Our WorkAll ServicesAI VisibilitySEO AutomationProduct ManagementClaude AI ServicesZatrovo BookingStart a Project
revenue · 8 min read · 5 August 2026

Website Maintenance Costs for UK Businesses in 2026

What UK small businesses actually pay to keep a website running in 2026, what maintenance covers, and how to tell a fair quote from a padded one.

Jacob Horgan, Founder, Irvale Studio
Jacob Horgan
Founder, Irvale Studio

Most UK owners find out what website maintenance costs at the worst possible moment: the site is down, the phone is not ringing, and the person who built it four years ago has stopped replying. This guide breaks the cost into the parts you can price yourself, the parts that vary honestly, and the parts that are padding.

What does website maintenance actually cover?

Website maintenance covers five distinct jobs: hosting the site, patching the software it runs on, backing it up and testing that the backup restores, monitoring uptime and forms, and handling small content or fix requests. Suppliers bundle these differently, which is the main reason quotes look impossible to compare.

Write those five jobs down as a list before you ask anyone for a price. A quote that covers hosting and nothing else is not wrong, it is just narrow, and you will end up paying separately for the rest. The most expensive outcome is assuming a line item exists when it does not.

The fifth item, small changes, is where quotes diverge most. Some suppliers include a fixed pool of hours. Some bill everything hourly. Neither is dishonest, but they suit different businesses. If you change your prices, staff photos and opening hours a few times a year, a small included allowance is worth paying for. If your site genuinely never changes, buy the first four jobs and pay hourly for the fifth.

How much does website maintenance cost in the UK?

Hosting is the only component with public list prices you can verify in a minute. UK shared hosting generally runs from single figures a month at the entry level to roughly £100 a month at the top of a shared range, and hosts publish those prices openly. The labour half of maintenance has no list price, because it scales with how complicated your site is.

Anyone quoting you a single national average for maintenance is guessing. What you can do is anchor the parts. Check the current published price for the tier you actually need on the host's own site, whether that is a UK provider such as Krystal or a larger international one, treat the domain renewal as a small fixed annual cost, then judge the labour quote against a written scope rather than against a number you read in a listicle.

A practical method: send the same one page scope to three suppliers. State the platform, the number of plugins or integrations, whether you take payments, and how many change requests you expect a year. The spread you get back is your real market rate, and it is specific to your site rather than to an average of everybody else's.

Why does the same site cost one agency twice what another quotes?

Because they are pricing different amounts of risk. A supplier who tests updates on a staging copy before pushing them live, and who guarantees a restore, is carrying work that a supplier clicking update on a Friday afternoon is not. The cheaper quote is usually cheaper for a reason you can identify by asking one question.

Ask this: do you test updates on a staging copy first, and have you restored a backup for any client in the last quarter? The answers separate the market quickly. Staging costs money because it is a second copy of the site. Restore testing costs time because nobody does it while things are calm. Both are the difference between a maintenance plan and a monthly invoice.

What actually breaks when nobody is maintaining a site?

Plugins go stale, PHP branches fall out of support, contact forms silently stop delivering, and certificates lapse. The form failure is the one that costs UK small businesses the most money, because it produces no error and no alert, just a quiet absence of enquiries that gets blamed on a slow month.
Over 90%Share of WordPress ecosystem vulnerabilities reported in plugins rather than core
Source: Patchstack, State of WordPress Security
43%UK businesses that identified a cyber breach or attack in the previous 12 months
Source: DSIT, Cyber Security Breaches Survey 2025
31 Dec 2025Date security support ended for the PHP 8.1 branch
Source: php.net, Supported Versions
31 Dec 2026Date security support is scheduled to end for the PHP 8.2 branch
Source: php.net, Supported Versions

Patchstack's annual State of WordPress Security reporting has consistently found the same pattern: thousands of new vulnerabilities disclosed across the WordPress ecosystem each year, with the overwhelming majority in plugins rather than in WordPress core, and a meaningful share of them disclosed publicly before a patch is available. If your site runs plugins, you are inside that population whether or not you ever log in.

On the business side, the government's Cyber Security Breaches Survey, published annually by DSIT, found 43 per cent of UK businesses identified a breach or attack in the previous 12 months. Most of those incidents are not sophisticated. They are unpatched, well documented flaws in software that somebody should have updated.

How do I know if my hosting already covers this?

Read the hosting terms and find the sentence where the provider's responsibility ends. Most UK hosts cover the server, the network and a backup schedule. Almost none cover the application code sitting on top, which is exactly where the vulnerabilities live.

Server level defences and firewalls help, but they are written to protect infrastructure rather than to understand your particular plugin stack. That is not a criticism of hosts. It is a description of scope. A host protects the building, not the contents of your flat. If your quote covers hosting only, write down who owns plugin updates, PHP upgrades and restore testing, and get that answer in the contract.

What about the PHP version nobody mentions?

Every WordPress, Laravel or Drupal site runs on a PHP branch, and each branch has a published end of life date. Running past that date means no security fixes are being issued for the language your site is written in, no matter how current your plugins are.

PHP publishes the calendar openly. According to PHP's own supported versions page, security support for the 8.1 branch ended on 31 December 2025, and security support for the 8.2 branch is scheduled to end on 31 December 2026. Upgrading a major PHP branch is the kind of job that appears once every couple of years, takes real testing, and is either inside your maintenance agreement or it is not. Get that in writing, because a surprise upgrade invoice is a common source of friction.

Is a retainer better than paying per job?

A retainer makes sense when the cost of downtime is higher than the cost of the retainer, which is true for any site taking bookings, payments or enquiries. Pay per job makes sense for a brochure site with no forms and no transactions, provided somebody is still watching the certificate and the domain renewal.

The honest trade off is response time. On a retainer you are in a queue with a stated turnaround. Ad hoc, you are in a queue behind everyone on a retainer. If a broken checkout costs you a day of trade, that queue position is the thing you are actually buying.

Be sceptical of retainers that bundle in reporting you never read. Monthly PDFs of traffic charts are cheap for a supplier to generate and easy to mistake for value. If you want the analytics side taken seriously, treat it as its own piece of work with its own goals rather than as filler inside a maintenance fee.

What can I do myself to cut the bill?

Three things reduce cost immediately: delete plugins you do not use, own your own domain and hosting accounts, and write down how your site works. Plugin count is the single biggest driver of ongoing update labour, and plugins are where the large majority of WordPress vulnerabilities appear.

Audit the plugin list this week. Most small business WordPress sites carry several plugins installed for a one off task years ago and never removed. Each one is code that must be updated, tested and trusted forever. Removing four of them is a permanent reduction in your maintenance surface.

Second, check the registrar record for your domain and confirm it is in your company name. This costs nothing and prevents the worst handover scenario.

Third, write a one page document covering where the site is hosted, who holds each login, which plugins do what, and what to do if a form stops sending. It turns an emergency into a task. Owners who have already used automation to cut their admin hours tend to find this the easiest habit to add.

How do I tell whether the maintenance is working?

Working maintenance produces evidence: dated update logs, a restore test you can point to, an uptime record, and a live test submission from your own contact form landing in the right inbox. If your supplier cannot produce those four things on request, you are paying for intent rather than outcome.

Set a quarterly reminder and check all four yourself. Send a test enquiry from the public form. Ask for the update log. Ask when a backup was last restored, not when one was last taken. Ask which PHP branch you are on and cross reference it against the php.net calendar. Fifteen minutes, four times a year, and you will never be the owner who discovers a problem from a customer.

Next stepGet a plain English maintenance reviewA written scope, current PHP and plugin status, and what it should honestly cost.

The uncomfortable truth about website maintenance pricing in the UK is that the cheap end and the expensive end often describe entirely different work, and the invoice does not say which one you bought. Price the hosting yourself, put the labour out to a written scope, and judge every quote on whether the supplier can show you a restore. That single question sorts the market faster than any comparison table.

Common Questions

Website Maintenance Costs for UK Businesses in 2026 — FAQ

What is a realistic monthly budget for website maintenance in the UK?

Split the bill in two before you budget. Hosting is the half with published prices, so you can check the real figure yourself in a minute: UK shared hosting typically runs from single figures a month at the entry level up to around £100 a month at the top of a shared tier, and every reputable host lists those prices openly. The second half is human time: updates, testing, backups, fixes and small content changes. That half has no list price because it scales with how many plugins, integrations and pages you run. Ask three suppliers to quote against the same written scope, and the spread you get back tells you more about your real market rate than any national average published in a listicle.

Do I still need maintenance if my website never changes?

Yes, because the software underneath it keeps changing even when your content does not. Patchstack's annual security reports log thousands of new vulnerabilities across the WordPress ecosystem each year, and the large majority sit in plugins rather than in core. A brochure site with a contact form and six plugins is still running that code, and it is still reachable from the public internet. Static sites built without a database and without plugins genuinely need less attention, which is one honest reason to consider rebuilding a rarely updated site on a simpler stack. Even then, somebody has to watch the domain renewal, the certificate, the DNS records and the forms, because those fail quietly rather than loudly.

Is hosting the same thing as maintenance?

No, and conflating the two is the most common reason UK owners believe they are covered when they are not. Hosting rents you the server, and usually includes the network, a certificate and some level of backup. Maintenance is the ongoing work of keeping the application on that server current, tested and functioning: plugin and core updates, PHP branch upgrades, restore tests, form checks and fixes. A host protects the building. It does not look after the contents of your flat. Read your hosting terms and find the sentence where the provider's responsibility stops, then decide who owns everything after that point. If the answer is nobody, that gap is where your next outage comes from.

How do I check whether my current supplier is actually doing the work?

Ask for evidence rather than assurance. Request the last three months of update logs showing what was patched and when, a restore test from backup with the date it was actually performed, and the PHP branch your site currently runs on. PHP publishes its own support calendar: security support for the 8.2 branch is scheduled to end on 31 December 2026, and the 8.1 branch stopped receiving security fixes at the end of 2025. If your supplier cannot tell you which branch you are on, you have your answer about the quality of the service. A supplier who is genuinely doing the work will have all three ready without needing a week to prepare them.

What should I do before switching maintenance providers?

Take control of the assets first. Check that the domain is registered to you or your company rather than to the agency, and that you hold the registrar login yourself. Get a full backup of files and database into storage you control. Confirm who holds the DNS, the certificate, the hosting account and any third party services such as payment, booking or email tools. Only once you have that list should you start the handover conversation. Switching supplier is usually straightforward when you own the keys and genuinely painful when you do not, so run this audit while the relationship is still good rather than in the middle of a dispute.

Next stepGet this run for youWe run Claude AI, websites, booking and SEO for UK small businesses. From £495 a month.
Start a Project