WordPress care plans: the complete guide
A care plan is a recurring maintenance service with a defined scope, a defensible price and a way of proving the work happened. Get those three right and it becomes the most reliable income in a WordPress business. Get any of them wrong and it becomes the thing that quietly loses money.
- What a care plan actually is
- Start a WordPress maintenance business worth building
- What to include at each tier
- How to price it
- What to exclude
- Sell WordPress maintenance services to existing clients
- WordPress maintenance contract terms and SLAs
- Reporting and retention
- Measuring profitability
- Scaling past fifty sites
What a care plan actually is
A WordPress care plan is a recurring service, usually monthly, under which you keep a client's site updated, backed up, monitored and supported for a fixed fee. The name varies: maintenance plan, care plan, retainer, website support plan. The structure is the same.
What separates a care plan from ad-hoc maintenance is that the scope is written down. A plan that has not defined what is included, what is excluded, how quickly you respond and how the work is reported is not a plan, it is an expectation waiting to be disappointed.
Start a WordPress maintenance business worth building
The obvious reason is revenue stability. Project income is lumpy and care plan income is not, and a base of recurring revenue changes how a business behaves: you can turn down bad projects, hire ahead of demand, and survive a slow quarter.
The less obvious reasons matter as much:
- Retention. A client on a care plan stays in contact monthly. When they need a new project, you are already there.
- Risk reduction for both sides. Sites you maintain break less. Sites that break less generate fewer emergency conversations.
- Business value. Recurring revenue with documented delivery is materially more sellable than project income.
What to include at each tier
Three tiers works better than two or four. Two forces a binary choice, and four creates decision paralysis.
Essential
Core, plugin and theme updates with verification. Daily off-site backups. Uptime monitoring. SSL monitoring. Security patching. A monthly report. Little or no support allowance.
The temptation is to make this tier deliberately thin so people upgrade. Resist it. A weak bottom tier produces churn and complaints, and the clients on it talk to the clients on the other tiers.
Standard
Everything above plus performance monitoring, one to two hours of support, faster response targets, staging for larger changes, and a quarterly review. This is where most clients should sit and where it should be designed to feel like the obvious choice.
Priority
Everything above plus same-day response, real-time backup, freeze windows around campaigns, a named contact and a formal SLA. Appropriate for stores and anything where downtime has a number attached.
A store add-on rather than a fourth tier
WooCommerce sites need order-safe backup, checkout monitoring, payment plugin caution and trading-hours freezes. Selling that as an add-on to any tier is cleaner than building a fourth tier nobody can position.
How to price it
Build the price rather than picking it. Work out delivery cost per site, divide by one minus your target margin, and that is your floor. Then check the floor against what the market supports and against what the site is worth to the client.
Typical market bands in 2026 run $29 to $60 for essential, $75 to $150 for standard, and $200 to $400 for priority, with managed retainers above that. The pricing article covers the arithmetic in detail and the calculator runs it with your own numbers.
Target 55 to 75 percent gross margin. Below 40 percent the plan cannot absorb a single bad month on that account.
What to exclude
The excluded list does more work than the included list. State explicitly that the following are outside the plan and quoted separately:
- Content edits beyond the stated allowance
- New features, new pages and design changes
- Third-party integrations and their ongoing support
- SEO, advertising and marketing work
- Recovery from problems caused by client changes or third-party developers
- Migration to new hosting, unless stated
- Training beyond a stated allowance
Ambiguity here always resolves in the client's favour and against your margin, not because clients are difficult but because everyone reads a vague scope generously in their own direction.
Sell WordPress maintenance services to existing clients
The most effective approach is a pre-sales audit rather than a pitch. Show them the current state of their site specifically: how many known vulnerabilities are present, which plugins are abandoned, when the last backup was taken, whether it has ever been restore-tested, what the current Core Web Vitals look like.
This works because it is specific and true, and because it moves the conversation from "would you like to buy maintenance" to "here is the current risk, here is what it costs to remove it." Most people say yes to the second framing and no to the first.
Some practical notes: lead with consequence rather than feature, offer the standard tier by default rather than the cheapest, price against what a problem would cost rather than against your hours, and be genuinely willing to walk away from a client who wants the protection without paying for it.
WordPress maintenance contract terms and SLAs
A care plan agreement does not need to be long. It needs to state:
- Scope, included and excluded, in plain language
- Support allowance and what happens when it is exceeded
- Response targets, and whether they are targets or commitments
- Uptime commitment, if any, and what happens if it is missed
- What data you hold and how it is protected
- Notice period, both directions
- What happens at the end: data handover, access removal, final backup
Only offer an SLA with a remedy attached if you can actually meet it. An uptime commitment you cannot measure is worse than no commitment, and a service credit you have not budgeted for is a liability.
Reporting and retention
The monthly report is the product as far as the client is concerned. It is the only regular evidence that anything is happening. Three rules:
- Send it on the same date every month. Predictability is most of the value.
- Lead with outcomes, not changelogs. Availability, incidents prevented, work completed, hours used. The version-by-version detail belongs underneath for anyone who wants it.
- Brand it as yours. A report carrying a third-party vendor's logo invites the client to look up what that vendor costs.
Beyond the report, retention comes from being visibly useful: a quarterly conversation about the site rather than the plan, proactive flagging of things you noticed, and being the person who already knows the context when something goes wrong.
Measuring profitability
Most care plan businesses do not know which accounts make money, which is how unprofitable accounts persist for years. Track four things per client:
- Recurring revenue
- Hours consumed, including support conversations
- Labour cost at your effective rate
- Gross margin
Review quarterly. The pattern is consistent: a small number of accounts consume a disproportionate share of support, and they are rarely the ones paying the most. Once you can see it, you have three options: raise the price, reduce the scope, or end the relationship. All three are better than continuing not to know.
Scaling past fifty sites
Care plan operations tend to break at predictable points. Around fifteen sites, manual delivery stops fitting into the week. Around fifty, the constraint becomes coordination rather than labour: who is doing what, on which site, under which plan.
What has to be in place to get past it:
- Automated delivery of routine work, with verification, so labour scales with exceptions rather than with site count
- Role-based access, so work can be delegated without sharing admin credentials
- Documented policy per tier, so behaviour is consistent regardless of who is on shift
- Tracked support allowances, so scope drift is visible before it becomes structural
- Per-client economics, so growth does not quietly reduce margin
None of these are exotic. They are just the things that stop being optional once the operation is bigger than one person's memory.
Frequently asked questions
At minimum: core, plugin and theme updates with verification, off-site backups, uptime monitoring, security patching and a monthly report. Higher tiers add performance monitoring, a defined support allowance, faster response targets, staging and a formal SLA.
Typical bands in 2026 run $29 to $60 for essential, $75 to $150 for standard, and $200 to $400 for priority plans. Build your price from delivery cost and target margin rather than picking a number from the range.
Run a pre-sales audit and show them the current state of their site: known vulnerabilities, abandoned plugins, backup age, whether a restore has ever been tested. Specific current risk converts far better than a feature list.
No. Undefined support is the most reliable way to turn a profitable plan into an unprofitable one, because the clients who use it most are rarely those paying most. Define an allowance in hours or tickets, track it and show usage in the report.
55 to 75 percent gross margin once routine delivery is automated. Below 40 percent the plan cannot absorb a single incident or long support call without losing money on that account for the month.
Put the guide into practice
WPCentrify automates the routine parts of everything above and verifies every change before it reaches a live site.
Free during early access. Keep your data, export any time.
Free calculators and templates accompany this guide, and customer outcomes show how agencies have applied it.