A cron job running updates overnight and a senior developer watching your site are both sold as “WordPress maintenance.” Here’s the actual calendar of work behind the name, what DIY vs a plan vs an agency retainer really costs, and the failure modes that turn a skipped update into a rebuild.
WordPress maintenance is the recurring technical work that keeps a live site secure, fast, and functional after launch, applying updates, verifying backups, watching uptime and performance, and catching the small breakages before a visitor does. That’s different from a support or care plan, which is the commercial package a plan wraps around that work, tiers, pricing, response times, and a change-hours allotment. This article is about the work itself: what actually gets done, on what schedule, and what it costs by method.
I’ve been doing this long enough, north of 20,000 hours specifically inside WordPress, that the pattern behind almost every “my site suddenly broke” call is boring and repeatable. A plugin update collided with the theme. A host bumped PHP and something wasn’t ready for it. A certificate quietly expired over a long weekend. None of that is bad luck. It’s the predictable output of maintenance that didn’t happen, or happened without anyone actually watching the result.
Three lanes exist in this market, and they trade off the same thing in different amounts: your time versus your money versus how much gets caught before it becomes visible.
| Method | Typical cost | What’s actually included | Best fit |
|---|---|---|---|
| DIY / automated tools | Roughly $30-$50/month, per Codeable’s 2026 pricing breakdown | Automated updates, weekly backups, zero staging, zero human review of what changed | A low-stakes site where the owner can tolerate and troubleshoot the occasional break |
| A managed care plan | Quoted per site | Tested updates, offsite backups, security and uptime monitoring, Core Web Vitals checks, a monthly change allowance and direct support | A site that needs a real human accountable for it, not just automation running in the background |
| Agency retainer | $240/mo (Basic) to $1,000-plus/mo (Enterprise), per Codeable’s published tiers | Staged testing, visual regression checks, malware cleanup folded in, multiple planning meetings a month at the top tier | Larger sites or teams that need process and reporting layered on top of the core maintenance work |
Read the table by what’s missing, not just the price. The jump from $30 to $200-plus a month buys one specific thing: a person who actually looks at what changed, instead of a script that assumes it’s fine.
Four things move the number, and none of them is “how big is the website” on its own.
Automated-only plans apply an update and hope. Plans that cost more test it on staging first, because an untested plugin update is exactly how a working site becomes a broken one, and catching that before launch instead of after is most of what you’re actually paying for.
Every active plugin, every CRM or booking integration, is one more thing that has to be checked after every update cycle, not just left running. A site with five plugins and a site with forty are not the same maintenance job even at identical traffic.
Codeable’s own tiers move from 1 hour of dedicated development at $240/month to custom hours at $1,000-plus, and that hours figure, not the backup schedule, is usually what separates a budget plan from a serious one.
Order data, payment integrations, and inventory sync raise the stakes of every update, which is why WooCommerce-specific maintenance retainers commonly run higher than a standard brochure-site plan, closer to $500-plus a month once real transaction volume is on the line.
Real maintenance runs on a schedule, not a whim. Here’s the cadence I work to, broken into what happens weekly, monthly, quarterly, and once a year.
Skip the quarterly and annual items long enough and you don’t notice for a while. Then a host forces a PHP bump, or a plugin nobody’s opened in two years turns out to be the one thing holding a feature together, and the small maintenance job becomes a bigger one.
Four failure modes account for most of the maintenance emergencies I get called into, and every one of them is boring, predictable, and preventable.
An update to one plugin quietly breaks another, or the theme, and the site throws a 500 error or a blank white screen. In my own troubleshooting work the pattern holds up every time: a corrupted .htaccess file, an exhausted PHP memory limit, or a plugin conflict, roughly in that order of likelihood. Reading the server’s error log before touching anything usually turns a twenty-minute guessing game into a two-minute fix, but that only works if someone’s actually watching for it.
Hosts retire old PHP versions on their own schedule, not yours. PHP 8.1 reached end of security support at the end of 2025; PHP 8.2 is in its security-only phase through the end of 2026, per the official PHP support timeline. A theme or plugin built against an older PHP version can fail outright, or fail silently, the moment a host forces the bump, and finding out during a forced upgrade is a worse day than finding out during a scheduled quarterly check.
A plugin with no recent update and a quiet support forum isn’t broken yet. It’s a liability waiting on the next core update, the next PHP bump, or the next disclosed vulnerability it will never get patched for. I’ve stripped an entire two-thousand-product store out of years of accumulated page-builder shortcode debt after that exact kind of lock-in quietly capped what the site could even do; by the time anyone noticed, it wasn’t a small fix anymore.
Most WordPress sites run on Let’s Encrypt certificates, which are valid for 90 days and renew automatically, when the automation is actually working. Let’s Encrypt itself is moving toward 45-day certificate lifetimes industry-wide, which means that renewal automation runs, and can silently fail, roughly twice as often going forward. An expired certificate doesn’t creep up on you the way a slow performance drift does. It just breaks the site behind a browser warning, all at once, usually noticed by a customer before it’s noticed by you.
Maintenance keeps a site running as-is. It can’t fix a site that’s structurally behind, and the line between the two is usually clear once you’re looking for it.
None of that should get discovered mid-crisis. It’s exactly what the quarterly and annual items on the maintenance calendar above are for, catching the moment maintenance stops being the right tool before it becomes an emergency instead of a plan.
Match the method to what the site’s actually worth to you. A low-stakes site can genuinely run on DIY automation. A site you depend on needs a person accountable for it, which is what a care plan is actually for, tested updates, real backups, and someone who answers when something breaks. For the plan side of this, get in touch and I will tell you honestly what fits, or whether you need one yet.
If your site’s already past what maintenance can fix, an unsupported PHP version, a plugin nobody maintains anymore, or a platform that’s the actual constraint, that’s a different conversation. WordPress redesign covers the rebuild path; WordPress migration covers moving to better infrastructure entirely. Not sure which one you’re looking at? Get in touch and I’ll tell you honestly which bucket your site is actually in.
Quick answers to what people ask most about WordPress maintenance services.
Browse the services or book a consultation.
All services →Enter your website and get a free 60-second performance, SEO & accessibility report.
~60 seconds · No login