Get in touch

Have a project in mind? Tell us a bit about it.

Enquiry Form

Almost every agency and freelancer sells a website maintenance retainer, and almost every client who’s had one for more than a year has the same quiet suspicion: they’re not entirely sure what they’re paying for. That’s not always a sign of a bad-faith seller. It’s usually a sign that “maintenance” was never actually defined, just bundled into a monthly line item and left there. If you’re paying for one, or selling one, it’s worth pulling the bundle apart and looking at what’s genuinely necessary work versus what’s padding dressed up as a service.

The non-negotiable core: updates, backups, uptime

Three things belong in every real maintenance retainer, no exceptions. Core, theme, and plugin updates, applied on a schedule and tested afterward rather than auto-applied blind, because an update that breaks a checkout flow is worse than the vulnerability it patched. Backups that are actually verified to restore, not just scheduled to run; a backup nobody has tested is a backup you don’t actually have. And uptime monitoring that alerts a real person within minutes, not a dashboard nobody checks until a client calls angry.

If a retainer doesn’t clearly include these three, on a stated schedule, it’s not a maintenance plan. It’s a support contract wearing a maintenance plan’s name.

Security monitoring is worth paying for, generic “security scans” often aren’t

There’s a real difference between a firewall and malware scanner that’s actively configured for your specific site’s stack, and a generic scanning tool running its default settings that gets glanced at once a month. The first catches and blocks real attack patterns. The second mostly produces a PDF report that makes the retainer feel more substantial than it is. Ask specifically what’s being monitored, what the response time is if something is flagged, and who actually looks at the results. If the answer is vague, that line item is padding.

Performance checks should produce action, not just a score

A lot of retainers include a monthly speed test, and that’s fine as a data point, but a score by itself isn’t a deliverable. A useful performance line item means someone actually looks at what changed, a new plugin that slowed things down, an image library that’s grown bloated, a hosting resource ceiling being approached, and does something about it. If the “performance monitoring” in your retainer has never once resulted in an actual fix, you’re paying to be told a number, not to have your site kept fast.

Content updates: reasonable to include, easy to abuse

Small content edits, updating a staff bio, fixing a typo, swapping a banner image, are a reasonable inclusion in a retainer because they’re quick and clients genuinely value not having to think about them. Where this goes wrong is when “content updates” quietly expands to mean unlimited requests with no scope, which either makes the retainer unsustainable for whoever’s providing it, or means low-priority busywork crowds out the security and performance work that actually protects the site. A clear cap, a certain number of small edits per month, with anything larger scoped and quoted separately, keeps this fair on both sides.

What’s usually padding

A few things show up in retainers more because they sound valuable than because they are. A monthly “SEO health check” that’s really just confirming the sitemap still exists. A generic uptime badge or certificate that has no bearing on actual reliability. Boilerplate monthly reports that get sent whether or not anything meaningful happened, built more to justify the invoice than to inform the client. None of these are harmful to include, but none of them are worth paying a premium for either, and a retainer priced mostly around this kind of reporting theater is worth renegotiating.

How to evaluate a retainer you’re already paying for

Ask for a plain-language breakdown of exactly what happens each month, and specifically ask what would have gone wrong by now if the retainer didn’t exist. A maintenance plan that’s actually earning its cost should have a concrete answer: a vulnerability that was caught, a plugin conflict that was resolved before it caused downtime, a backup that got used. If the honest answer is “nothing’s really happened,” that either means the site is genuinely low-risk and a lighter plan makes sense, or it means nobody’s actually been checking.

How to price one if you’re selling it

The core three, updates, backups, uptime, are what justify a baseline monthly fee, because they require real recurring attention regardless of how quiet the site’s been. Everything past that should scale with actual site complexity and traffic: a small brochure site and a high-traffic e-commerce store shouldn’t be on the same flat retainer price, because the second one has more that can break and more at stake when it does. Being transparent about which line items are the essential core and which are add-ons builds more long-term trust than bundling everything into one number and hoping nobody asks what’s inside it.

A maintenance retainer isn’t a bad idea, most sites genuinely need ongoing attention, and most site owners genuinely don’t want to be the one giving it. The problem only shows up when the plan is sold as protection but built as a subscription nobody has to justify. Pulling it apart into what’s essential, what’s reasonable, and what’s filler is a five-minute conversation that most retainers, on both sides of the relationship, would benefit from having.