A website gets budgeted once, as a project. Then it goes live and quietly becomes an operational responsibility that nobody was assigned and nobody costed. Six months later there is a plugin update that has been waiting since spring, a contact form that stopped emailing in March, and an owner who assumes the web designer is "keeping an eye on it" while the web designer assumes the project ended at handover.
This is not a technical problem. It is an ownership problem, and it is solved the same way you solve any other recurring operational task: list the work, decide who does it, and price the decision honestly.
First, the work nobody lists
Website upkeep sounds vague until you write it out. For a typical small-business site, the recurring job is roughly this:
Weekly or fortnightly - Apply security patches to the platform, plugins and theme — after checking they do not break anything. - Confirm backups actually ran and are stored somewhere other than the website's own server. - Glance at uptime and error alerts.
Monthly - Test the contact and enquiry forms end to end — that they submit and that the email arrives. - Check for broken links and missing images, especially after content edits. - Review the site's speed on a phone, not just a desktop. - Review who has administrator access and remove anyone who no longer needs it.
Quarterly - Restore a backup somewhere safe to prove the recovery path works. - Check what is expiring: domain, TLS certificate, premium plugin and theme licences. - Review the platform and server software versions that are approaching end of support.
As needed - Content edits, new pages, seasonal changes. - Fixing whatever broke, whenever it broke.
Call it two to four hours a month when nothing goes wrong. The variance is the point: the median month is small and the bad month is enormous.
The three ways to cover it
1. Do it yourself
Works when: the site is simple, the person doing it is genuinely comfortable with it, and the business does not depend on the site being up at 2am on a Saturday.
Real cost: rarely the two hours. It is the context-switching — stopping revenue-generating work to investigate why the update screen is showing an error — and it is the tail risk. The failure mode of DIY is not bad work; it is skipped work. Everyone maintains diligently for two months and then a busy quarter arrives.
Honest test: has the routine above actually happened in each of the last three months? If not, you are not doing DIY maintenance. You are doing nothing and paying for it in instalments.
2. Call someone when it breaks
Works when: you have a trusted freelancer or agency who answers, and the site is not commercially critical.
Real cost: this is the most expensive model per incident and the cheapest per month, which is exactly why it feels affordable and behaves badly. Hourly billing quietly discourages preventative work — nobody bills you for the update that stopped a problem happening — so you only ever pay for the expensive end of the curve. Add the wait: an emergency competes with everyone else's schedule.
Honest test: how long did it take to reach your person the last time something broke, and was that acceptable?
3. A fixed monthly care plan
Works when: the site is a real business asset — it generates leads or revenue — and the routine needs to happen whether or not anyone remembers.
Real cost: a predictable fee for a defined scope, plus the discipline of reading what is actually in that scope. The trade-off is that you are paying in quiet months for the guarantee of attention in bad ones. That is insurance, and like insurance it is worth it exactly in proportion to what an outage would cost you.
Honest test: what does a day of downtime cost your business? If the answer is "a lot", the case is already made. If the answer is "very little", a care plan may be an honest luxury.
The four questions that actually decide it
- Does the site produce revenue or leads? If enquiries, bookings or orders arrive through it, the site is operational infrastructure, not marketing collateral. Infrastructure gets a maintenance owner.
- How complex is it? A five-page brochure site is genuinely low-risk. Ecommerce, memberships, booking systems and anything integrated with your other software are not — they have more moving parts and more ways to fail silently.
- Who else could do it if you were unavailable for a month? If the answer is nobody, you have a single point of failure who also has a day job.
- What is your honest tolerance for downtime? Not the aspirational answer. If the site being down for a working day would cost you real money or credibility, buy the response, not the good intentions.
The same logic applies to every recurring task in a small business — our guide to hiring, outsourcing or automating works through the general version, and the operations guide covers writing the routine down so it survives whoever leaves.
If you buy a plan, buy it on scope
Care plans are priced similarly and scoped wildly differently. Compare on the scope, and get these in writing before you compare a single price:
- What is included, itemised. Updates, backups, uptime monitoring, security, performance, and how much content-edit time — with the hourly rate for anything beyond it.
- Where backups are stored and how far back they go. Off the site's own server, or it is not a backup.
- Whether restores are tested, and how quickly a full restore can be completed.
- Whether there is a staging environment. This is the difference between "we test updates" and "we hope".
- What response actually means. A stated response window is only meaningful with the hours it applies to and what counts as an emergency.
- What you get if you leave. Your backups, your licences, your credentials, exported and handed over. A provider who is vague here is describing a hostage situation politely.
- What reporting you receive, and how often.
For a WordPress site, WPCare is a reasonable example of the fixed-fee model to hold that checklist against. Two things about how it presents itself are relevant to the comparison above rather than to any claim about quality: it publishes flat monthly pricing explicitly in contrast to hourly agency billing — which is the incentive problem in model 2 — and it separates its scope into named lines (general site maintenance, WooCommerce support, server management, speed optimisation, and emergency response) rather than selling one undifferentiated "support" bundle. Both of those make a scope comparison possible, which is the thing that is usually hardest when you are collecting quotes.
Run the checklist against any provider you consider, including that one. The good ones answer in specifics; the rest answer in adjectives.
FAQ
How much should website maintenance cost? There is no single answer, and any figure quoted without a scope is meaningless. Price the scope instead: a brochure site needing patching and backups is a fundamentally smaller job than a store with a checkout, integrations and a database that grows every day. Get two or three quotes on the same written scope and the comparison becomes real.
Isn't this what my hosting company does? Hosts look after the server, and generally not the application on top of it. Plugin updates, theme conflicts, form deliverability, content edits and the site's own security posture usually sit with you unless your plan says otherwise in writing. Check what your plan actually covers before assuming.
Can't I just turn on automatic updates? You can, and for security patches it is usually the right call. The gap is verification: automatic updates apply changes without anyone checking that the forms still send, the checkout still completes, and the layout has not shifted. Automation covers the applying, not the checking.
We rebuilt the site last year. Do we still need this? Yes — a new site is up to date on day one and no more resistant to change than an old one. Maintenance is not a symptom of a bad build; it is the cost of running software connected to the internet.
The bottom line
Decide who owns website upkeep the same way you decide who owns any recurring task: write out the work, compare the three delivery models honestly, and let the four questions above pick one. If the site earns money and nobody in-house will reliably do the routine, buy a fixed-fee plan and choose it on scope — for a WordPress site, WPCare is one to compare against the checklist above, alongside whoever built your site in the first place.