Website Maintenance: What You Actually Need vs What You're Being Sold

Most maintenance plans bundle essentials with padding—here's how to tell which is which

Hosting & Reliability · · 4 min read

What Actually Needs Maintaining

A website maintenance plan should keep your site online, secure, and recoverable. The essentials are: your domain renewing on time, your SSL certificate staying current, security patches applied if your site runs software with vulnerabilities, backups that work when you need them, and someone who answers when something breaks. Everything else is either a convenience you're choosing to pay for or padding.

The confusion comes from the fact that maintenance plans bundle these essentials with services that range from genuinely useful to completely unnecessary, often at one flat monthly rate. You end up paying for things you don't need because they're wrapped with things you do.

The Non-Negotiables

Domain renewal is the foundation. If your domain expires, your site goes dark and your email stops. Worse, someone else can register it. A maintenance plan should track your renewal date and handle it before it lapses. If you're managing this yourself, set a calendar reminder for 60 days before expiration.

SSL certificate renewal keeps the padlock in your visitors' browser bar and keeps Google from flagging your site as "Not Secure." Most hosts now automate this with Let's Encrypt, which renews every 90 days. If your host or maintenance provider is charging separately for SSL renewal on a standard site, you're paying for something that should already be automatic.

Security updates matter if your site runs software—WordPress, Joomla, Drupal, or any CMS with plugins and themes. Those get patched regularly because vulnerabilities get discovered regularly. Applying those updates is real work, and it carries real risk if an update breaks something. A good maintenance plan tests updates on a staging copy of your site first, then applies them to the live site, then checks that everything still works.

Backups are worthless unless they've been tested. A maintenance plan should back up your site regularly—daily or weekly depending on how often it changes—and store those backups somewhere other than the same server your site lives on. More important: someone should occasionally restore a backup to make sure it actually works. We've inherited sites with years of corrupt backups that would have been useless in an emergency.

Uptime monitoring and response means someone gets an alert when your site goes down and actually does something about it. The monitoring itself is cheap and often automated. The response is what you're paying for—someone who knows where your site is hosted, has access to fix it, and will do that at 2am on a Saturday if that's when it breaks.

What's Often Padding

Monthly reports are a favorite line item. You'll get a PDF with uptime percentages, traffic charts, and maybe some security scan results. Most business owners glance at it once and delete it. If you're not reading the reports, you're paying for someone to generate them. Ask your provider if you can opt out and reduce the cost.

Content update allowances—"up to 2 hours of content changes per month"—sound useful but often go unused. If your site rarely changes, you don't need a monthly allowance. Pay for updates when you actually need them. If your site changes weekly, a retainer makes sense. Match the plan to your actual usage.

SEO line items with no deliverable are the worst offender. "Ongoing SEO optimization" or "monthly SEO maintenance" that doesn't specify what's being done or measured is usually nothing. Real SEO work has a scope: keyword research, page optimization, technical fixes, content strategy, link building. If your maintenance plan includes SEO, ask exactly what gets done each month and what you should expect to see change.

Plugin updates as a separate charge is double-dipping if you're already paying for security updates. Plugin updates are part of keeping a CMS site secure. They shouldn't be a separate line item.

Static Sites vs CMS: A Real Technical Difference

A static site—plain HTML and CSS files, no database, no server-side code—has a genuinely smaller maintenance surface than a WordPress or database-driven CMS. There's no software to update, no plugins to patch, no database to back up. You still need domain and SSL renewal, hosting, and backups of the files, but the security update burden disappears.

That's not a sales pitch for static sites. A CMS gives you the ability to update content yourself, add functionality with plugins, and scale complexity when you need it. But if you're paying $100/month for maintenance on a five-page static site that never changes, you're paying for work that doesn't exist. A static site should cost a fraction of what a CMS site costs to maintain.

Questions to Ask Your Provider

If you're already paying for maintenance, ask these questions:

  • What exactly is included each month, and what gets done even if nothing breaks?
  • Are backups stored off-server, and when was the last time you restored one to test it?
  • If my site runs a CMS, do you test updates on a staging site first?
  • What happens if my site goes down at night or on the weekend—who responds, and how fast?
  • Can I see a log of what was done last month?

If your provider can't answer these clearly, you're paying for a plan that may not do what you think it does.

What You Should Actually Pay For

Pay for the essentials: domain and SSL renewal, security updates if your site needs them, real backups, and someone on call when things break. Pay for content updates if you actually use them. Pay for performance monitoring if your site's speed matters to your business. Pay for real SEO work if you can see the scope and the results.

Don't pay for reports you don't read, allowances you don't use, or vague line items with no deliverable. A fair maintenance plan should cost in proportion to how complex your site is and how much it changes. A static brochure site might run $10–30/month for hosting and essentials. A WordPress site with plugins and regular updates might run $50–150/month depending on complexity and how much hand-holding you need. If you're paying more than that, make sure you know exactly what the extra money is buying.

The goal is to keep your site working and recoverable without paying for theater. If your current plan feels expensive and you're not sure what you're getting, you're probably right.

Common questions

How much should I pay for website maintenance?

A static brochure site typically runs $10–30/month for hosting and essentials like domain and SSL renewal. A WordPress site with plugins and regular updates usually runs $50–150/month depending on complexity. If you're paying significantly more, ask for a detailed breakdown of what the extra cost covers.

Do I really need a website maintenance plan?

You need the essentials covered: domain renewal, SSL certificate renewal, backups, and someone to call when things break. Whether you buy that as a plan or handle it yourself depends on your comfort level. If your site runs a CMS like WordPress, you also need security updates applied regularly—that's real ongoing work.

What's the difference between maintaining a static site and a WordPress site?

A static site has no software to update, no plugins to patch, and no database to back up—just HTML and CSS files. Maintenance is mostly domain renewal, SSL, hosting, and file backups. A WordPress site needs all of that plus regular security updates for WordPress core, plugins, and themes, which means more ongoing work and higher cost.

How often should my website be backed up?

It depends on how often your site changes. If you update content daily, back up daily. If your site rarely changes, weekly backups are usually fine. More important than frequency: backups should be stored off-server, and someone should occasionally test a restore to make sure they actually work.

Need a maintenance plan that makes sense?

We'll tell you what your site actually needs—and what it doesn't.