← All resources

Website maintenance: what a realistic retainer should actually include.

A lot of "maintenance plans" are just hosting with a markup. Here is what should genuinely be in scope.

Website maintenance retainers vary wildly in what they actually deliver, from a genuinely useful ongoing partnership to little more than a hosting bill with a support label stuck on it. Knowing what should be included makes it much easier to tell which one you are being offered.

The baseline: keeping the lights on

At minimum, a maintenance plan should cover dependency and security updates, uptime monitoring, backups with periodically tested restores, and SSL certificate renewal. This is the unglamorous, non-negotiable floor — without it, a site slowly accumulates security and reliability risk regardless of anything else.

What separates a real retainer from a markup

A genuine maintenance retainer includes a defined number of support hours each month for bug fixes and minor changes, a monthly report covering uptime, performance and what was actually done, and a named point of contact rather than an anonymous ticket queue. Most plans include somewhere between one and four hours of included changes a month, with anything beyond that quoted separately.

What should be scoped separately

New features, redesigns, content migrations and anything beyond genuinely minor changes should be quoted and scoped as their own small project, not silently absorbed into — or silently excluded from — the retainer. A good agency will tell you clearly where that line sits before you sign.

Questions to ask before signing one

What specifically counts as a "minor fix" versus a billable extra? What happens if you exceed the included monthly hours? And who actually does the work — the same team that built the site, or a separate support desk with no context on it?

And one question about the floor itself: how quickly do security updates actually get applied? Patchstack recorded 11,334 new vulnerabilities in the WordPress ecosystem during 2025, a 42% rise on 2024, with 91% of them in plugins rather than core. A plan that patches monthly is a different product from one that patches on disclosure, and the price difference between the two is usually smaller than the gap in exposure.

The upgrades nobody scheduled

The part of maintenance that catches people out is not an attack — it is the calendar. Every runtime and framework underneath your site has a published end-of-life date, and when it passes, security patches simply stop being written. Node 18 stopped receiving security support on 30 April 2025 and Node 20 on 30 April 2026. A site still sitting on either is running unpatched by definition, however diligently everything above it has been looked after.

This is the cleanest test of whether a retainer is real or decorative. A markup plan bills monthly and leaves the runtime exactly where it was on launch day, so four years of deferred upgrades arrive as one invoice, usually wearing the words “the site needs rebuilding”. A real retainer knows those dates in advance, budgets the version bump *before* support lapses, and treats it as scheduled work rather than an emergency. It is a fair question to put to anyone quoting you: which major version are we on, and when does its support end? If nobody can answer, that is the answer.

Sources

The vulnerability figures, market retainer rates and support-lifecycle dates above come from these, checked August 2026. The scope checklist is our own.

Frequently asked questions

Wondering if your current maintenance plan is actually enough?

Send us what is currently included and we will tell you honestly if there are gaps.