Budgeting & Planning

What a Website Maintenance Report Should Tell You

Most small businesses treat the website as a project that finished. It was built, it was paid for, it went live. Then a set of small charges keeps appearing — a renewal here, a licence there, an invoice from whoever fixed the thing that broke — and none of it sits in the budget under a single heading, so nobody can say what the website actually costs to run.

It is an operating cost, like insurance or your accounting software, and it should be budgeted the same way: named line items, known renewal dates, and a report each month that tells you what you got. This article covers what recurs, what a maintenance report has to contain to be worth reading, and how to plan a year of it.

The costs that actually recur

Separate the one-off build from the standing costs. The standing costs, for a typical small-business site, are:

  • Domain registration — annual, per domain. Include the variants you defensively registered and forgot about.
  • Hosting — monthly or annual. This is the one people compare on price alone, which is usually a mistake, because the cheap tier and the resilient tier differ mainly in things you only notice on a bad day.
  • SSL certificate — often included free with hosting now, sometimes a separate line. Check which yours is.
  • Premium plugin and theme licences — the easiest costs to lose track of, because they renew quietly and often on different dates. A form builder, a booking system, a page builder, a security plugin: each with its own anniversary.
  • Backup storage — if backups are stored somewhere other than the host, that is a separate subscription.
  • Email or SMTP sending service — if the site sends notifications or receipts through a transactional service.
  • Maintenance labour — either a retainer or ad-hoc hours. This is the line that is usually unbudgeted, and it is the one that arrives at the worst possible moment when it is ad-hoc.

Write these into a single schedule with amounts and renewal dates. Most owners discover two things immediately: a subscription nobody uses, and a renewal that lands in the same month as several others. Both are useful findings, and both belong in the process described in our guide to building a business budget.

What a monthly maintenance report must show

If you pay a retainer, the report is the product. A dashboard screenshot and the words "all good" tell you nothing you can verify or act on. A useful report answers six questions:

1. What was updated, and to which versions? Names and version numbers — WordPress core, plugins, theme, and the PHP version the site runs on. This matters because "we did updates" is unfalsifiable, whereas a version list is a record you can compare month to month. It is also how you spot a plugin that has not moved in a year.

2. What went wrong, and what was done about it? An update that failed and was rolled back, a broken layout, a form that stopped working. A report with no incidents ever is not a report of a perfect site; it is a report that does not record incidents.

3. Was a backup taken, and was a restore actually tested? Those are two different claims. A backup job that reports success and a backup that has been restored successfully are not the same thing, and only the second one is insurance. Ask when the last test restore was performed.

4. What was the availability record, and were there outages? You want the actual observed record for the month with any incidents listed and their duration — not a marketing figure. If the site went down, the report should say when and for how long.

5. What did the security and performance checks find? Scan results, whether anything needed action, and a like-for-like performance measurement taken the same way each month so the numbers are comparable.

6. What needs a decision from you? The most valuable section, and the one most often missing. A plugin that is no longer maintained, a licence expiring, a hosting plan the site is outgrowing. These are budget decisions, and you want them with notice rather than as an emergency.

Red flags in a report

  • No version numbers. Nothing else in the report can be checked without them.
  • No incidents, ever. Real sites have events. A permanently clean record usually means events are not being recorded.
  • Backups mentioned but never tested. The most common gap between what people think they are buying and what they have.
  • Hours billed with no description. "Maintenance — 4 hours" is not a line item; it is a number.
  • No recommendations. A provider who never proposes anything is either not looking, or is looking and not telling you.
  • A different format every month. You cannot compare what is not comparable. Consistency is a feature.

None of these mean you are being cheated. Most often they mean the reporting was never specified, and a reasonable provider will improve it if you ask. Specify it in the agreement rather than hoping.

Comparing plans without comparing only price

When you evaluate providers, the useful question is not the monthly figure but what the figure covers, and specifically where the boundary sits between "included" and "billed separately." Ask for that boundary in writing.

Look for a provider whose service lines are named distinctly, because that tells you where the boundaries are. WPCare, for example, publishes separate lines for WordPress maintenance and support, WooCommerce support, speed optimisation, server management, malware removal, and emergency support — the reason that structure is worth looking for is that a single undifferentiated "we look after your site" price hides the question you actually need answered: when something breaks at 6pm, is the fix inside what you already pay, or is it a new invoice? Get that answer before you sign, from whoever you are considering.

Then compare like with like: same scope, same reporting frequency, same response arrangement. A cheaper plan that excludes emergency work is not cheaper; it is a different product with a deferred cost.

Budgeting the year

Three lines in your annual budget, and the third is the one people skip:

  1. Fixed recurring — domain, hosting, licences, storage. Known amounts on known dates. Put every renewal date in a shared calendar with a reminder ahead of the charge, so a renewal is a decision rather than a surprise.
  2. Maintenance — the retainer, or a realistic estimate of ad-hoc hours if you have no retainer. Be honest about the second one: look at last year's invoices rather than what you hope this year looks like.
  3. Contingency — a set-aside for the unplanned: an emergency fix, a plugin that has to be replaced, a hosting upgrade the site grew into. Size it from your own history, not from a rule of thumb someone published. If you have never tracked it, start by logging every unplanned website expense this year; next year's figure will be based on evidence.

Review the whole schedule once a year, at the same time as your other supplier renewals. Cancel what nothing depends on, and confirm that what is left still matches what the site actually needs.

FAQ

How much should a small business spend on website upkeep?

There is no defensible universal figure, and anyone quoting one is guessing about your site. The answer depends on how much of your revenue arrives through the site, how complex it is (a shop with payments and stock is a different animal from five brochure pages), and how quickly a problem must be resolved. Build the number from your own line items — recurring subscriptions plus maintenance plus contingency — rather than from a benchmark.

Can I just do the updates myself and skip the retainer?

Plenty of owners do, and for a simple site it can be a reasonable choice. Cost it honestly, though: your time at whatever your time is worth, plus the fact that the update you are least likely to do is the one that needs judgement — a version that breaks a page, or a plugin whose author has stopped maintaining it. The realistic comparison is not "retainer versus free," it is "retainer versus my hours plus the risk I am carrying."

What should I do if my provider won't give me a detailed report?

Ask once, specifically, listing the six items above — most providers can produce them and simply were not asked. If the answer is still no, that is information: you cannot manage a supplier whose work you cannot see. Detailed reporting is a normal thing to require in a service agreement, not an unusual demand.

Is website maintenance a capital or operating cost?

The recurring elements — hosting, licences, maintenance labour — are operating costs and belong in your regular expense budget. A substantial rebuild or a new feature is a different kind of spend. Treat them separately in your accounts so the ongoing cost of running the site stays visible, and check the specific treatment with your accountant, since the rules depend on your jurisdiction and how the work is structured.

Next step

Build the schedule this week: every website-related recurring charge, its amount, and its renewal date on one page. That single document usually pays for itself in cancelled subscriptions and avoided surprise renewals. Then ask whoever maintains your site for a monthly report covering the six items above — versions, incidents, tested backups, availability, checks, and decisions needed. If you are choosing a provider, ask each one where "included" ends and "billed separately" begins, and look for clearly separated service lines like those WPCare publishes, because a defined scope is what makes a maintenance cost something you can budget rather than something that just arrives.

Comments are disabled for this article.