Website maintenance is the ongoing work required to keep a website secure, available, accurate, usable, and aligned with the business it supports. It can include software updates, monitoring, backups, security response, content changes, performance work, accessibility checks, analytics, and technical improvements.
The right maintenance plan depends on what the website does. A brochure site with a contact form has different risks from an ecommerce store, membership portal, headless CMS, or web application connected to operational systems.
A useful plan should answer five questions:
- What will be checked regularly?
- What happens when something fails?
- Who owns the website, hosting, code, content, and third-party accounts?
- What work is included in the recurring fee, and what is charged separately?
- How will the provider show that the website remains healthy?
Maintenance is not a substitute for a redesign, modernization programme, or new feature development. It is the operating discipline that keeps an existing website useful while those larger decisions are considered.
Website Maintenance at a Glance

| Maintenance area | What it should cover |
|---|---|
| Software and dependencies | CMS, plugins, frameworks, libraries, runtime versions, themes, integrations, compatibility, testing, and rollback. |
| Backups and recovery | Scheduled backups, separate storage, retention, restoration testing, recovery procedures, and ownership. |
| Security | Vulnerability monitoring, access reviews, malware detection, secrets, security configuration, logging, and incident response. |
| Operations | Uptime, forms, checkout, authentication, APIs, background jobs, certificates, DNS, and application errors. |
| Content and media | Page updates, images, downloads, links, publishing workflows, accessibility, and content accuracy. |
| Performance | Real-user performance, Core Web Vitals, image delivery, caching, third-party scripts, API response, and mobile behaviour. |
| Measurement and discoverability | Analytics, conversion tracking, redirects, indexation, metadata, structured data, sitemaps, and internal links. |
| Support and improvements | Troubleshooting, small fixes, release support, vendor coordination, documentation, and recommendations for larger work. |
Website Maintenance Services
Need a maintenance plan that reflects how your website actually works?
We can review your platform, integrations, deployment process, security and backup arrangements, content workflow, and support requirements, then help define a proportionate plan.
Explore Web Engineering Services → Request a Maintenance Plan Quote →
What Does Website Maintenance Include?
A complete maintenance service normally combines several categories of work. Not every website needs the same level of effort, but a credible plan should make the categories visible rather than describing everything as “general support.”
1. Software and Dependency Updates
This includes updates to the CMS, plugins, themes, frameworks, libraries, runtime versions, integrations, and other dependencies. Updates may address security vulnerabilities, compatibility problems, defects, or platform changes.
An update is not complete simply because a new version was installed. A responsible process also considers:
- Whether the update is compatible with the current website
- Whether it should be tested in a staging environment
- Whether database or content migrations are required
- Whether important workflows still work afterwards
- Whether the change can be rolled back
- Whether the update introduces privacy, performance, or accessibility issues
A website built with a hosted platform may require less infrastructure maintenance than a self-hosted CMS, but it still needs review of integrations, content, forms, analytics, and user journeys.
For websites with custom releases or important integrations, maintenance should include a clear deployment and rollback process. Our guide to zero-downtime deployments covers practices that help reduce avoidable disruption during releases.
2. Backups and Recovery
Backups protect against accidental deletion, failed deployments, hosting incidents, compromised accounts, and faulty updates. A serious backup plan should cover the parts of the website that need to be restored, including code, configuration, databases, uploaded files, and relevant content.
Ask four practical questions:
- How often are backups taken?
- Where are they stored?
- How long are they retained?
- When was the last restoration test?
A backup that has never been restored is an assumption, not proof of recoverability. Backups should be protected from the same failure or account compromise that could affect the production website.
For more complex systems, recovery also requires documented procedures, credentials, environment configuration, deployment instructions, and a realistic recovery-time expectation. Restoration should be tested at a frequency proportionate to the website’s business importance.
3. Security Monitoring and Response
Website security maintenance may include vulnerability monitoring, access reviews, malware detection, dependency scanning, security headers, secrets management, firewall rules, logging, and incident response.
The level of protection should match the website’s data and business role. An informational website does not have the same risk profile as an ecommerce site, customer portal, or website connected to internal systems.
A security plan should consider:
- Administrator and contributor access
- Multi-factor authentication
- Least-privilege permissions
- Software and dependency vulnerabilities
- Form and authentication abuse
- Personal or financial data
- Third-party scripts and integrations
- Logging and incident investigation
- Recovery if an account or environment is compromised
“Security included” is too vague to compare. Ask what is monitored, how often it is reviewed, who responds, what response times apply, and what happens if the work requires code changes or incident recovery.
4. Uptime and Operational Monitoring
Monitoring should show whether the website is available and whether important functions are working. Basic uptime checks are useful, but availability alone is not enough. A homepage can return a successful HTTP response while a contact form, checkout flow, search function, or CMS integration is broken.
Depending on the website, monitoring may cover:
- Availability from relevant regions
- TLS certificate expiry
- DNS and domain configuration
- Form submissions
- Authentication flows
- Checkout or payment journeys
- API and integration responses
- Background jobs and scheduled publishing
- Error rates and application logs
- Performance of important pages
Monitoring is valuable only when it has an owner and a response path. An alert sent to an inbox nobody checks is not an operational control.
Websites connected to external systems should also be monitored at the integration boundary. A site may be available while CRM submissions, payment notifications, search indexing, or content synchronisation are failing.
Our guide to reliable system data synchronization explains why integrations need ownership, retry behaviour, reconciliation, and failure handling rather than a connection that is assumed to work indefinitely.
5. Content and Media Updates
Content maintenance includes publishing or editing pages, updating images, replacing outdated information, correcting broken links, maintaining downloads, and checking that calls to action still work.
For content-heavy websites, this may be a regular service. For a smaller site, it may be occasional support. Either way, clarify whether the recurring plan includes content editing or only technical maintenance.
Content work can also expose technical issues. A new image may be too large, a page may lack an accessible heading structure, a translated version may be missing, or a CMS change may create duplicate URLs.
Content and technical maintenance should not be treated as completely separate when the site’s performance, usability, and discoverability depend on both.
6. Performance and Page Experience
Performance maintenance involves more than checking a single page-speed score. It should consider real-user experience, page weight, third-party scripts, caching, image delivery, server response, JavaScript execution, and the performance of important journeys.
Useful activities may include:
- Reviewing Core Web Vitals and real-user data
- Identifying slow templates or API calls
- Optimising images and media
- Reviewing caching and CDN behaviour
- Removing unnecessary scripts
- Testing mobile interactions
- Checking performance after releases
- Investigating regressions rather than chasing a score in isolation
If the website is built on a headless CMS or composable architecture, performance may depend on several systems: the frontend, CMS API, search service, image platform, authentication provider, and hosting environment.
Maintenance needs to include the relationships between those systems, not only the visible website. See our guide to headless CMS architecture for more on the flexibility and operational responsibility that come with separating content management from presentation.
7. Accessibility and Usability Checks
Accessibility should be maintained as the website changes. New templates, components, content, forms, and third-party widgets can introduce problems even when the original site was reviewed.
Maintenance checks may include:
- Keyboard navigation
- Focus states and focus order
- Form labels and error messages
- Heading and landmark structure
- Colour contrast
- Alternative text and media controls
- Responsive behaviour
- Screen-reader compatibility for important journeys
Automated tools can find some issues, but they do not replace manual testing or user-centred review. The appropriate level of testing depends on the audience, functionality, risk, and applicable obligations.
Accessibility should be considered during updates and content changes rather than reserved for a large audit every few years.
8. SEO and Discoverability Maintenance
SEO maintenance can include technical checks, indexation reviews, redirects, canonical URLs, structured data, internal links, metadata, sitemap health, content updates, and monitoring for search-impacting changes.
SEO should not be treated as a reason to create arbitrary monthly activity. The work should connect to an identifiable problem or opportunity.
Examples include:
- A migration that changed URLs
- New content that needs a logical internal-link path
- Pages that are indexed but no longer accurate
- Template changes that affect metadata or structured data
- Performance or accessibility problems affecting users
- Important service pages that do not reflect current capabilities
See our technical SEO services for deeper audits and remediation when website maintenance reveals a broader discoverability problem.
9. Analytics and Conversion Tracking
Website maintenance should include periodic checks that important analytics and conversion events still work. Forms, consent behaviour, analytics tags, call tracking, ecommerce events, and CRM integrations can break during design or platform changes.
A useful review asks:
- Are the important conversion events still recorded?
- Are duplicate or missing events distorting reports?
- Do forms still send data to the intended system?
- Are consent and privacy settings working as intended?
- Can the business distinguish traffic from meaningful enquiries?
The objective is not to collect every possible event. It is to preserve trustworthy evidence about how the website contributes to business outcomes.
10. Technical Support and Small Improvements
Most businesses need somewhere to send questions and unexpected problems. Support may include troubleshooting, minor fixes, advice, release assistance, and coordination with hosting or third-party vendors.
Clarify the boundaries. A maintenance plan may include a fixed number of support hours, a response-time target, or a defined class of small changes.
Larger feature development, redesigns, migrations, new integrations, and major content production usually require separate planning. A useful maintenance provider should help identify when a request has crossed that boundary rather than quietly treating project work as an undefined support task.
What Website Maintenance Does Not Automatically Include
Many disagreements come from the word “maintenance” being used to describe several different services. Before comparing providers, separate routine upkeep from project work.
Maintenance does not automatically include:
- A complete redesign
- New application features
- A new ecommerce capability
- A platform migration
- Large-scale content creation
- A full SEO campaign
- Brand strategy or conversion-rate optimisation
- Custom integration development
- Major accessibility remediation
- Emergency recovery after a serious compromise
- Hosting or third-party licence fees
- Legal or compliance advice
These activities may be available from the same provider, but they should be identified separately in the scope and budget.
For example, fixing a broken contact form may be maintenance. Replacing the form system, redesigning the enquiry workflow, connecting it to a CRM, and adding qualification logic is a project.
The boundary matters because it affects price, scheduling, testing, and responsibility.
How Much Does Website Maintenance Cost?
There is no single universal price for website maintenance. The cost depends on the website’s platform, complexity, business criticality, integrations, traffic, content volume, security needs, internal capability, and expected response time.
As a planning framework rather than a market promise, businesses commonly encounter these broad service shapes:
| Service shape | Typical scope | Usually suitable for |
|---|---|---|
| Basic technical upkeep | Updates, backups, simple monitoring, and limited support. | Relatively straightforward websites with low operational complexity. |
| Managed website maintenance | Technical upkeep plus security review, performance checks, content assistance, issue resolution, and regular reporting. | Business websites where forms, content, SEO, and reliability affect enquiries or reputation. |
| Application-level support | Ongoing engineering, infrastructure, integrations, release management, incident response, and defined service expectations. | Complex websites, ecommerce platforms, portals, and web applications. |
A small brochure site may need only occasional technical attention. A lead-generation website may justify a more active plan because forms, analytics, content, SEO, and performance affect the pipeline. An ecommerce site or customer portal may need defined response times, stronger monitoring, integration support, and recovery procedures.
Be cautious with generic pricing ranges presented as if they apply to every website. A low monthly fee may cover only automated updates and a basic backup. A higher fee may include real engineering availability, security response, release testing, and proactive improvements.
Those are different services, even if both are called a “maintenance plan.” A credible quotation should show the assumptions behind the price, what is included, what is excluded, and how additional work is approved.
Our custom software development cost guide explains the same principle from a broader product perspective: a credible budget is tied to delivery assumptions and operational requirements, not a feature label alone.
The Factors That Really Affect Website Maintenance Cost

Platform and Architecture
A hosted website builder, standard CMS, headless CMS, custom frontend, and web application each create different maintenance responsibilities.
A platform with fewer moving parts may reduce operational work, while a composable architecture may provide flexibility at the cost of more integration points to monitor.
Number and Type of Integrations
A website connected to a CRM, marketing platform, payment provider, search service, ERP, identity provider, or fulfilment system has more failure modes than a standalone site.
The cost is affected by API quality, authentication, data ownership, retries, monitoring, and how quickly an integration must be restored.
Custom Code and Release Risk
Custom functionality can create differentiation, but it also requires testing and maintenance. A plan should account for how code changes are reviewed, deployed, monitored, and rolled back.
Older custom code may also require more time to understand before it can be changed safely. Documentation, automated tests, deployment history, and environment access can materially affect the cost of maintaining it.
Business Criticality
The more revenue, customer service, or operational work depends on the website, the more important response time, monitoring, recovery, and clear ownership become.
A site that can be unavailable overnight does not need the same service model as one that processes orders continuously. The maintenance plan should reflect the consequences of failure.
Content and Change Frequency
A static website with occasional updates is different from a content platform with daily publishing, multiple editors, localisation, promotions, product data, or regulated content.
Frequent changes increase the value of review, testing, permissions, publishing controls, and a clear process for approving urgent changes.
Security and Data Sensitivity
Websites processing personal information, payments, accounts, or business-critical data require more careful access, logging, dependency, backup, and incident practices.
The cost of maintenance is affected not only by the number of pages but also by the sensitivity of the data and the consequences of unauthorised access or incorrect processing.
Internal Capability
If your team can handle content, first-line support, and routine reviews, an external provider may focus on engineering and escalation.
If the organisation has no technical owner, the maintenance service may need to include more monitoring, documentation, coordination, vendor management, and proactive management.
How to Choose a Website Maintenance Service
A maintenance plan should be evaluated like an operating agreement, not a list of vague promises.
Ask prospective providers:
- What exactly is checked, and how often?
- Are updates tested before production?
- Are backups stored separately and restoration-tested?
- What happens when an update breaks the website?
- What security monitoring is included?
- What response times apply to different severity levels?
- Who receives alerts, and who is responsible for action?
- Are content updates included? If so, how much?
- Are SEO, accessibility, analytics, and performance reviews included?
- What is explicitly out of scope?
- Which hosting, licence, and third-party costs are separate?
- Who owns the code, accounts, domains, infrastructure, and documentation?
- How will work and issues be reported?
- How are larger changes estimated and approved?
The strongest provider will not necessarily promise that nothing will go wrong. It will explain how problems are detected, communicated, contained, corrected, and learned from.
Look for evidence rather than polished language. A useful provider should be able to show an example maintenance report, explain its backup and restoration process, describe how it handles failed releases, and identify who will work on the website.
Warning Signs in a Website Maintenance Proposal
Be cautious when a proposal:
- Uses “unlimited support” without defining response times or exclusions
- Describes security as a single plugin or checkbox
- Promises backups without explaining restoration
- Offers a low fee while excluding all meaningful engineering work
- Does not identify who owns the accounts and infrastructure
- Treats every issue as an emergency billable task
- Provides no change history or maintenance report
- Cannot explain how staging, testing, and rollback work
- Bundles SEO, content, development, and support without measurable scope
- Requires permanent dependence on the provider to understand the website
A good maintenance relationship should make the website easier to operate and the client better informed. It should not make the system more opaque or create unnecessary dependence on one supplier.
A Practical Website Maintenance Schedule
The exact schedule depends on the platform and risk, but a useful operating rhythm may look like this.

Continuously or Daily
- Availability and critical workflow monitoring
- Security alerts where appropriate
- Backup job monitoring
- Error and integration alerts
Weekly or Fortnightly
- Review updates and dependency changes
- Check important forms, journeys, and integrations
- Review unusual errors or failed jobs
- Publish approved content changes
Monthly
- Apply and verify planned updates
- Review performance and real-user signals
- Check analytics and conversion tracking
- Review access and administrator accounts
- Confirm backup and recovery status
- Report completed work, risks, and recommendations
Quarterly or on a Risk-Based Schedule
- Test restoration or recovery procedures
- Review accessibility and important user journeys
- Review SEO technical health and redirects
- Review third-party services and licences
- Reassess support needs and business priorities
- Plan technical debt or larger improvement work
This schedule is a starting point, not a universal rule. A high-change ecommerce or application environment may require continuous delivery and more frequent automated checks. A low-change brochure site may need less frequent human intervention but should still have reliable backups, security, and ownership.
Website Maintenance as Total Cost of Ownership
Website maintenance is easier to budget when it is treated as part of total cost of ownership rather than an optional fee added after launch.
The full operating cost may include:
- Hosting and infrastructure
- Domain and DNS services
- CMS, plugin, framework, and SaaS licences
- Security and backup services
- Engineering and support time
- Content production and review
- Analytics and SEO work
- Accessibility and compliance work
- Incident response and recovery
- Planned modernisation and replacement
The cheapest monthly plan may not be the lowest-cost option if it increases the likelihood of downtime, manual work, security incidents, or rushed emergency fixes.
The most expensive plan may also be wasteful if it includes services the website does not need. The goal is a proportionate maintenance model tied to the website’s role, risk, and expected business value.
When Website Maintenance Becomes Modernisation
Maintenance can reveal that the underlying website needs more than routine care. Repeated deployment failures, unsupported dependencies, slow development, fragile integrations, poor content workflows, or unclear ownership may indicate structural problems.
Modernisation may be appropriate when:
- The current platform is no longer supported
- Small changes require disproportionate effort
- Security updates cannot be applied safely
- The architecture prevents important business improvements
- Integrations are unreliable or impossible to monitor
- Content teams cannot work without engineering help
- The website has become a critical application without application-level operational practices
Do not use maintenance as a way to hide a modernisation programme. If the system needs substantial architectural change, scope it as a deliberate initiative with discovery, risk management, and a delivery plan.
Our application modernisation strategy guide covers how to assess legacy systems and sequence change without treating replacement as the only option.
How Ridiculous Engineering Approaches Website Maintenance
Ridiculous Engineering approaches website maintenance as a combination of technical reliability, product context, and practical ownership.
The right plan may involve routine support, performance and security improvements, headless CMS or integration work, deployment improvements, or a broader modernisation assessment.
We work with organisations that need more than a generic support mailbox. That may mean helping an internal team establish a maintenance process, taking responsibility for a defined technical area, or providing ongoing engineering support for a website connected to important business systems.
The first step is to understand what the website does, which systems it depends on, what risks are currently visible, and what level of support the organisation actually needs.
Our software consulting and delivery support can help when the immediate maintenance problem is also revealing broader questions about ownership, architecture, delivery, or technical risk.
Website Maintenance Services
Need a maintenance plan that reflects how your website actually works?
Bring your current platform, integrations, support concerns, and recovery requirements. We can help define the work that should be routine, the risks that need engineering attention, and the improvements that belong in a separate roadmap.
Explore Web Engineering Services → Request a Maintenance Plan Quote →
FAQ
What is website maintenance?
Website maintenance is the ongoing technical, security, content, performance, accessibility, analytics, and support work required to keep a website secure, available, accurate, usable, and aligned with business needs.
How much does website maintenance cost?
The cost depends on the platform, complexity, integrations, business criticality, security needs, content volume, internal capability, and response expectations. A basic website may need occasional technical upkeep, while ecommerce sites, portals, and web applications may require managed engineering support and defined response times.
What is included in website maintenance services?
Services may include software updates, backups, recovery testing, security monitoring, uptime checks, performance reviews, content changes, accessibility checks, SEO maintenance, analytics checks, troubleshooting, and small improvements. The exact inclusions should be defined in the maintenance agreement.
Is website maintenance different from website support?
They overlap but are not identical. Maintenance is the planned work that keeps the website healthy. Support is the help provided when users or owners have questions or something unexpected happens. A service may include both, but response times, hours, and scope should be explicit.
Do I need a website maintenance plan if my site rarely changes?
Usually, yes. A low-change website still depends on hosting, domains, certificates, software, backups, forms, security, and third-party services. It may need less frequent work, but inactivity does not remove technical or operational risk.
Does website maintenance include SEO?
It can include technical SEO checks such as redirects, indexation, metadata, structured data, internal links, and sitemap health. Ongoing content strategy, link acquisition, and broader SEO growth work are usually separate services and should be scoped independently.
Who should own the website maintenance plan?
The business should have an accountable owner even when a provider performs the work. Ownership should cover access, priorities, content approvals, risk decisions, vendor coordination, and the decision to fund larger improvements.
When should a website be rebuilt instead of maintained?
A rebuild or modernisation project may be appropriate when the platform is unsupported, changes are disproportionately expensive, security cannot be managed safely, integrations are unreliable, or the current architecture prevents important business improvements. Routine maintenance should not be used to disguise a larger structural problem.