Ask ten agencies what's in their website maintenance plan and you'll get ten different answers, most of them vague. "Updates and support." "Ongoing care." "Peace of mind." Then a client's site goes down on a Saturday and everyone discovers, at the same moment, that nobody agreed on whether Saturday was covered.
A maintenance plan is a contract about what happens when something breaks. Written well, it prevents the argument. Written badly, it is the argument.
What actually belongs in the plan
Six categories cover nearly everything worth putting in writing.
Software updates. On WordPress this is the bulk of the work: core, themes, and plugins, plus the testing that catches what an update broke. The part most plans skip is the rollback commitment. Say who reverts a bad update, and how fast.
Security. Firewall and malware scanning, monitoring, patch response time for disclosed vulnerabilities, and (this is the one people leave out) what happens if the site is actually compromised. Cleanup is either in scope or it's a separate bill. Decide before it happens, because a hacked site is a terrible time to negotiate.
Backups. Frequency, retention, where they're stored, and how fast a restore happens. "We take backups" is not a commitment. "Nightly, kept 30 days, restored within four business hours" is.
Uptime and performance monitoring. What's watched, how often, who gets alerted, and what response time you're promising. Distinguish "we notice" from "we fix," because clients assume those are the same thing.
Content changes. The single biggest source of scope creep. Most plans include a monthly allowance of small edits, and most plans fail to define "small." Use hours, not adjectives. Two hours a month is unambiguous; "minor updates" is a future disagreement.
Reporting. A monthly note covering what was updated, what broke, what got fixed, and how the site performed. This is the line item that makes the invoice make sense. Skip it and the client sees a charge with nothing attached.
What it costs
Roughly where the market sits in 2026, for a standard business site with no e-commerce:
- $50 to $100 a month. Updates, backups, uptime monitoring. Largely automated, minimal human time, no real content allowance.
- $150 to $350 a month. The above plus security tooling, a content allowance of an hour or two, and monthly reporting. Where most small business plans land.
- $500 to $1,500 a month. Adds performance work, SEO monitoring, meaningful content hours, and a real support SLA. Priced for sites that produce revenue directly.
- $2,000 and up. E-commerce, complex integrations, or compliance requirements, where downtime has an hourly cost the client can actually name.
Underneath any of these sits the hard cost. A production WordPress site typically runs $300 to $500 a year in plugin licenses, $400 to $3,600 in managed hosting, and $250 or so in security and backup tooling. Call it $1,000 to $4,000 annually before a person does anything. If you're an agency, that's your floor, and pricing a plan without knowing it is how the maintenance line quietly turns into a loss.
If you're the agency: how to price it
Add your hard cost per site. Add the support hours you actually spend, measured rather than estimated. Multiply by three.
The multiplier covers the month a client needs six hours instead of one, funds the account management that prevents churn, and leaves profit. Price at 1.5x and you're running a help desk that breaks even.
Two things worth doing regardless of the number. Define the content allowance in hours so overage is a calculation rather than a debate. And sell the outcome, not the task list, because nobody has ever been excited to buy plugin updates. They're buying a site that keeps working and keeps producing leads.
If you're the client: what to ask
Four questions surface most of what a vague plan is hiding:
- What's the response time when the site goes down, and does it apply on weekends?
- If the site is hacked, is cleanup included or billed separately?
- How many hours of content changes are included, and what's the overage rate?
- If we leave, do we get the site, the domain, and the backups?
That last one matters more than it sounds. Some arrangements are structured so leaving means starting over, and you want to find that out while you're happy rather than while you're not. If you do end up moving, the migration checklist covers how to do it without losing your rankings on the way out.
The part worth questioning
Most of what a WordPress maintenance plan covers is work created by the platform itself. Plugin updates exist because there are plugins. Version conflicts exist because a dozen independent teams ship on their own schedules into the same site. Security patching is relentless because WordPress runs a huge share of the web and gets attacked accordingly. You're paying a person to manage complexity the architecture generates.
That's the assumption we built BrightSite against. Hosting, SSL, backups, security, updates, forms, analytics, and session replay are part of the platform rather than assembled from vendors, at a fixed $39, $79, or $149 a month per site. There are no plugins to update, so there's no update queue to maintain.
It doesn't eliminate maintenance as a category. Content still needs writing, pages still need building, and performance still needs attention. What it removes is the part that exists only to keep the software from falling over, which for most sites is the bulk of the plan.
If you're on WordPress and it's working, treat this as an argument to know your number rather than an argument to move. Add up the licenses, the hosting, and the hours, and compare it against what the plan is producing. We wrote a fuller breakdown of that math in the real cost of WordPress maintenance. Whichever direction it points, the number is worth having.