Tag: Choosing

  • Do Websites Really Need Monthly Maintenance?

    Do Websites Really Need Monthly Maintenance?

    Start here

    1. 01Understand why this keeps coming up
    2. 02Work out where your site sits
    3. 03Decide what to do about it

    Why a launched site does not stay finished

    WordPress core, the theme and every plugin on a site are written and versioned independently. Each one ships on its own schedule, set by its own author, with no coordination between them.

    Core itself changed pace recently. As WordPress explained in A new cadence for WordPress core: “Starting in 2025, WordPress will move to a single major release per year, with WordPress 6.8 ‘Cecil’ marking the final major release for the calendar year.” The stated reason is “the energy and resources being diverted due to ongoing legal matters,” and the post frames the change as reversible: “If those lawsuits are dropped or resolved, we’ll revisit this cadence and strongly consider returning to a three-releases-per-year schedule.” Before this, the core release cycle handbook targeted roughly one major release every four months, alongside security and maintenance point releases as needed.

    Plugins and themes follow no such pattern. Some ship weekly. Others go years without a touch. When a vulnerability is disclosed in any one component, the patch that fixes it applies to that component alone. A fix sitting on the plugin author’s server does nothing for a site running the version from before the fix existed, because nobody there applied it.

    What actually breaks a site without upkeep

    Two failure modes account for most of what goes wrong on a site nobody maintains.

    The first is an unpatched security hole: a vulnerability gets disclosed, a patch exists, and the site never receives it. The second is a compatibility break: one component updates, another doesn’t, and the two stop working together. Neither requires an attacker with unusual skill or a site with unusual traffic. Both just require time passing with nobody checking.

    Where the vulnerabilities actually concentrate, from Patchstack’s tracking of the first six months of 2025:

    Component Count Share
    Plugins 3,044 89%
    Themes 386 11%
    Core 1 —

    Source: Patchstack, first six months of 2025. Vendor-tracked figure, not an independent industry consensus.

    A table showing that plugins accounted for 89 percent of new WordPress vulnerabilities disclosed in a six-month 2025 period, compared to 11 percent for themes and effectively none for core.

    Across the ecosystem, 6,700 new vulnerabilities were identified in that period, and 57.6% required no authentication to exploit.

    Patchstack is a commercial vulnerability-disclosure vendor, not a neutral industry body, and there is no independent figure to cross-check these numbers against. Read them as what one vendor’s tracking shows, not as an industry consensus. Even with that caveat, the shape of the finding matches the mechanism above: plugins carry almost all of the disclosed risk, because there are far more of them, written by far more separate authors, patched on far more separate schedules than core ever has to coordinate.

    Does a small brochure site really need this

    Not every site carries the same exposure. A low-traffic site with minimal plugins, no forms handling sensitive data and no e-commerce carries meaningfully lower risk than one running a checkout or a client portal. For that specific case, manual, infrequent, self-managed updates can be an adequate, honest answer.

    The maintenance-needed testTwo variables, and the direction each one pushes
    Many componentsFew components
    Many plugins, no sensitive dataMore moving pieces, each on its own release schedule
    Strongest case for ongoing maintenanceMany plugins, and they touch money, personal data or file uploads
    The narrow honest exceptionFew plugins, nothing touching money or personal data
    Few plugins, handles sensitive dataFewer pieces, but what they touch raises the stakes

    No money, data or uploadsHandles money, data or uploads

    A reasoning aid, not a scored model. The two variables and the direction each pushes, with no weighting between them.

    A simple diagram showing how the number of active plugins and whether a site handles money or personal data together determine how strong the case for ongoing maintenance is.

    The practical test is to count the active pieces of software: WordPress core, the theme, and each plugin. Then ask whether any of them touch money, personal data or file uploads. More components and more of that kind of data both push the case for ongoing maintenance further from optional.

    What a security plugin or auto-updates alone still miss

    A security plugin can scan for known threats and, in some cases, keep itself current. It does not update the other plugins running on the site, and it does not create an off-site backup unless someone configures that separately.

    Turning on automatic updates for everything closes the patching gap, but not the compatibility gap. WordPress can apply some updates in the background, but plugins and themes generally are not auto-updated by default, and even where an update applies cleanly, it can still break a specific plugin and theme combination on your site. An unattended auto-update with no rollback path is itself a known way sites go down, which is a large part of why staging and a tested rollback exist as a step rather than a single button. See how NoDrama tests an update before it goes live.

    What monthly maintenance actually has to cover

    Three things, and none of them substitute for the others.

    Backups

    A real backup covers the database and the file system together, on a schedule tight enough that the restore point is actually usable, stored off the live server. A copy that lives on the same server as the site it protects is not a backup for the case where that server is the problem.

    Confirm it

    Check that your backup destination is off-site, not a folder on the same host.

    Update testing

    Update testing happens on a staging copy before anything reaches the live site, with a rollback path ready if the update still breaks something once it is live.

    Confirm it

    After an update, check the specific pages and forms that depend on the updated plugin, not just that the site loads.

    Monitoring

    Monitoring detects an outage: a site that stopped responding. It does not detect a slow, still-running compromise, and it is not a substitute for patching. It is a detection layer sitting alongside the other two, not a replacement for either.

    What this guide does not solve

    This guide does not tell you whether your specific site has already been compromised. That takes a scan of the actual site, not an article about sites in general.

    It also does not hand you a fixed WordPress-specific number for how often maintenance has to run. The honest answer is “as often as the software underneath keeps shipping updates,” which is continuous rather than a fixed monthly figure, even though most care plans, NoDrama’s included, bill on a monthly cycle.

    NoDrama’s care plans cover backups, tested updates and monitoring at three levels of depth.

    See The Three Plans

    Conclusion

    For most sites running more than a handful of plugins, or handling payments, personal data or file uploads, the answer is yes: ongoing maintenance is not optional, because core, the theme and every plugin keep shipping updates on their own schedules whether or not anyone applies them, and plugins in particular carry the overwhelming share of the disclosed vulnerabilities in the ecosystem. The honest exception is narrow. A near-static brochure site with almost no plugins and nothing touching money or personal data can get by on manual, infrequent, self-managed updates. Everything past that point is a question of how many moving pieces are running and what they touch, not whether WordPress as a platform is somehow dangerous on its own.

  • How to Choose a WordPress Maintenance Company

    How to Choose a WordPress Maintenance Company

    Start here

    1. 01Working out what actually matters
    2. 02Checking a specific vendor against it
    3. 03Avoiding the traps

    The five things that actually separate one WordPress maintenance company from another

    Every established WordPress maintenance company claims tested updates, backups and security monitoring somewhere on its page, so a features list does not tell you much. What actually separates one provider from another is whether five specific things are checkable, not promised.

    Five criteriaWhat to hold any provider to

    Tested updates, with a real rollback pathStaging catches the obvious breakage. Rollback is the separate fallback for what it missed.

    Restore-tested backups, not just takenA backup that has never been restored is a file, not a plan.

    A written response time for a real incident“We’re quick” is not a number. A stated response time is.

    Who keeps the domain, hosting and admin credentialsThis decides how hard it is to leave later.

    The monthly report: evidence, or a marketing emailOne shows what was checked and when. The other reads well and proves nothing.

    Checklist of five criteria for choosing a WordPress maintenance company: tested updates, backups, response time, access ownership, report quality.

    For the fuller list of questions to work through with a specific vendor, see the fuller scope of what a maintenance retainer covers.

    How the core mechanisms actually work, and what each one does not catch

    Knowing the mechanism behind each claim is what lets you ask a useful question instead of an easy one to dodge.

    Mechanism What it catches What it misses
    Update testing Obvious conflicts, caught on a copy of the site before a visitor sees them Breakage that only appears under live traffic, live form submissions or a live checkout
    Backups The database and the files, stored off the production server Whether a recovery actually works, unless someone restore-tests it
    CDN Static assets served from a server closer to the visitor A slow database query or a bloated plugin stack causing the slowness
    Uptime monitoring An outage, an error code or an SSL failure A page that returns a normal response while its checkout or form quietly fails
    Security monitoring Ongoing scanning for vulnerabilities and malware, plus a watch on login activity Anything after onboarding, where the claim is really a one-time scan
    Table comparing WordPress maintenance components, what each one catches and what it misses.

    Tested updates and rollback

    Staging runs the update on a copy of the site first, so obvious conflicts get caught before a visitor sees them. Rollback exists for the failure staging missed, since a staging environment does not carry live traffic, live form submissions or a live checkout, and some breakage only shows up under those conditions. The two are different safety nets, not the same claim said twice.

    Visual regression testing

    This is a pixel-level before-and-after comparison that flags a CSS conflict or a layout shift an update introduced. NoDrama offers a version of it, and so do ManageWP, WP Umbrella and WP Remote. It is worth asking about, but it is not a reason to choose one provider over another on its own.

    Backups

    A real backup covers the database and the files, stored off the production server so a server failure cannot take out both the site and its own backup. The part providers skip is restore testing, actually running a recovery and confirming the result works, which is a different exercise from confirming a backup job completed.

    CDN

    A content delivery network caches and serves static assets from servers closer to the visitor. It does not fix a slow database query or a bloated plugin stack causing the slowness in the first place, and it is typically measured and sold in bandwidth per month.

    Uptime monitoring

    External checks ping the site at intervals and flag an outage, an error code or an SSL failure. What they do not catch is a page that returns a normal response while the checkout or a form on it quietly fails, since the check only confirms the page loaded, not that it worked.

    Security monitoring

    Active monitoring is ongoing scanning for vulnerabilities and malware, plus a watch on login activity. A one-time scan run at onboarding is not the same claim, even when both get described as “security monitoring” on a sales page.

    Verify it

    Before signing, ask to see one real example in each category: a sample restored backup log, a sample staging test note and a sample monthly report. A provider that runs these processes can produce all three without much notice.

    What good looks like

    A handful of benchmarks are worth holding any provider to, whatever else is in the pitch.

    • Restore-tested backups, on a defined schedule the provider can name.
    • A written response time, stated as a number rather than as reassurance.
    • A sample monthly report available to look at before you sign anything.

    Before you sign anywhere, NoDrama’s free website audit is a way to see what your own site’s baseline looks like.

    The questions worth actually asking before signing

    • What happens if an update breaks my site?
    • How fast will someone respond if the site goes down on a weekend?
    • Are backups actually restore-tested, or just taken?
    • Who owns the domain, hosting and admin login after this ends?
    • Is security monitoring active, or a one-time scan?
    • Can I see a sample monthly report before I sign?

    Plan structure matters here too, since a response time is often tied to the tier. See the three plans and what each covers before comparing what different providers include at a given price.

    What a generalist retainer or DIY plugin stack falls short on

    A broad, undefined-scope retainer with no report leaves nothing to check the vendor against later, since there is no record to point back to when something goes wrong. A DIY stack, a backup plugin, a security scanner and an uptime pinger stitched together, has the same gap: nobody is restore-testing those backups or applying a flagged patch, because none of those tools does that on its own. Managed hosting alone is not a substitute either. It typically does not test plugin or theme updates before they go live, and its security coverage usually stops at the server layer rather than watching the WordPress installation itself.

    Common misconceptions when comparing providers

    A few habits lead buyers to the wrong comparison, even when they are asking reasonable questions.

    The fastest response-time SLA is not automatically the right buy. A low-traffic brochure site with no checkout gets little from a 4-hour response time compared to a site where every hour of downtime costs revenue.

    Tested updates and visual regression testing are not a real differentiator among WordPress maintenance companies, since most serious providers offer some version of both. The actual gap between them shows up in response time, backup verification and report quality.

    Star ratings and testimonials do not surface how a provider behaves during a real incident. A customer who left after a bad response rarely writes up why, so the review count says little about the thing that matters most.

    Compare on the record, not the pitch. NoDrama publishes what its updates and backups actually caught, not just that they ran. Compare NoDrama against the same five criteria.

    What this does not solve

    None of the above replaces confirming a specific vendor’s process against your own site, once. A checklist tells you what to ask. It does not tell you what a specific provider will actually do when that process gets tested for real, and the only way to find that out is to ask for the sample evidence directly and read it.

    Conclusion

    Choosing among WordPress maintenance companies comes down to the same five checkable things every time: tested updates with a real rollback path, restore-tested backups, a written response time, clarity on who holds the domain and admin access, and a monthly report that reads as evidence rather than marketing. Price is a secondary filter, useful only once those five hold up on their own, not a shortcut around them.

  • How Often Should a WordPress Site Be Updated?

    How Often Should a WordPress Site Be Updated?

    In this guide

    1. 01Work out what you actually have.
    2. 02Set the cadence and apply it.
    3. 03Confirm it held.

    What “keeping WordPress updated” actually means

    WordPress core, plugins, and themes do not run on the same update mechanism, and that gap is where most of the confusion about update frequency comes from.

    Core minor releases, the point releases that fix security holes and bugs, install themselves automatically on any WordPress site running a reasonably current version, with no admin action required. Core major releases, roughly one every four months, do not install themselves on an existing site unless the owner opts in.

    Plugins and themes are manual by default, unless the WordPress security team decides a vulnerability is severe enough to force a patch through the update API. Outside that forced-patch exception, every plugin and theme update is something the site owner has to apply.

    That split gives a practical rule: a security-flagged release gets a short, defined window. A feature or maintenance release gets batched with the rest and applied on a schedule. NoDrama patches security releases with key pages photographed before and after, and puts back anything that breaks.

    Check what you have now

    Two things to check before setting a policy. First, whether WP_AUTO_UPDATE_CORE is set to minor, true, or false in wp-config.php, since that constant governs core only. Second, which plugins and themes already have auto-updates toggled on, under the Plugins and Themes screens in the dashboard.

    Working out how often to update WordPress plugins on a given site starts with what is already switched on, not with a fixed number.

    Verify it

    List every plugin and theme with auto-update turned on, and confirm someone is actually watching the ones that are not. A setting nobody checks is not a policy.

    Start with a free audit of your current update settings to see where the site actually stands.

    Choose the right cadence

    A workable WordPress update schedule has two real values, not one.

    Anything security-flagged gets a short, defined window, commonly discussed as 24 to 48 hours once it has passed staging. That is industry-common practice, not a NoDrama response-time commitment: NoDrama’s confirmed response times are 4 hours on The Standard, 2 hours on The Higher Standard and 1 hour on The Highest Standard, if a site is down or hacked, and that is a different clock from how fast a patch itself gets classified and tested.

    Everything else, a feature release, a maintenance update, a routine plugin bump, runs on a batch: weekly for most sites, monthly for sites with very little at stake.

    Update type Cadence Trigger
    Core minor (security, bug fixes) Automatic, on WordPress’s own schedule No action needed
    Core major Roughly every 4 months Opt-in on existing sites
    Plugin or theme, security-flagged Short window, commonly 24 to 48 hours, once staging has passed Vulnerability disclosure
    Plugin or theme, routine Weekly to monthly batch Scheduled review
    A table comparing WordPress core, plugin and theme update cadences by type. The 24 to 48 hour window is common practice this piece recommends, not a stated NoDrama SLA.

    The advice this replaces is “update everything the moment a notification appears.” That is the habit that breaks sites, because it skips the step that matters: classify first, security or feature, then apply on the clock that matches. The major release cycle runs on roughly a four-month scoping-to-launch cadence, one more reason a single interval was never going to cover everything WordPress ships.

    For a low-traffic, no-commerce site

    The defaults are a reasonable position here: core minor auto-on, plugins and themes manual, checked monthly. There is not much for an untested update to break, and not much riding on catching it fast.

    For a site with checkout, forms, or client data

    The case for a tighter cadence and staging gets stronger, not because the site is more exposed in the abstract, but because there is more attached to an update going wrong: a broken checkout, a form that silently stops submitting, and a customer finding out before the owner does.

    Apply the change

    To prevent a theme from being able to update on its own, without turning off updates everywhere, WordPress gives you a filter rather than a blanket setting. The auto_update_theme filter is the documented route, and the call that disables it for a single theme is:

    add_filter( 'auto_update_theme', '__return_false' );

    Place that in a plugin file, not directly in wp-config.php. The WP_AUTO_UPDATE_CORE constant in wp-config.php governs core only and does not touch theme auto-updates at all.

    For per-theme control instead of a blanket switch, check $item->slug inside a custom callback on the same filter, rather than returning false for every theme on the site.

    The core-only equivalent lives in wp-config.php: the WP_AUTO_UPDATE_CORE constant, set to false, true, or the string ‘minor’.

    Via code

    For an owner comfortable editing a plugin file or wp-config.php, the filter and the constant above are the whole job.

    Via a managed maintenance plan

    The alternative is having the classify-then-stage-then-test sequence run on the owner’s behalf rather than by the owner: someone else watches for the release, decides whether it is security or routine, and applies it on the matching clock.

    See how NoDrama classifies and patches WordPress updates, with key pages checked before and after.

    Verify it

    After either path, confirm the setting took place. Check the Site Health screen or the auto-update column on the Plugins and Themes screens, rather than assuming the change was saved.

    Verify safely

    Verifying an update safely means testing on staging, not checking the live site after the fact. Apply the update on a copy of the site, not a preview mode on the same install, then load the front page, the key templates, any forms, checkout if the site has one, and the admin login before promoting the change to production.

    The safe-update sequence

    1. 01
      Backup taken
      Files and database together, immediately before.
    2. 02
      Staged
      Applied to a copy of the site, not the live install.
    3. 03
      Tested
      Front page, templates, forms, checkout, admin login.
    4. 04
      Promoted or held
      Passes, it ships. Fails, it stays on staging.
    5. 05
      Verified live
      Same checks again on production, not a homepage glance.

    This is one common sequence, not the only one. NoDrama runs updates on the live site with key pages photographed before and after, and puts back anything that breaks.

    A flow diagram of the staging, testing and promotion sequence for a WordPress update.

    The rollback path only works if a backup was taken immediately before the update, restoring files and the database together, not one without the other. Here’s how backups and rollback actually work once a change needs undoing.

    Verify it

    After promoting, confirm the update on the live site the same way it was checked on staging, the front page, templates, forms, and checkout, not just a glance at the homepage.

    Troubleshoot

    The update went live, and something broke.

    Restore from the backup taken immediately before the update, files and database together, ahead of trying to manually undo a single plugin. Reversing one change by hand risks missing whatever else the update touched.

    WordPress emailed me about a critical error.

    That is Recovery Mode, a built-in fallback that lets an admin log in with the offending plugin or theme paused so it can be deactivated without FTP access. Recovery mode catches fatal errors. It does not catch a page that loads but looks wrong, which is what the staging and test step is for.

    What this does not solve

    Uptime and error monitoring tells you the site is down or throwing an error. It does not tell you an update quietly slowed the site down or broke one form without triggering an error. Catching that needs the staging and test step, not a monitoring alert.

    The short answer, restated

    So, how often should WordPress be updated? Core patches its own security releases without anyone touching it. Everything else, plugins and themes, runs on a policy: fast for anything security-flagged once it is tested, batched weekly or monthly for the rest, and tested on staging before it goes live either way. See the three plans and what each covers if a managed policy is the simpler route.

  • How Much Does WordPress Maintenance Cost?

    How Much Does WordPress Maintenance Cost?

    What this guide covers

    1. 01What drives the number.
    2. 02What it means for a site like yours.
    3. 03What to check before you sign.

    The short answer on WordPress maintenance cost

    Website maintenance pricing splits into three bands, and which one applies to you depends on what the site does, not how it looks.

    Personal or brochure site: roughly $0 to $50 a month.

    Some vendor guides put the low end even tighter, $5 to $25 a month, for a site with no ecommerce and no client data.

    Small business site: roughly $35 to $300 a month.

    One published worked example puts a small restaurant site doing basic maintenance, no marketing work included, at about $81 a month.

    Business, membership, or ecommerce site: roughly $150 to $1,000 or more a month.

    Ecommerce sites specifically run $300 to $1,000 or more a month, and at the top end, medium businesses report annual maintenance spend of $12,000 to $30,000 a year, with large or enterprise sites at $30,000 to $50,000 or more a year.

    The three price bands

    Monthly maintenance cost, by what the site does

    Personal or brochure

    $0 to $50 / month

    Small business

    $35 to $300 / month · $81 marker: worked example, small restaurant site

    Business or ecommerce

    $150 to $1,000+ / month

    Bars are scaled against a $0 to $1,000 a month axis. Ranges as stated by vendor pricing pages and agency estimates, not an audited survey.

    Bar chart showing WordPress maintenance cost ranges by site type, from $0 to $50 a month for personal sites up to $150 to $1,000 or more a month for business and ecommerce sites.

    None of those figures come from an audited industry survey. They are the range that repeats across several vendor pricing pages and agency blogs, and this guide treats them as a market pattern, not a fixed rate card.

    The test that matters more than the number itself: ask what a quote excludes, not what it includes. A plan near the bottom of that range and a plan at $140 a month can both say “backups and security.” Only one of them usually says what happens when an update breaks something.

    How WordPress maintenance pricing actually works

    The three ways it gets sold

    The same word, “maintenance,” covers three genuinely different purchases, and comparing across them without noticing is where most confusion starts.

    Per-task or hourly freelancer billing.

    You pay $50 to $150 an hour, or a flat $50 to $300 a month, for someone to apply updates and fix what breaks. Nothing is tested or staged unless that person happens to do it manually, and coverage depends entirely on them being available when you need them.

    Self-serve SaaS tooling.

    Tools like WP Umbrella, ManageWP, and WP Remote put a dashboard in front of you and you approve every change yourself. WP Umbrella, for example, prices its base plan at $2.19 per site a month, with encrypted incremental backups on a daily, weekly, or monthly schedule retained for 50 days, continuous uptime monitoring, and a bulk “Safe Update” feature with automatic rollback if an update fails. Security scanning and hourly backups are separate add-ons at $2 and $2.49 a site a month. These capability claims come from the vendor’s own pricing page, not from independent testing.

    Managed care-plan retainer.

    You pay one flat monthly fee, and a defined process, run by a person or a team, reviews, tests, and responds on your behalf within a stated window. This is what a managed care plan actually does that separates it from the first two options: someone is watching the process, not just running a script.

    What actually moves the price

    Four things separate a cheap plan from an expensive one, and none of them is a marketing word.

    1. 01Backup frequency and retention. Daily versus hourly, and how many days or versions get kept.
    2. 02Whether updates are tested before going live, or just applied and hoped for.
    3. 03Whether there is a stated human response time, in writing, not “we’ll get to it.”
    4. 04What happens when something breaks. Does a rollback exist, is it automatic or manual, and who actually runs it.
    Verify it

    Before you compare two quotes, ask each vendor to answer those four questions in writing. A vendor who cannot answer one of them plainly has told you something too.

    Why this matters for a site that makes you money or holds client data

    A cheap plan with no tested update path is a manageable gap on a site nobody depends on. It stops being manageable once the site is doing real work: taking orders, holding client records, or feeding a paid campaign. An update that breaks checkout on a Friday, with nobody watching for it, is the kind of thing you find out from a customer rather than from a report.

    The counter-case matters just as much. A personal or low-traffic brochure site, run by an owner willing to check in on it periodically, genuinely does not need a premium retainer. Paying for a 4-hour response time on a site that generates no revenue and holds no client data is paying for a guarantee you have no use for.

    What the gap actually costs shows up in more places than uptime. A site nobody is maintaining tends to get slower as plugins pile up unchecked, which is what an unmaintained site costs you in load time even before anything breaks outright.

    What good WordPress maintenance pricing looks like

    A well-specified small business plan, priced in the low hundreds a month, states its backup frequency plainly, says how much work it will take on for you, and includes a monitored uptime check you can point to. A plan under fifty dollars a month, by contrast, often covers only backups and a security scan, with nothing tested before it goes live and no stated response time anywhere in the agreement.

    NoDrama’s own three tiers are one clean illustration of the “what does the price actually include” test, because the differences between them are stated rather than implied:

    Typical sub-$50 plan The Standard
    $129 / month
    The Higher Standard
    $249 / month
    The Highest Standard
    $479 / month
    Backups Backups only, frequency often unstated Daily Every 12 hours Every change
    Response if down or hacked No response time stated 4 hours 2 hours 1 hour
    Small jobs at once No job allowance stated One Two Three
    Restore test Restore testing not stated Once a year Twice a year Every 3 months
    Table comparing a typical sub-$50-a-month WordPress plan against NoDrama’s The Standard, The Higher Standard, and The Highest Standard tiers on backup frequency, response time, small jobs at once, and restore testing. The sub-$50 column is a market pattern, not a named competitor.

    Every tier includes the same features. What moves between them is how often the site is backed up, how fast someone responds when it is down or hacked, how many small jobs get worked on at once, and how often a real restore is tested. See the full plan breakdown for what each tier covers in full.

    What to do about it before you sign

    Run any quote you are comparing through the same short list.

    1. 01Ask what is excluded, not what is included. A vendor’s answer to this question is more informative than their feature list.
    2. 02Get backup frequency, retention, and storage location in writing. “Backed up” without a number attached means nothing.
    3. 03Get the response time, and how much work is included, in writing. “We’ll get to it” is not a commitment.
    4. 04Confirm whether updates are tested before going live. And what happens if a test fails.
    5. 05Check the agreement itself. A quote is a price. An agreement states what a real maintenance agreement has to specify, including what happens when something goes wrong.

    Not sure what your current setup actually covers?

    Send NoDrama your URL and get a free website audit, no pitch attached.

    Audit My Site

    Common misconceptions about WordPress maintenance cost

    “More expensive always means safer.”

    This does not hold up on the numbers. WP Umbrella delivers automated backups, uptime monitoring, and automatic rollback for $2.19 a site a month, far below Codeable’s Basic retainer at $140 a month, which adds one human developer hour alongside similar automated coverage. The price gap is mostly the human time and the response commitment, not the underlying automated feature set.

    “A free security plugin is basically a maintenance plan.”

    It usually covers scanning only. It does not test an update before it goes live, does not verify that a backup actually restores, and does nothing when something breaks.

    “My host’s backups have this covered.”

    Hosting price and maintenance price are separate line items. A host-level backup is not the same as a tested, verified restore process, and a cheap plan built around that assumption is usually the one that skips the risk that matters most.

    What this does not solve

    No figure in this guide comes from an audited industry survey. Every number is a vendor’s own stated price or a market estimate from an agency blog, and several of the tool prices quoted here are vendors pricing their own product. This guide names that plainly rather than implying an authority that does not exist.

    This guide also does not tell you which plan a specific site needs. That depends on traffic, how much revenue the site is exposed to, and how much downtime the business can absorb, none of which a pricing table can answer. That is what an audit is for, not a price comparison.

    So, what should WordPress maintenance actually cost you?

    The number itself means little without knowing what it excludes. The honest comparison across any two quotes is backup frequency, whether updates are tested before going live, and whether there is a stated response time, not the headline price on its own. A five dollar plan and a five hundred dollar plan can both be correct choices, for different sites, and the way to tell them apart is the list above, not the invoice.

  • What Is a WordPress Care Plan?

    What Is a WordPress Care Plan?

    The mechanism

    Before shot
    Key pages photographed before the update runs.

    →

    Update and compare
    The update runs on the live site. The same pages are photographed again and compared.

    →

    Put back
    Anything that changed or broke goes back to the last working version.

    Before-and-after checks and rollback are common across providers, not unique to NoDrama.

    A WordPress update checked with before-and-after screenshots of key pages, and put back if anything breaks.

    The short answer

    A WordPress care plan is a recurring, paid service in which a provider takes over the ongoing work a live WordPress site needs once it’s launched: keeping the software current, backing the site up, watching for security issues, and picking up when it goes down. Nobody owns a fixed definition of the category, so what’s actually inside a given plan depends on the provider selling it.

    The pieces that recur across the market are: core, plugin and theme updates tested before they go live, backups on a schedule with a real restore path, a scan-and-response loop for security, uptime monitoring, and some bounded amount of human support. A CDN or performance layer is common but not universal to the category. That last part matters if you’re comparing providers on price alone, because a plan without a CDN isn’t necessarily a worse plan, it may just be a narrower one. This is how NoDrama runs the maintenance side specifically, one version of the bundle rather than the only one.

    How it actually works

    The update pipeline

    The mechanism that separates a working care plan from a plugin subscription is how an update gets checked. A care plan photographs the key pages before an update runs, runs it, photographs them again and compares, and puts it back if something broke.

    WordPress treats update urgency seriously at the platform level too. When WordPress 7.0.4 shipped as a security release, the release notes said it is recommended that sites update immediately, and that sites supporting automatic background updates would begin updating shortly on their own. That’s useful, and it’s also incomplete on its own: automatic updates close the exposure window, but they don’t check what the update did to a specific site’s plugin and theme combination. That’s the gap a before-and-after check closes.

    Verify it

    After any update goes live, confirm the site’s actual pages still load and function. Confirming the update installed is not the same check.

    Backups, security, and uptime

    Three separate systems get lumped under “security” on most sales pages, and they do different jobs.

    Backups

    Only as good as three properties: how often it runs, how many restore points exist, and whether the restore has actually been exercised.

    Security

    A scan-and-response loop, not a one-time hardening pass followed by silence. A scanner nobody reads is a cost, not a control.

    Uptime

    Detects that the site did not respond inside a check window. It flags that something needs a look, it does not diagnose what’s wrong.

    Each of these only counts if it runs as an ongoing process rather than a one-time setup step, and the plan worth paying for is the one that keeps running it.

    Why it matters for a live business site

    Whether any of this is worth paying for comes down to two questions: what it would cost the business if the site broke or went dark for a period, and whether anyone will actually run the schedule themselves.

    A brochure site with no forms, no checkout and no compliance obligation, run by an owner who genuinely follows a backup-and-update routine, doesn’t need a paid plan to stay fine. That’s a reasonable place to stop reading and keep doing what you’re doing.

    A revenue-generating or reputation-critical site is a different calculation. An update that breaks checkout, or a stretch of days where nobody notices the site is down, costs more than the plan would have. The failure mode that most often pushes an owner from DIY to a paid plan isn’t one dramatic event. It’s a freelancer who built the site going quiet, or a schedule that got followed for the first few months and then quietly stopped.

    What good looks like

    A care plan worth paying for shows three things: updates tested off the live site rather than pushed straight to production, a restore that has actually been run at least once rather than assumed to work, and a monthly record showing this happened in a given period.

    Vendor pricing guides put the market for this category roughly between $100 and $500 a month, with brochure sites at the low end and ecommerce sites at the high end. That’s a market range from vendor pricing pages, not a NoDrama figure, and it’s worth treating as a rough band rather than a quote. What a maintenance retainer actually covers varies by provider inside that range, which is why the bundle matters more than the number on its own.

    Plan Price Backups Response if down or hacked Small jobs at once Restore test
    The Standard $129/month Daily 4 hours One Once a year
    The Higher Standard $249/month Every 12 hours 2 hours Two Twice a year
    The Highest Standard $479/month Every change 1 hour Three Every 3 months
    NoDrama’s The Standard, The Higher Standard and The Highest Standard plans compared by backup frequency, response time, small jobs at once and restore testing.

    What to do about it

    Before signing anything, ask the provider these questions and check the answers against what the sticker price implies.

    • Are updates tested somewhere other than the live site before they ship?
    • When was the backup last actually restored, not just taken?
    • What does a security scan alert lead to, and who reads it?
    • What does the monthly report actually show?
    • What’s excluded at this price, not just what’s listed?
    • If a CDN is included, what size, and does that matter for this site’s traffic?

    NoDrama’s care plans lay out exactly what’s tested, backed up, and watched every month. See the three plans and what each one covers.

    Common misconceptions

    “I installed a backup plugin and a security plugin, so I’m covered.”

    A plugin is software installed once. A care plan is an operating process: someone confirms the backup restores, and someone reads the scan alert and decides what to do about it. The software doesn’t run itself.

    “Auto-updates handle this.”

    Automatic updates shrink the window a known vulnerability is exposed for, which matters. They don’t check what the update did to a specific site’s combination of plugins and theme. That’s the gap a before-and-after check closes.

    “The $30 plan and the $1,000 plan are basically the same thing with a different price tag.”

    Not reliably. One vendor’s account of the market puts plans priced around $30 to $50 a month as commonly running with no staging environment testing at all. A plan at that price is closer to an auto-update setting with a subscription fee than to the update pipeline described above.

    What a care plan does not solve

    A care plan keeps a site running the way it was built. It doesn’t fix a site that was built badly in the first place, and it isn’t a substitute for development work when a site needs new functionality or a redesign.

    A CDN, where a plan includes one, cuts load time for static assets like images and scripts. It doesn’t fix a slow database query, bloated code, or a plugin conflict, which is the separate speed work a CDN does not replace.

    Is a WordPress care plan worth it for my site

    A WordPress care plan is worth paying for once a site’s downtime or a broken update would cost more than the monthly fee, and once nobody in the business will reliably run updates, backups and monitoring on a schedule themselves. The category has no fixed bundle, so the question worth asking of any provider is whether updates get tested before they go live, whether a restore has actually been exercised, and whether a monthly record proves any of it happened. Where a site is low-traffic, low-risk, and someone will genuinely follow the schedule, DIY is a reasonable answer. Where it isn’t, the bundle matters more than the sticker price.