops the week they are not, which is why so many sites arrive at an agency with a year of neglect behind them and a freelancer who changed jobs.

The practical test when reading any offer: find the sentence that says who updates plugins and themes, who checks the site afterwards, and who you call when it breaks. If the answer to any of the three is “you”, you have bought hosting or a tool, not a maintenance service.

Updates - tested, not just clicked

Every maintenance plan says “updates”. The question is how they happen.

Clicking “update all” on a live site is not maintenance, it is gambling with a business asset. A plugin update can conflict with your theme, your page builder or another plugin, and the first person to find out is a customer looking at a white screen.

The version of this that works: updates run on a staging copy of the site first, get checked, and only then touch production. That is how we run it, and it is why an update has never taken a client’s business offline on our watch. If a plan does not mention staging, ask where updates are tested. “We monitor after updating” means your live site is the test environment.

This includes PHP. Hosts bump PHP versions on their own schedule (WordPress itself currently recommends PHP 8.3 or greater), and a site that was never tested against the new version finds out in production. A database update loop or a frozen, expired page builder licence is the kind of thing that surfaces exactly then.

Two more words to look for in the updates section of any plan: rollback and testing. When an update goes wrong despite staging, there has to be a known path back to the last working state, not an all-nighter. And after every update round, someone should check the things that earn money - forms submit, checkout completes, booking works. An update that “succeeded” while silently breaking the contact form is worse than no update at all.

Backups that someone has actually restored

Everyone has backups. Almost nobody has tested a restore.

A backup you have never restored is a hope, not a backup. The checklist here is short and unforgiving: backups run automatically, they are stored offsite (not on the same server that could die), they cover both files and the database, and someone has performed a real restore from them recently enough to know it works and how long it takes.

Ask a provider “when did you last restore a site from backup, and how long did it take?” A good answer is specific. A bad answer is “our host handles that”.

Monitoring - uptime is the minimum

Uptime monitoring tells you the site is down. Useful, but it is the smallest part.

A plan should also watch for the quieter failures: error logs filling up, forms that stopped delivering, checkout or booking flows breaking, SSL certificates about to lapse, disk quotas filling. These do not take the site down - they just quietly cost money until a human notices. In our experience the silent form failure is the worst of them, because the site looks fine while leads go nowhere.

Security - patching, hardening, and honesty

Most sites do not get hacked by geniuses. They get hacked by neglect: a disclosed vulnerability in an outdated plugin, exploited by a bot that scans half the internet for it.

The numbers say exactly that. Patchstack logged 11,334 new WordPress vulnerabilities in 2025 - up 42% on the year before, 91% of them in plugins, and only 6 in WordPress core itself (all low risk). The core is fine; the plugins nobody updates are the attack surface. Sucuri’s remediation data matches from the other side: 39.1% of infected CMS sites were running outdated software at the time they were compromised.

The security section of a real plan is mostly discipline: security releases applied promptly (this is where staging-tested updates pay off - you can apply them fast because you can apply them safely), admin access limited and behind two-factor authentication, credentials in a password manager rather than an email thread, and login endpoints protected from brute force.

What it is not: a security plugin installed and forgotten. A firewall plugin on a site running plugins from 2021 is a lock on a door with no wall.

Performance upkeep

Sites slow down over time - plugins accumulate, databases bloat, image libraries grow, caches misbehave after updates. A maintenance plan should hold the line: periodic checks against Core Web Vitals, database cleanup, and a look at what changed whenever the numbers drift.

This does not need to be a monthly performance project. It needs to be someone noticing the site got slower before your customers and Google do.

Small changes, with a real response time

The item that separates a maintenance plan from a monitoring subscription: a human who makes the small changes that pile up - a price update, a new team member, a section swapped on the homepage - with a defined response time, not “when we get to it”.

Our plans include a budget of small content changes, and urgent edits are typically turned around in 1-2 hours during working hours. Whatever provider you pick, get the response time in writing. “Fast” is not a number.

Know the boundary too, so quotes stay comparable: maintenance is not custom development, a redesign, new features or an SEO campaign. Those are projects with their own scope and price. A provider who blurs that line in the sales call will blur it on the invoice.

A report - the receipt for the invoice

Every month you pay for work you mostly cannot see. The proof it happened is a report: which updates were applied, backups taken and verified, incidents caught, what changed in performance, hours used from the change budget.

It does not need to be long - one page is fine. But if a provider sends no report at all, you are not buying maintenance, you are buying a promise. We put numbers on everything for a reason; ask your provider to do the same.

What WordPress maintenance services cost

Nobody publishes numbers, so here are the shapes the market actually sells in. These are going market ranges, not our rate card, and they exist so you can read any quote you are handed.

  • Automated-only - roughly 20 to 50 EUR a month. A script runs updates and backups on a schedule. Nobody checks the result, and there is no staging. Fine for a hobby site, wrong for anything that takes payments or leads.
  • Standard managed care - roughly 60 to 200 EUR a month. Staging-tested updates, monitored offsite backups, security patching, a small change budget, a monthly report. This is where most business sites belong.
  • Business-critical and eCommerce - roughly 200 to 600 EUR a month. Everything above plus faster response times, checkout and payment-gateway testing after every update round, and someone who knows the site by name. A WooCommerce store has more that can break and more that breaking costs.

Three things move a quote inside those bands, and none of them are visible on a feature list: whether updates are tested on staging before production, whether a named person owns your site instead of a ticket queue, and what response time is actually written down. A plan that skips all three is genuinely cheaper, and the saving lasts exactly until the first incident.

One number worth doing yourself: take your standard care quote, multiply by 12, and compare it to what one day of downtime, one lost checkout weekend, or one malware cleanup and reindex costs your business. In our experience that comparison ends the pricing conversation faster than any feature list.

Agencies reselling care under their own brand buy at partner rates and mark them up; we published those numbers separately in white label WordPress development pricing and the mechanics in reselling care plans under your brand.

What the cheap plans skip

Reading a cheap plan’s feature list, notice what is missing rather than what is there. The usual gaps:

  • Staging. Updates go straight to production, untested.
  • Restore testing. Backups exist; nobody has ever restored one.
  • A named person. You get a ticket queue, and every request is handled by someone who has never seen your site before.
  • PHP and hosting-level issues. “We maintain WordPress” quietly excludes the server it runs on.
  • An exit. No documentation, no handover, access held hostage. Leaving is made expensive on purpose.

None of these show up as problems in month one. All of them show up eventually.

When you don’t need a maintenance plan

Honesty over upsell: not every site needs one.

A hobby site with no business function can run on auto-updates and an occasional manual check - worst case, you lose a hobby site. A site already scheduled for replacement needs a freeze and a rebuild plan, not a retainer; sometimes the right call is leaving WordPress altogether. And if you have in-house developers who actually own the site, a plan duplicates what you are paying them for.

For everything in between - any site that generates leads, sales or credibility - the math is simple: a year of maintenance costs less than one serious incident. We have cleaned up enough of those incidents to publish that as fact, not fear.

The checklist, in one list

What a monthly WordPress maintenance plan should include:

  1. Core, theme and plugin updates, tested on staging, with a rollback path
  2. Automated offsite backups, files and database, with tested restores
  3. Uptime plus error, form and SSL monitoring
  4. Security patching, two-factor access, brute-force protection
  5. Performance checks against Core Web Vitals
  6. A budget of small content changes with a written response time
  7. A monthly report of what was actually done
  8. Documentation and a clean exit - your site, your access, your code

If your current plan covers all 8, keep it. If it covers 2, you now know what the invoice is actually buying.

Want the 8 items handled without chasing anyone? That is what our care plans are - month to month, no lock-in, and we take over sites we didn’t build after a short audit.

Tell us what’s broken.
We’ll tell you the truth.

Book a free call →
Reply within one business day · EN / LV
↑↓ navigate · ↔ open · esc close