Website maintenance is the least glamorous line on any digital budget and the one most likely to be quietly worthless. Every agency offers a package, most describe it in the same four bullet points, and the difference between a tier that protects your business and one that runs an automated update and emails you a chart is not visible in the proposal. The distinction is worth caring about, because the failures maintenance is supposed to prevent are expensive and slow to detect: a broken checkout, a plugin conflict that blanks a template, an expired certificate, a form that silently stopped delivering. This guide sets out what the tiers actually contain, what drives the price, and the questions that separate real upkeep from a subscription.
What the tiers usually contain
Entry tiers are essentially insurance against catastrophe: offsite backups on a stated schedule, core and plugin updates, uptime monitoring, security patching and an SSL certificate that does not lapse. That is genuinely worth paying for, and it is also almost entirely automated, which is why it should be cheap. Middle tiers add human attention: someone checks that the site still works after updates, fixes small breakages, makes a defined number of content changes each month and watches page speed. Upper tiers add ongoing improvement, which is a different product altogether, covering conversion changes, new pages, accessibility remediation and performance work. The common mistake is paying a middle-tier price for entry-tier automation. Ask which specific tasks a human performs each month and how many hours are allocated, then judge the fee against that rather than against the bullet list.
The checks that actually matter
Three things break most often and are least often monitored. Forms are first: a contact or quote form that stops delivering can go unnoticed for weeks, and the only reliable defence is an automated submission test that alerts a person when it fails. Backups are second, and the question is never whether backups exist but whether a restore has been performed recently; an untested backup is a belief, not a safeguard. Performance is third, and Core Web Vitals give you a published, vendor-neutral way to measure it rather than relying on an agency's own dashboard. Ask for the restore test date, the form monitoring method and a current performance measurement, and you will learn more about a maintenance provider in five minutes than a proposal will tell you in ten pages.
What drives the price
Platform is the first driver. A static or headless site needs far less ongoing attention than a WordPress installation with two dozen plugins, and an e-commerce site with payment integrations needs more than either. Response commitment is the second: an agreement that promises attention within a business day costs a fraction of one guaranteeing an hour of response on a weekend, because the second requires cover. Included change hours are the third, and they are where most of the spread between quotes lives; a package with four hours of included work is a different product from one with none, even if both are described as maintenance. Buyers often purchase this alongside a broader website services retainer, since the same team that builds the site is usually cheapest to keep it running.
How to compare packages honestly
Normalise the quotes before you compare them. Write down, for each candidate, the backup frequency and retention period, whether restores are tested, the update cadence, what happens when an update breaks something, the number of included change hours, the response commitment and who is on call. Most proposals go quiet on at least two of those, and the silence is informative. Then ask the ownership question: where the backups are stored, whether you can download them, and what you receive on the day you leave. A maintenance arrangement that only works while you keep paying is not maintenance, it is a hostage arrangement with a friendly invoice.
Questions people ask about website maintenance packages
Is a maintenance package worth it for a simple brochure site?
Usually yes at the entry tier, and usually no above it. A small site still needs backups, patching and a certificate that renews, and those are cheap. Paying for included change hours you never use is the common waste. If you make edits twice a year, buy the protection and pay hourly for the changes.
How often should backups actually run?
Match the frequency to how much work you could stand to lose. A site that changes monthly is fine with weekly backups. A site taking orders needs daily at minimum and often continuous. What matters more than frequency is retention length and whether a restore has been tested, because a backup nobody has ever restored from is an assumption.
What should happen when an update breaks the site?
Updates should be applied to a staging copy first, checked, then promoted. If something breaks in production anyway, the provider should roll back from backup and tell you, without an argument about whose fault it was. Ask what the rollback procedure is and how long it takes; a provider without a clear answer applies updates directly to your live site.
Should maintenance and hosting come from the same supplier?
It is convenient and often cheaper, and it removes the finger-pointing when something breaks. The risk is concentration: if the same company holds your hosting, your domain, your backups and your code, leaving becomes hard. Keep domain registration and a downloadable copy of backups under your own control and the convenience costs you nothing.