Website maintenance retainers vary wildly in what they actually deliver, from a genuinely useful ongoing partnership to little more than a hosting bill with a support label stuck on it. Knowing what should be included makes it much easier to tell which one you are being offered.
— Guide
Website maintenance: what a realistic retainer should actually include.
A lot of "maintenance plans" are just hosting with a markup. Here is what should genuinely be in scope.
The baseline: keeping the lights on
At minimum, a maintenance plan should cover dependency and security updates, uptime monitoring, backups with periodically tested restores, and SSL certificate renewal. This is the unglamorous, non-negotiable floor — without it, a site slowly accumulates security and reliability risk regardless of anything else.
What separates a real retainer from a markup
A genuine maintenance retainer includes a defined number of support hours each month for bug fixes and minor changes, a monthly report covering uptime, performance and what was actually done, and a named point of contact rather than an anonymous ticket queue. Most plans include somewhere between one and four hours of included changes a month, with anything beyond that quoted separately.
What should be scoped separately
New features, redesigns, content migrations and anything beyond genuinely minor changes should be quoted and scoped as their own small project, not silently absorbed into — or silently excluded from — the retainer. A good agency will tell you clearly where that line sits before you sign.
Questions to ask before signing one
What specifically counts as a "minor fix" versus a billable extra? What happens if you exceed the included monthly hours? And who actually does the work — the same team that built the site, or a separate support desk with no context on it?
And one question about the floor itself: how quickly do security updates actually get applied? Patchstack recorded 11,334 new vulnerabilities in the WordPress ecosystem during 2025, a 42% rise on 2024, with 91% of them in plugins rather than core. A plan that patches monthly is a different product from one that patches on disclosure, and the price difference between the two is usually smaller than the gap in exposure.
The upgrades nobody scheduled
The part of maintenance that catches people out is not an attack — it is the calendar. Every runtime and framework underneath your site has a published end-of-life date, and when it passes, security patches simply stop being written. Node 18 stopped receiving security support on 30 April 2025 and Node 20 on 30 April 2026. A site still sitting on either is running unpatched by definition, however diligently everything above it has been looked after.
This is the cleanest test of whether a retainer is real or decorative. A markup plan bills monthly and leaves the runtime exactly where it was on launch day, so four years of deferred upgrades arrive as one invoice, usually wearing the words “the site needs rebuilding”. A real retainer knows those dates in advance, budgets the version bump *before* support lapses, and treats it as scheduled work rather than an emergency. It is a fair question to put to anyone quoting you: which major version are we on, and when does its support end? If nobody can answer, that is the answer.
Sources
The vulnerability figures, market retainer rates and support-lifecycle dates above come from these, checked August 2026. The scope checklist is our own.
- Patchstack — State of WordPress Security in 2026 ↗
Annual whitepaper from a WordPress vulnerability intelligence provider: 11,334 new vulnerabilities disclosed in 2025 (+42% year on year), 4,124 of them serious enough to need mitigation rules, 91% in plugins and 9% in themes, with only 6 low-priority issues in core.
- ExpertLocal — Was kostet eine Digital-Agentur 2026? ↗
German market rates for ongoing work, including basic SEO retainers at €800–1,800 a month — useful for judging whether a maintenance quote is priced as a service or as a subscription.
- Let’s Encrypt — Documentation FAQ ↗
Certificate lifetimes and the case for automated renewal — the reason "SSL renewal" belongs in a retainer as monitoring rather than as a recurring manual task worth billing for.
- OWASP — Top 10 Web Application Security Risks ↗
The reference list a maintenance plan is implicitly defending against, including vulnerable and outdated components — the category most dependency updates address.
- endoflife.date — Node.js release support ↗
Node 18 security support ended 30 April 2025 and Node 20 on 30 April 2026; production applications should run only Active or Maintenance LTS releases.
— FAQ
Frequently asked questions
Wondering if your current maintenance plan is actually enough?
Send us what is currently included and we will tell you honestly if there are gaps.