Website maintenance cost: what the monthly fee should cover

What a website maintenance plan should cover, and how to compare quotes for hosting, updates, backups, page changes and response times.

On 10 September 2026, entry-level website maintenance cost $39 to $89 a month for one WordPress site at the two US providers I checked, £49 to £125 at the two in the UK and €25 to €90 at the three in the EU, with VAT on top in the UK and the EU.

The software decides the tier. A contact form and a dozen plugins fit an entry plan. A checkout with customer accounts needs a tier that lists shop support, which at one UK care firm means £149 a month instead of £49.

How much does website maintenance cost per month?

In euros, the cheapest paid maintenance plans for one WordPress site from seven US, UK and EU providers ran from €25 to about €146 a month before VAT on 10 September 2026; the dearest reached €460. The spread comes from how often updates run, whether a shop is supported and how many hours of a person's time are included.

One-site maintenance prices from each provider's own page, read on 10 September 2026; free tiers and hosting-only plans are left out. Euro figures use the ECB reference rates of 9 September: $1.1652 and £0.85898 to the euro.
Provider, marketCheapest paid plan, a monthDearest plan, a monthWorth knowing
Freelancer, Spain€25 + VAT€59 + VATMonthly backups; each restore costs €50
WordPress care firm, US$39 (about €33)$99 (about €85)Five half-hour edits by a person from $99
WordPress care firm, UK£49 + VAT (about €57)£379 + VAT (about €441)Monthly updates; WooCommerce from £149
Web agency, Bulgaria€75 + VAT€146 + VAT3 hours of work, then €80 an hour
WordPress care firm, US$89 (about €76)$359 (about €308)Edits from $179, shop plugins from $239
Freelancer, Germany€90 + VAT€460 + VATMonthly updates; a €200 audit first
Web agency, UK£125 + VAT (about €146)£125 + VAT (about €146)Includes hosting, which alone is £25

On their cheapest plans, the UK care firm and both freelancers run routine updates once a month. The $89 and £125 plans run them weekly, and the $39 plan updates automatically, with a visual check of the pages afterwards. On a monthly plan, ask whether a security fix waits for the next routine. The German freelancer's page answers in writing: when a hole is found, the update goes in promptly.

I would pay for the update rhythm before anything else in that table. About half of the high-impact WordPress vulnerabilities published last year were exploited within 24 hours of going public, a security company that tracks them found, and a monthly routine can leave a site four weeks behind.

What should a monthly maintenance plan include?

A monthly plan should cover updates to the site's software, plugins and theme; security fixes as they are released; daily backups kept away from the site, plus a restore somebody has actually tried; an uptime check; the SSL certificate and domain renewals; and a stated allowance of small edits. Anything past that allowance is a change.

Monitoring tools automate the checks: UptimeRobot lists 60-second checks for €10 a month. A maintenance agreement should also specify who reviews alerts, investigates failures and restores the site when needed.

Ask how backups are tested. I would include a quarterly restore to a separate copy of the site, followed by checks of pages, forms and images. Record the date and outcome in the maintenance report.

For edits, I would take a defined number, such as the five of about 30 minutes each in the $99 US plan, over an unlimited number with no stated turnaround.

Is hosting included in website maintenance?

Some maintenance plans include hosting, and a good quote shows it on a line of its own. Hosting is renting the machine the site runs on, maintenance keeps its software current and recoverable, and changes are new work on the pages. One figure that blends the three cannot be set against any other quote.

The UK agency in the table prints both numbers on its price page: hosting alone is £25 a month plus VAT, and its care plan with that hosting included is £125, so the upkeep inside it, with half an hour of changes a month, costs £100.

Ask for the same split.

The hosting line is the easiest to price: a big managed WordPress host lists $35 a month, about €30, for one site. A .com domain is smaller still. From 1 November 2026 Verisign's wholesale fee, the floor under every registrar's price, rises to $10.97 a year, about €9.40. Changes are billed by the hour or the task: in Bulgaria, the agency in the table bills €60 to €80 for each extra hour.

We look after sites somebody else built, WordPress among them, as well as the ones we made: updates, backups and certificate renewals, either on our own servers or on the hosting a client already pays for. The domain, the code and the content stay the client's, and a move to another host comes with a full handover and our help setting it up. What goes into a build is on our web design page; what it should cost is in how much a website costs.

Why does a WordPress site cost more to maintain than a static one?

WordPress runs PHP, a database and plugins from many authors, and each of those has its own security clock. A static site, built as plain files with no database and no admin panel, has three: the domain, the certificate and the server's own updates. Maintenance follows the number of clocks, and so does the price.

The plugin clock is the loud one. A WordPress security company's yearly report counted 11,334 new vulnerabilities in WordPress, its plugins and its themes in 2025, about 31 a day, and put 91% of them in plugins against six in WordPress itself. Of the total, 1,966 were high severity, which the report defines as likely to be exploited in automated mass-scale attacks, and 46% had no fix on the day they were made public.

Automated attacks do not check a company's size.

WordPress keeps its own core current without being asked: minor releases install automatically, and new installations since version 5.6 take major releases too. Plugins wait for a person. The exception is a critical hole the WordPress security team patches from its side. An administrator can switch automatic updates on plugin by plugin, and until somebody does, each plugin stays at the version it had when last touched.

The PHP clock is quieter and has dates. PHP 8.1 reached end of life on 31 December 2025, 8.2 gets its last security fixes on 31 December 2026, and WordPress recommends 8.3 or newer. Yet WordPress.org's statistics, read on 10 September 2026, show about 38% of WordPress sites on 8.1 or older and 25% on 8.2, so from New Year's Day close to two in three will run a PHP version its own developers no longer patch, unless they move. With current plugins and theme, I would budget a morning for that move. With a theme untouched for three years, days. The theme is what breaks.

Put the clocks side by side and the plans follow. A small static site with no forms gets by on a plan a fraction the size of a shop's: its domain and certificate watched, an uptime check, a copy of the files kept elsewhere, and a few hours a year for changes. A site custom-coded on Node.js adds one runtime to move every two or three years, since each long-term-support release gets critical fixes for about 30 months. A WordPress brochure site needs weekly plugin updates and a supported PHP. A WooCommerce shop needs each update tried on a copy first, a test order afterwards, and backups at least daily, more often when orders come in all day, because an order placed between two backups exists only on the live site; a shop's other running costs are in how to build an online store. A platform with accounts and paid subscriptions, like Riomera, which we built in Bulgarian and English, adds two checks to every update: can people still sign in, and does a subscription payment still go through.

Agree on an update policy for each site. Automatic updates reduce the delay before a fix is installed, but changes to a theme or page builder also need layout checks. The plan should cover security fixes, testing and recovery if an update causes a problem.

What happens if nobody maintains a website?

A website nobody maintains looks fine for the first weeks. Then the failures arrive one at a time: a certificate that stopped renewing puts a full-page browser warning in front of every visitor, an unpatched plugin lets someone plant pages Google flags as hacked, and finally the domain lapses, taking the website and email with it.

  1. Certificate lifetimes are shrinking on a fixed schedule. Under the CA/Browser Forum's Baseline Requirements, a certificate issued since 15 March 2026 lasts at most 200 days, from 15 March 2027 at most 100, and from 15 March 2029 at most 47, which means at least eight renewals a year. Let's Encrypt moves from 90 days to 64 on 10 February 2027 and to 45 on 16 February 2028. A certificate installed by hand once a year stopped being possible in March.
  2. Someone gets in through an unpatched plugin. Google's Security issues report then flags hacked content or malware, affected pages can carry a warning in search results or a full-page one in the browser, and the review after a clean-up can take several days or weeks.
  3. The host retires an old PHP version, and the stale theme breaks.
  4. The domain goes last. For .com and other generic domains, ICANN's expired-registration policy requires reminders about a month and a week before expiry and another within five days after. Once the name expires, the registrar must switch off its DNS for at least the last eight days in which it can still be renewed, and the website and email stop working. After deletion, a 30-day Redemption Grace Period lets the registrar restore it at your request. Country domains such as .co.uk follow their registries' own rules.

Whose name should the accounts be in?

Every account the site depends on belongs in your business's name: the domain, Google Analytics, Search Console, the Google Business Profile and any hosting account you pay for, with the studio added as a user. On each service the owner decides who else gets in, so whoever holds that role holds the site.

A Business Profile manager can edit nearly everything but cannot add or remove users or delete the profile; Google Analytics needs the Administrator role to change users; in Search Console only owners add them. The studio needs the lower role on each. You need the top one.

At the registrar, check the record rather than the invoice: the registrant should be your business and the login yours, with the studio allowed to change DNS records. Where the studio hosts the site itself, the contract should give you the files and the database whenever you ask. Who owns the code in a website contract covers the rest.

Five clauses a maintenance contract needs

A maintenance contract should state how many hours until someone responds when the site is down; what counts as a change and what an hour of it costs; how often backups run and how you get a copy; how either side ends the contract and what is handed over; and, for a site that collects personal data, the data-processing terms.

That last one is law. A provider who can see the enquiries or orders on your site processes personal data for you, and Article 28(3) of the GDPR requires a contract setting out what is processed, why and for how long; the UK GDPR has the same article. Article 32 adds, among the measures appropriate to the risk, the ability to restore personal data in a timely manner and a process for regularly testing the measures. A restore test on a schedule answers both.

Is a maintenance plan worth paying for on a small website?

On a WordPress site with plugins, yes. Plugin security fixes come out every week, and the entry plans that apply them start at €25 a month in the EU, £49 in the UK and $39 in the US. A static site of a few pages has so little to break that a light arrangement covers it.

Can I look after a WordPress site myself?

Yes, if somebody on your side logs in every week, keeps a backup off the site and has restored it once. What you will miss is a person who knows, on a Sunday morning, why the checkout stopped taking payments after last night's update.

Does a plan cover cleaning up a hacked site?

Only if it says so. One US care firm lists daily security scans and clean-up in its $39 plan, a UK one includes the clean-up at £49 if something gets through while it looks after the site, and another US firm keeps complete malware removal for its $239 plan. Where a plan is silent, a clean-up is new work, quoted as a change.

What should I check today if my site has no plan at all?

Log in to your domain registrar and look at two things: whose name the domain is registered in, and whether auto-renew is on with a card that will still be valid on the renewal date. A broken site can be rebuilt from a backup. A domain that lapsed and was registered by somebody else cannot be rebuilt from anything.

Read next