Website Maintenance Package Inclusions and What Belongs on the List
- Seven monthly items: security, updates, backups, uptime, speed, reports, edits.
- Quarterly work catches drift daily maintenance misses.
- Annual audit prevents most site-breaking emergencies.
- Edit hours scale from zero to ten based on tier.
- Push back on retainers that exclude core coverage.
- What every website maintenance package includes at the core
- Quarterly deep work in a real website maintenance package
- Annual big-ticket work in a website maintenance package
- Edit hours included in a website maintenance package
- Monitoring and reporting inside a website maintenance package
- Abels Residential case study on a complete website maintenance package
- What a website maintenance package should not exclude
- Website maintenance package includes different depth per tier
- Process inclusions in a website maintenance package
- Where to start evaluating website maintenance package inclusions this week
Website maintenance package inclusions are the fine print every buyer skips and then regrets. You sign the retainer. The vendor promises monthly updates, security, and support. Then three months in, you learn security means a Wordfence scan running on the free tier, updates means clicking auto-update in the dashboard, and support means email replies within 72 hours. This guide walks the full inclusion list a real website maintenance package should carry, tier by tier, so you know what to expect before you pay for month four.
You’ll get the seven-point monthly core, the quarterly deep-work list, the annual big-ticket items, the edit hours structure, the reporting standard, and the exclusion patterns you should push back on. Read straight through in about eleven minutes. Then compare your current retainer against the list and decide if you’re getting the coverage the sticker price implies. This is the reference every buyer wishes they had before signing the first retainer contract, and every vendor wishes buyers had before pushing back on scope.
What every website maintenance package includes at the core
Every real website maintenance package includes seven items on a monthly cadence: security updates, plugin updates, theme updates, verified backups, uptime monitoring, page speed check, and a monthly report. Anything missing means the retainer isn’t complete. Retainers that add these together for under $75 a month are almost always running on free-tier tools without human oversight.
These seven items map to real hours of work. Security updates applied within 48 hours: 30 minutes to an hour of scanning, testing, and applying. Plugin updates on a weekly batch: 1 to 3 hours. Theme updates on release: 30 minutes with child theme integrity checks. Backup verification with monthly restore testing: 30 minutes. Uptime monitoring with active response chain: 15 minutes of setup and continuous automated coverage. Page speed check on the home page and top three landing pages: 30 minutes. Monthly one-page report: 20 minutes. Total: 3 to 6 hours per month at minimum for a small site.
Security work in the monthly core
Security inclusion covers three layers. Core WordPress security patches applied within 48 hours of release. Plugin CVE monitoring through Wordfence Central, Patchstack, or WPScan, with fixes applied within 72 hours of disclosure. And a monthly login audit that removes stale admin accounts, resets weak passwords, and confirms two-factor authentication on every admin user with heightened permissions. Real retainers document these in the report. Fake retainers just claim security without listing what got done.
Update workflow in the monthly core
Update inclusion covers WordPress core, active themes, and every installed plugin. The workflow: pull staging on the first of the month, apply queued updates, run a smoke test on the checkout, forms, and top landing pages. If everything passes, apply to production during a low-traffic window with rollback ready. If something breaks, file a ticket with the vendor, pin the working version, and log the reason. The pinned-version log is the artifact every retainer should produce. It becomes the reference the day a new developer asks why WPForms is stuck on version 1.8.4.
Quarterly deep work in a real website maintenance package
The quarterly cadence is where average retainers coast and good ones separate themselves. Quarterly inclusions cover database optimization, image compression sweep, plugin bloat review, broken link scan, schema markup check, and a page speed rerun on the top ten pages by traffic. Each of these takes 1 to 2 hours per quarter. Together they surface the drift that daily maintenance can’t catch.
- Database optimization: expired transients, spam comments, revision bloat, orphan meta rows
- Image compression sweep: catches everything uploaded since the last quarter above 200 KB
- Plugin bloat review: honest question on whether each installed plugin still earns its slot
- Broken link scan: internal + external links across the whole site
- Page speed rerun: top ten pages by traffic, note any drops below 90 mobile
- Schema markup validation: confirms RankMath still issues valid JSON-LD after core updates
- SEO baseline check: primary keyword rankings on the top 20 tracked queries
Database cleanup that keeps the site fast
WordPress databases accumulate junk over time: expired transients, spam comments awaiting review, post revisions from every save, orphan meta rows from deleted plugins. Left alone, the database grows 5 to 20 percent a year with content that adds zero user value. Quarterly cleanup with WP-Optimize or wp-sweep drops the wp_options and wp_postmeta table sizes back to baseline, keeping admin dashboard load times fast and reducing backup archive size. A well-maintained WordPress database sits at 100 to 500 MB. A neglected one crosses 5 GB inside three years. Cleanup is 15 minutes quarterly and saves hours later.
Plugin bloat review
Every quarter, review every installed plugin against the honest question: do we still use this. Sites accumulate 10 to 30 plugins across their lifespan, and roughly 20 to 30 percent of those become dead weight. Old contact form plugins replaced by newer ones. Analytics plugins from a previous vendor. Redirect plugins bypassed by server-level rules. Removing dead plugins reduces update surface area, cuts security exposure, and improves page speed by an average of 5 to 15 points on mobile PageSpeed. The bloat review is a 30-minute quarterly task that compounds.
Annual big-ticket work in a website maintenance package
Annual work covers the items that don’t fit the monthly or quarterly cadence but must happen once a year. PHP version planning, WordPress major version audits, SSL renewal verification, hosting stack review, security posture audit, and a full disaster recovery drill. Retainers that don’t include annual work usually push each of these to a paid change order, which turns a routine annual audit into a $2,000 project.
PHP version planning matters because WordPress supports specific PHP versions, and each version reaches end-of-life. Sites running PHP 7.4 in 2026 face security and performance issues, plus incompatibility with modern plugins. The annual review assesses the target PHP version, tests on staging, then coordinates the hosting bump. WordPress major version audits do the same for the WordPress platform itself. Both items are 4 to 8 hour projects annually that keep the site current without triggering a costly emergency migration.
Annual disaster recovery drill
The annual disaster recovery drill is the honest test on your backups. Pull the latest off-site archive. Spin up a fresh staging environment on a different host if possible. Restore the full site. Time the process. Document every step. Fix any failure points. Sites that run this drill annually recover from real disasters in 30 to 90 minutes. Sites that never test their backups usually spend 12 to 48 hours in a panic reinstall the first time something serious breaks. The drill is 2 to 4 hours annually and is the highest-return line item on the whole retainer.
Security posture audit
The annual security audit reviews everything a monthly scan misses. User account inventory: prune stale contributors, editors, and administrators. Login attempt log review: look for patterns indicating targeted attempts. Firewall rule review: check that hosting-level or plugin-level firewalls carry the latest CVE blocklists. Two-factor authentication compliance: confirm every admin account has 2FA enabled. Session token expiration: reset any long-lived tokens issued outside standard workflow. Each of these tasks takes 15 to 45 minutes annually. Stacked together they take a security posture from acceptable to defensible.
If your retainer is under /month, someone's clicking auto-update in the dashboard and calling it security. Ask when your last verified backup restore actually ran.
Edit hours included in a website maintenance package
Edit hours are the release valve on every retainer. Without them, every small change triggers a billable ticket. With them, the client and vendor work smoothly through routine content changes. Real retainers include one to ten hours a month depending on tier. Anything beyond bills at the vendor’s hourly rate, usually $95 to $195.
| Tier | Included edit hours | Typical use |
|---|---|---|
| Starter ($75-$200) | 0-1 hours | Occasional content edit |
| Growth ($200-$500) | 2-3 hours | Monthly blog + small updates |
| Ecommerce ($500-$1,500) | 3-5 hours | Product edits, promo updates |
| Enterprise ($1,500-$2,500) | 5-10 hours | Landing pages, campaign builds |
What counts as an edit hour
Edit hours cover changes that don’t require developer intervention. Content updates: publishing blog posts, editing service pages, updating team bios. Copy tweaks: changing hours, phone numbers, promotional banners, testimonials. Image swaps: uploading new headshots, replacing hero images, refreshing gallery photos. Small design fixes: adjusting spacing, changing button colors, tweaking mobile responsiveness. Form edits: adding a field, changing a notification email, updating confirmation copy. Menu changes: adding items, reordering navigation, updating footer links. Anything on that list should count as included.
What doesn’t count as an edit hour
Bigger work doesn’t fit inside edit hours. New page builds: usually billable at 2 to 8 hours per page. New plugin installations with configuration: billable at 1 to 3 hours. Ecommerce product uploads at scale: billable per product. Custom code work: always billable. Design changes touching the theme structure: usually billable. Integrations with third-party services: billable at 2 to 10 hours per integration. Get this list in the contract so nothing about billable versus included is a surprise later.
Monitoring and reporting inside a website maintenance package
Monitoring inclusion covers uptime, performance, and security. Real retainers run uptime monitoring at 60-second intervals or shorter, with notifications through Slack, SMS, or PagerDuty to a real person. Performance monitoring runs monthly PageSpeed checks and Core Web Vitals reviews. Security monitoring runs continuous plugin CVE scans and monthly login audits. All three streams feed the monthly report.
Reporting inclusion is the artifact that proves the retainer is working. The monthly one-page report should list: uptime percentage with any incidents, updates applied (core, themes, plugins, count and pinned versions), backup verification results with the last successful restore test date, page speed scores for the top five pages, security events (scans run, incidents handled, user accounts pruned), and next month’s planned work with any risks flagged. Six sections, one page, delivered by the fifth of the month. Anything longer is padding.
Uptime monitoring standard
The uptime standard for a serious retainer runs at 60-second check intervals from multiple geographic regions with a notification chain that reaches a person inside three minutes. Free-tier UptimeRobot at 5-minute intervals is acceptable for Starter tier. Better Stack or StatusCake at 60-second intervals is standard for Growth and above. Enterprise tier often adds synthetic monitoring that runs a full checkout or lead form submission every 5 minutes to catch functional failures the ping-based monitors miss.
Performance tracking through Core Web Vitals
Google Search Console reports Core Web Vitals from real Chrome user data. Every month, the retainer opens Search Console, reviews the Core Web Vitals report, and lists any pages moving from good to needs-improvement or from needs-improvement to poor. Fix the shifts before they become site-wide rank drops. Reference the web.dev Core Web Vitals guide for the current thresholds. Real retainers track CWV monthly and flag any regression on the next report. Fake retainers claim performance monitoring without ever opening Search Console.
Abels Residential case study on a complete website maintenance package

Abels Residential, a London-based real estate lettings agency, ran a Web + SEO engagement with us that included the full maintenance package on their WordPress lettings platform. The site handles rental inquiries, property listings, and lead capture across a competitive London market. The retainer covered the seven-point monthly core, quarterly deep work, and a full annual audit that surfaced two PHP compatibility issues before they became emergencies.
Results across the engagement: 20-plus qualified rental leads per month, 300-plus keywords ranked, and page load times at 2 seconds on the main service pages. The maintenance retainer preserved those numbers month over month by catching plugin conflicts on staging before they hit production, keeping the site fast through routine WordPress updates, and running the security scans that kept the login secure across 12 months without incident. Every included inclusion earned its slot on the retainer.
Transferable inclusions for lead-generation sites
The inclusions transfer to any lead-generation site running WordPress. Staged testing on the form flow. Quarterly page speed audits on the money pages. Monthly Core Web Vitals review through Search Console. Two included edit hours a month for content updates. Every one of these is a Growth-tier standard, running $300 to $500 monthly. Sites that skip any of them usually lose organic ranking, break the form, or lose data on a bad backup within 12 to 18 months.
The annual audit paid for itself
Abels’s annual audit surfaced two PHP compatibility issues that would have broken the site during the next major WordPress core release. Cost to fix inside the annual audit: 4 hours, absorbed by the retainer. Cost to fix during an emergency post-outage: 12-plus hours of downtime, panic support hours, and lost lead revenue. The annual audit paid for itself before it happened. This is the pattern the retainer prevents you from ever noticing, because the emergency never happens in the first place.
Every retainer buyer eventually asks the vendor the same question. What exactly did you do this month. The vendor sends a 12-page PDF with pie charts, brand color palettes, and phrases like “strategic optimization initiatives” repeated across three pages. Buried on page nine is a single line item: updated 3 plugins. That’s the whole report. The buyer stares at page nine for a minute. Then subscribes to a new retainer that ships a one-page report instead.
What a website maintenance package should not exclude
Push back on any retainer that excludes core coverage. Security updates, backup verification, uptime response inside SLA, monthly reporting, and quarterly deep work should never sit outside the retainer. If a vendor says outage response costs extra, walk away. Legitimate exclusions are project work: new page builds, custom code, integrations with third-party services.
Legitimate exclusions typically include: new page builds, new plugin installations with custom configuration, ecommerce product uploads at scale, custom code work, design changes touching theme structure, third-party integrations, and content creation (blog posts, whitepapers, videos). These are project work priced at hourly rates or project bundles. Retainers that quietly include content creation in the retainer are subsidizing it from your maintenance budget, which usually means the maintenance suffers.
Red flag exclusions
Red flag exclusions signal a vendor selling the illusion of maintenance. Emergency response as an extra: signals the vendor won’t respond during outages without a surcharge. Backup restoration as an extra: signals the vendor won’t honor their own backup coverage. Plugin conflict resolution as an extra: signals the vendor pushed updates without staging. Monthly reporting as an extra: signals the vendor doesn’t want to prove what got done. Every one of these is a walk-away signal. The retainer that hides its scope in exclusions is the retainer that will disappear during the actual work.
The honest project line
Every retainer has a project line where routine maintenance ends and project work begins. Real vendors draw the line clearly in the contract. Anything under 30 minutes of dev time is included. Anything over 30 minutes triggers a change order at the hourly rate. This kind of scope clarity smooths the entire relationship. Ambiguous vendors let scope creep run for a month, then send a surprise invoice for 8 hours of unbilled work. The 30-minute rule is one of the fairest structural elements in maintenance contracts.
Website maintenance package includes different depth per tier
Each tier keeps the same inclusion categories but scales the depth. Starter includes the seven-point monthly core, quarterly light-touch work, and zero to one edit hour. Growth adds staged rollouts on any form-touching update, monthly Core Web Vitals reviews, and two to three edit hours. Ecommerce adds weekly backup verification, transaction integrity checks, PCI compliance, and three to five edit hours. Enterprise adds custom code review, PHP upgrade planning, dedicated engineer on call, and five to ten edit hours.
The tier that fits your site depends on three factors: how many plugins run on the site, whether transactions happen in real time, and how much custom code sits under the theme. A five-page dentist site with no forms fits Starter. A chiropractic site with online booking fits Growth. A WooCommerce store fits Ecommerce. A multi-site enterprise install fits Enterprise. Match your site to the tier honestly. Overpaying on Enterprise for a brochure site wastes money. Underpaying on Starter for a WooCommerce site loses revenue during the first outage.
When to upgrade the tier
Upgrade the tier when the site’s complexity moves up a band. Adding ecommerce triggers a jump from Growth to Ecommerce. Adding custom Gutenberg blocks or a custom REST endpoint triggers a jump to Enterprise. Doubling plugin count triggers a jump within the tier. Retainers that stay locked at Starter while the site grows into Growth or Ecommerce complexity eventually break during a routine update. Renegotiate the tier every 6 to 12 months as the site changes.
When to downgrade the tier
Downgrade when the site simplifies. Removed an ecommerce section. Consolidated 40 plugins down to 15. Migrated custom code to a standardized plugin. Downgrading is fair. Talk to the vendor about the change. Most will accommodate a tier drop without breaking the contract because a slightly smaller monthly commitment beats losing the client entirely. Downgrade discussions also help you sanity-check whether the vendor is honest about scope.
Process inclusions in a website maintenance package
Process inclusions are the invisible items that determine whether the technical work actually happens. Staging environment for testing updates. Version-controlled deployments. Communication protocol during outages. Quarterly review calls with the client. Documentation shared with the client. Onboarding runbook produced during setup. Offboarding process defined in the contract. Each of these is a process, not a technical task, but the retainer works or fails on them.
Ask the vendor to walk you through each process on the sales call. Show me the staging environment. Show me the last monthly report. Walk me through an outage response from your log. Show me a client’s documentation. Show me the onboarding checklist. Vendors that produce these artifacts on demand are running a real operation. Vendors that promise them for later are still figuring out how to run the operation. Trust the artifacts, not the promises.
Staging environment as a core process inclusion
The staging environment is where every plugin update gets tested before it hits production. Managed hosts like Kinsta, WP Engine, and Cloudways ship one-click staging. Cheaper shared hosts don’t. If your vendor can’t produce staging on demand, either the hosting is wrong or the process is missing. Both need to change before you renew. Staging is not optional. Retainers that skip staging are testing updates directly in production, which is where the outages come from.
Quarterly review call
Every quarter, the vendor schedules a 30-minute review call. Walk the numbers. Discuss any pinned plugins that need attention. Plan any larger work for the following quarter. Adjust the retainer scope if the site has grown. This call is where the retainer transitions from a monthly transaction to a real strategic relationship. Vendors that skip the quarterly review coast into complacency. Vendors that hold it stay accountable.
Where to start evaluating website maintenance package inclusions this week
Print the seven-point monthly checklist. Print the quarterly list. Print the annual audit list. Compare each to your current retainer. Note gaps. Ask your vendor about each gap. The vendor should either produce evidence the item runs or acknowledge the gap and quote a tier upgrade to close it. If the vendor deflects on any item, you have the answer.
Then read the last three monthly reports the vendor sent. Count how many of the seven monthly items appear in the report. If any are missing, ask why. If the vendor responds with process specifics, they’re doing the work. If they respond with vague reassurance, they’re not. Reference our WordPress website maintenance packages guide for the platform-specific inclusion detail. Our website maintenance package pricing post covers the tier math. If you’re still deciding whether the retainer is worth it, our do you need a website maintenance package post walks the argument. For the full service, our monthly website maintenance packages service page lists inclusions by tier. Also review the Kinsta maintenance checklist, the WP Rocket task list, and the WordPress security guide for third-party references.
Frequently asked questions
What should a website maintenance package include at minimum
At minimum, a website maintenance package should include core WordPress security updates within 48 hours of release, plugin updates on a weekly batch tested on staging first, theme updates on release, verified daily backups with monthly restore testing, uptime monitoring at 60-second intervals with a real notification chain, monthly page speed checks on top pages, and a one-page monthly report. These seven items are the non-negotiable core. Anything less and the retainer isn't complete. Higher tiers add staged rollouts on major updates, quarterly deep-work like database optimization, and included edit hours. The delta between tiers usually reflects response time and testing depth more than fundamentally different technical work.
What is included in a monthly website maintenance package
A monthly website maintenance package includes seven core items: security patches applied within 48 hours, plugin updates run through staging before production, theme updates with child theme integrity checks, backup verification with occasional restore testing, uptime monitoring at 60-second intervals, page speed checks on the home page and top three landing pages, and a one-page monthly report. Growth tier and above add included edit hours, monthly Core Web Vitals review from Search Console, and staged rollouts on any form-touching update. Ecommerce tier adds weekly backup verification and transaction integrity checks. Enterprise tier adds custom code review and dedicated response times.
Does a website maintenance package include content updates
Yes, most website maintenance packages include content updates within a set number of edit hours. Starter tier includes zero to one hour a month. Growth tier includes two to three hours. Ecommerce tier includes three to five hours. Enterprise tier includes five to ten hours. Content updates that fit inside edit hours: publishing blog posts, editing service pages, updating team bios, changing hours or phone numbers, swapping images, small design tweaks, form field edits, and menu changes. Anything over the included time bills at the vendor's hourly rate, usually $95 to $195. New page builds, plugin installations with custom configuration, and design overhauls are almost always billable separately.
What does a website maintenance package not include
A website maintenance package usually does not include new page builds, new plugin installations with custom configuration, ecommerce product uploads at scale, custom code work, design changes touching the theme structure, third-party integrations, or content creation like blog writing or video production. These are project work priced at hourly rates or project bundles. Retainers that quietly include content creation in the maintenance budget are subsidizing project work from your maintenance dollars, which usually means the maintenance suffers. Push back if any of these are hidden inside the retainer. Also push back if backup restoration, plugin conflict resolution, or outage response are excluded, because those should be included by definition.
How often should tasks in a website maintenance package run
Different tasks run on different cadences. Weekly: plugin update batches, uptime monitoring reports. Monthly: WordPress core patches within 48 hours of release, backup verification, one page speed check, one Core Web Vitals review, one login audit, and the monthly report by the fifth of the month. Quarterly: database optimization, image compression sweep, plugin bloat review, broken link scan, schema markup validation, and a full page speed rerun on the top ten pages. Annually: PHP version planning, WordPress major version audit, SSL renewal verification, hosting stack review, security posture audit, and a full disaster recovery drill. Every retainer should list which tasks fall on which cadence in the contract.
How do I know if a website maintenance package is doing the work
Read the monthly report. Six sections, one page: uptime percentage with any incidents, updates applied with count and pinned versions, backup verification results with last restore test date, page speed scores for top pages, security events including scans and account pruning, and next month's planned work. If any of these are missing, ask why. If the vendor responds with process specifics like the exact update workflow or the restore test log, they're doing the work. If they respond with vague reassurance about strategic initiatives or full-stack coverage, they're not. Also ask for the pinned-plugin log and the staging environment URL. Real retainers produce these artifacts on demand.
Book your free 30-minute strategy call.
No spam, no sales rep. We use your email to schedule your call with a senior strategist. That is it.