What Website Support and Maintenance Actually Covers
Published on August 21, 2026
Most business websites are not maintained. They are launched, they work, and then nothing happens to them for two years until something breaks — and at that point the person who built it has moved on, the plugins are eleven versions behind, and the quote to fix it costs more than two years of looking after it would have.
This is not carelessness. It is that nobody explained what maintenance actually is, so it reads like an optional extra rather than the thing that stops the expensive version of this conversation.
So here is what it covers, what it costs, and how to tell whether you need it.
Why a finished website is not finished
A website is software. That sounds obvious written down, but it changes how you should think about it.
If your site runs on WordPress — and roughly four in ten websites do — it is built from a core platform, a theme, and some number of plugins. Every one of those is maintained by somebody else, updated on their schedule, and occasionally found to contain a security flaw that was there all along.
When that happens, the fix is published and so is the vulnerability. Automated scripts then go looking for sites still running the old version. Nobody targets your business specifically; a script goes looking across a million addresses and finds whoever has not updated.
That is the mechanism behind almost every small-business website compromise. Not a hacker deciding you are worth attacking. A script finding a door left open because nobody was checking the doors.
What maintenance actually covers
Different providers include different things, and the differences matter more than the price. Here is what a reasonable plan should contain.
Updates, tested before they go live
Core, theme and plugin updates applied on a schedule. This is the part everybody includes.
What separates a real service from a monthly invoice is testing. Updates get applied to a copy of the site first, checked, and only then applied to the live one. Skip that step and you eventually get the conversation that starts “we ran the updates” and ends “and now the checkout is broken”.
Ask any provider whether they test updates on a staging copy. The answer tells you what you are buying.
Backups you could actually restore
Daily, stored somewhere other than the same server as the website, and restored occasionally to prove they work.
That last part is the one people skip. A backup nobody has ever restored is not a backup, it is a file. The first time anybody finds out whether it works is the worst possible moment to find out.
Uptime monitoring
Something checking every few minutes whether the site is responding, and telling somebody when it is not.
Without it, you find out your site is down when a customer mentions it — which means it has been down for a while, and you have no idea how long.
Security monitoring
Watching for known vulnerabilities in what your site runs, and patching them when they appear rather than at the next scheduled update.
Most of the time this is uneventful. The value is entirely in the exceptions.
Performance checks
Sites get slower over time without anybody doing anything wrong. Content accumulates, images are uploaded at full size, a plugin gets added.
A monthly check against Google’s Core Web Vitals catches the drift while it is still cheap to fix. Left alone for two years, you are looking at a project rather than an adjustment.
A change allowance
Every site needs small changes. A price, a new page, an extra form field, a staff photo.
Individually these are twenty-minute jobs. What makes them expensive is the overhead of quoting each one, so a plan with an included monthly allowance for small changes usually saves more than it costs — and it means you stop putting off changes because raising them feels like a hassle.
Somebody who answers
The least technical item on the list and the one clients mention most.
What people actually want from maintenance is that when something is wrong, a message reaches a person who knows their site and replies within a day. Not a ticketing system. Not a queue. A reply.
What maintenance is not
Two things get confused with it, and knowing the difference stops you paying twice or assuming you are covered when you are not.
It is not hosting. Hosting is the server your site runs on — uptime at the infrastructure level, server-side backups, SSL certificates, and keeping the server itself patched. Maintenance is the software on top of it. Some providers bundle them and some do not, and you should know which you are buying.
It is not new development. A maintenance plan covers keeping the site working and making small changes. A new section, a redesign, or a new feature is a project, quoted separately. A provider who lets you slowly absorb development work into a maintenance retainer is either underpricing or about to disappoint you.
What it costs
Rather than a figure, here is how the pricing works — which is more useful, because it lets you judge a quote.
Maintenance is priced on how much site there is and how much it changes. A five-page brochure site that alters twice a year is a fraction of the work of an e-commerce store with weekly product updates and a checkout that cannot be down.
Anybody quoting a single figure for “website maintenance” without asking what the site is has not asked the questions that determine the answer.
Two things worth checking in any quote:
- Is it a fixed monthly fee, or a retainer of hours? A fixed fee means the provider absorbs a bad month. An hours retainer means you do.
- Is there a contract period? There is no technical reason for one. A provider requiring twelve months is protecting themselves against you leaving, which is worth knowing.
For comparison: the cost of recovering a compromised site — cleaning it, finding how it happened, restoring content, and dealing with Google flagging it as unsafe — routinely exceeds a year of maintenance. That is the actual calculation.
How to tell whether you need it
Three questions. If the answer to any of them is uncomfortable, you probably do.
When were the plugins last updated? If you do not know, and nobody is paid to know, the answer is likely to be whenever the site was built.
If the site went down tonight, when would you find out? If the answer involves a customer telling you, that is the gap.
If the site were compromised tomorrow, could you restore it? Not in principle — actually. Do you know where a recent backup is, and has anybody tried it?
What to do if you do not have it
Two options, and neither requires committing to anything immediately.
Check the basics yourself. Log in, look at whether updates are pending, find out whether backups are running and where they go. That tells you how urgent this is.
Or have somebody audit it. A proper look at what state the site is in — what is outdated, what is exposed, whether the backups work — tells you whether you have a problem worth paying to solve. Any provider worth using will tell you if the answer is that the site is fine.
If you would like us to look, our support and maintenance service starts with exactly that audit, and you get the findings whether or not you take a plan. Where the server itself needs looking after too, managed hosting covers that layer.
Either way, the worst outcome is the one where nobody looks until something breaks. That version is always more expensive than the alternative, and it always arrives at an inconvenient time.