• Guides
  • 29 July 2026
  • 11 min read
  • Website Care Plans
  • WordPress
  • Pricing
  • Managed Services
  • Website Maintenance
Redevon IT Team
Written byRedevon IT TeamManaged Operations

What Is a Website Care Plan? (And What Should It Cost?)

What Is a Website Care Plan? (And What Should It Cost?)

Your website launched. The invoice was paid. Everything worked.

Then, quietly, things started to drift. A plugin update broke a form and nobody noticed for three weeks. The SSL certificate lapsed on a Sunday. Page speed crept up as the image library grew. Someone asked for a small content change and there was no one obvious to ask.

None of these are disasters on their own. Together, they're how a good website becomes an embarrassing one over eighteen months.

A website care plan is the arrangement that prevents that drift. It's a monthly agreement with whoever looks after your site, covering updates, backups, security, monitoring, and usually a block of time for actual changes. Think of it less like insurance and more like a service contract for something you depend on every day.

If your organisation is UK-based, see how we work with UK teams.

This guide covers what a care plan actually includes, what it should cost, and how to tell a genuine one from a line item that buys you nothing.

What a website care plan actually includes

The term gets used loosely, which is part of the problem. Here's what a real plan covers, roughly in order of how essential each item is.

The essentials

Software and dependency updates. Your CMS, plugins, themes, libraries, and server packages all release updates, many of them security patches. Someone has to apply them, and apply them carefully, because a bad update can break a live site. This is the single most important line in any care plan.

Backups, tested. Daily or weekly backups stored somewhere other than the server itself, with a known restore process. The word that matters is tested. Plenty of businesses discover their backups were failing silently at the exact moment they need one.

Uptime monitoring. Automated checks that alert someone when the site goes down, ideally before your customers tell you.

Security scanning. Malware scans, vulnerability checks against known CVEs in your dependencies, and a firewall or WAF where appropriate.

SSL certificate management. Renewals handled so a certificate never lapses. Modern setups largely automate this, but someone still needs to own it.

The ones that separate a real plan from a token one

Performance monitoring. Tracking Core Web Vitals and page speed over time, not just at launch. Sites get slower gradually; without measurement, nobody notices until rankings drop.

Agreed time for changes. Capacity for content changes, small features, and fixes. This is what turns a care plan from passive protection into something that keeps improving the site. Whether it is included, how much there is, and what happens to unused time all vary by contract, so get them written down.

A staging environment. Somewhere to test changes before they hit production. Any provider updating a live site directly is taking a risk with your business.

Defined response targets. Where a provider offers them, they should be written down with severity levels and the hours they apply to. A site outage and a typo fix should not be treated the same. A response target is also not a promise that the fault will be fixed in that time. Vague "we'll get to it" is not a response target.

Reporting. A monthly summary of what was done, what was found, and what's coming. You should never have to ask what you're paying for.

What's usually not included

Worth knowing so you're not surprised:

  • Full redesigns or rebuilds
  • Major new features beyond the agreed capacity
  • Third party licence and subscription fees (plugins, CDN, monitoring tools)
  • SEO, conversion optimisation and content writing, unless separately scoped
  • Paid advertising management

WordPress care plans: what's different

WordPress runs a huge share of the web, and the same extensibility that makes it popular is what makes it harder to keep healthy. A WordPress care plan should include everything above, plus a handful of things specific to the platform.

Plugin vulnerability monitoring. Most WordPress security incidents start in a third party plugin or theme, not WordPress core. A proper plan actively tracks your installed plugins against new vulnerability disclosures, with a plan for what happens when one affects you.

Coordinated update testing. Core, theme, and plugin updates interact with each other. Applying them one at a time with no testing is how page builders and custom post types quietly break. Updates should go to staging as a batch, get checked, then go live together.

A deliberate policy on automatic updates. WordPress can apply certain updates automatically. That's fine for a simple brochure site and risky for anything complex with custom functionality. Someone should have actually decided the policy, rather than leaving whatever the default happens to be.

PHP version tracking. PHP versions reach end of life on a published schedule, and hosts eventually force the upgrade whether you're ready or not. A good plan checks compatibility ahead of time and fixes issues before the host makes the decision for you.

Database housekeeping. Post revisions, expired transients, orphaned metadata, and spam comments all accumulate in a WordPress database over time. Periodic cleanup keeps a site with a lot of content from slowing down.

Licence renewals. Premium plugins and themes stop receiving updates, including security updates, the moment a licence lapses. It's a small thing that causes a disproportionate number of avoidable problems.

If a provider pitches you a generic care plan and can't speak to plugin monitoring or update testing specifically, they're describing a plan built for a simpler platform than the one you're running. For the operational detail, see our WordPress maintenance plan schedule.

Website care plan pricing: what determines the cost

There is no single fair price for a care plan, because two quotes with the same label can cover very different amounts of work. Prices also vary by market, currency, and how the provider bills. Instead of anchoring on a headline number, work out what scope you need, then compare quotes against it.

The table below shows how scope differs between a minimal arrangement and a fuller one. It is general buying guidance, not a set of Redevon packages.

Area Minimal arrangement Fuller arrangement Confirm in writing
Updates Applied automatically or in bulk Reviewed, tested on staging, then released How updates are tested and rolled back
Backups Scheduled, rarely restored Stored off-server and restore-tested Frequency, retention and the last restore test
Monitoring Uptime alerts Uptime, security and performance tracked over time Who receives alerts and when a person responds
Changes and fixes Little or none included Agreed capacity for fixes and improvements How much is included, unused time, and how extra work is approved
Support coverage Best effort, business hours Written response targets by severity Hours covered, any outside-hours arrangement, response versus resolution
Reporting None, or on request Regular summary of work, findings and recommendations A sample report

For business-critical applications and websites, our Application Management service covers maintenance, incident triage, monitoring and planned improvements within an agreed scope. Support is provided during business hours, and we agree the commercial terms and support coverage, including how critical issues are handled, before work begins.

What actually moves the price

Four things, mostly:

  1. Complexity. A WordPress brochure site and a headless commerce platform with three integrations are not comparable work.
  2. Traffic and criticality. If an hour of downtime costs you real money, you're paying for faster response, and that costs more to staff.
  3. Change work. This is often the biggest variable. A plan with regular capacity for fixes and improvements is a different product from one that only applies updates.
  4. Response commitments. Coverage outside business hours, with a short response target for critical issues, requires people on call. That is genuinely expensive, and you should only buy it if downtime justifies it.

Be careful at the bottom of the market

The cheapest "care plans" are often an automated updater and a backup script with no human attached. That can be fine for a personal site. For anything your business depends on, the gap shows up the first time something goes wrong and there's no one to call.

Equally, expensive doesn't guarantee good. The real question isn't what does it cost, it's what am I actually getting, in writing.

How to tell a real care plan from a bad one

Five questions that expose the difference quickly:

"What happens if my site goes down at 2 a.m. on a Sunday?"

A clear agreement says whether outside-hours incidents are covered and, if they are, how. A weak one has an answer with the word "usually" in it.

"Do you test updates before applying them to my live site?"

If there's no staging environment, they're updating production and hoping. That's a risk you're paying them to take on your behalf.

"What change work is included, and what happens if I don't use it?"

Clear plans state this plainly. Vague ones leave it deliberately fuzzy so every request becomes a negotiation.

"Can I see a sample monthly report?"

Providers doing real work are happy to show you what reporting looks like. Providers doing nothing have nothing to show.

"Am I locked in?"

Check the minimum term, the notice period, and what happens to your access and documentation if you leave. A longer term can be reasonable when onboarding work is substantial, but the reasons and the exit terms should be written down before you sign.

If you're weighing quotes from more than one provider, our guide to comparing website maintenance packages walks through a framework for putting them side by side on equal terms.

Do you actually need one?

Honestly, not everyone does.

You probably don't need a care plan if: your site is a simple static page that rarely changes, you have internal technical staff who own it, or the site genuinely doesn't matter much to your business.

You probably do if: your site generates leads or revenue, you're on a CMS with regular security updates, you handle any customer data, you don't have someone internal who owns the platform, or you've already been burned by something breaking with nobody to call.

The honest test: if the site went down tomorrow morning, who would fix it, and how long would it take? If you can't answer that quickly, the care plan is worth more than its price.

Frequently asked questions

No. Hosting is the server your site lives on. A care plan is the human work of keeping the site healthy on top of it. Some providers bundle them, which is fine, but they're separate things. Bundled hosting doesn't mean anyone is updating your plugins.

There is no reliable single figure, because quotes cover very different amounts of work. The annual cost depends on the platform, how much change work is included and the support coverage you need. Ask each provider for the yearly total on the same written scope, including licences, any bundled hosting and how additional work is approved and billed.

It should cover everything above, plus a few things specific to the platform: monitoring your installed plugins against new vulnerability disclosures, testing core, theme, and plugin updates together on staging before they go live, a deliberate policy on automatic updates, tracking PHP version compatibility ahead of forced host upgrades, routine database cleanup, and keeping premium plugin and theme licences current. Those risks come from how extensible WordPress is. A plan that doesn't mention any of them is written for a simpler platform than the one you're running.

You can, and for a simple site it's reasonable. The catch is that maintenance is only interesting when it fails: it's easy to defer for six months, and the update you put off for six months is the one that breaks something. If you handle it yourself, at minimum automate backups and set a recurring calendar reminder you'll actually honour.

Scope. A care plan keeps an existing website healthy. Application management can include that maintenance, plus incident triage, integration support, monitoring and planned improvements for an application the business depends on, all within an agreed scope and capacity.

It can help indirectly. Keeping pages fast, secure and working, and reducing avoidable outages, supports a site that visitors and search engines can use. It does not guarantee rankings. A care plan is not an SEO service, and ranking work is scoped separately.

The short version

A website care plan is someone taking responsibility for your site after launch. What it costs depends on the platform, how much change work is included, and the support coverage you need, so compare quotes on the same written scope rather than on the headline number.

Judge plans on what's written down: response targets, change capacity, staging, reporting. The cheapest plan that leaves you calling an unanswered inbox during an outage isn't cheap.

At Redevon IT, we've been looking after clients' platforms since 2012. If you're comparing care plans, or inheriting a site someone else walked away from, tell us what you're working with and we'll give you an honest read on what you actually need.

Supporting a business-critical application or website? See what our Application Management service covers.