By Cody Wise, Founder, Wise Media. Last updated 2 September 2026. All prices in CAD.

Summary

A real WordPress maintenance plan in Canada covers seven things: staging-tested core, theme and plugin updates; offsite backups with a tested restore; security monitoring and hardening; uptime monitoring; performance checks; a named response window for critical vulnerabilities; and ownership of your commercial plugin licences. Published Canadian rates run roughly $120 to $500 CAD per month for a professional plan. The two clauses almost nobody quantifies are the response window and the licence ownership, and they are the two that decide what happens to you in a bad week.

Laptop showing an administrator warning panel beside a lit phone late at night in a workshop
The real test of a maintenance plan is not what it does on a quiet Tuesday. It is what happens when a critical vulnerability lands on a Friday evening.

Table of contents

What should a WordPress maintenance plan include?

Answer first. At minimum: core, theme and plugin updates applied on a staging copy and checked before they touch the live site; daily offsite backups with a restore that has actually been tested; a security plugin or firewall with monitoring and alerting; uptime monitoring; a monthly performance and broken-link check; a written response window for critical vulnerabilities; and clear ownership of every commercial plugin and theme licence the site depends on.

Line itemWhat good looks likeWhat to watch for
UpdatesApplied on staging, visually checked, then pushed live. Rollback plan documented“Automatic updates enabled” is not maintenance. It is a setting
BackupsDaily, stored offsite, retention stated, restore tested at least twice a yearBackups stored on the same server as the site
SecurityFirewall, malware scanning, login hardening, admin account reviewScanning with no one reading the alerts
UptimeMonitored at one to five minute intervals with alerting to a humanMonitoring that emails an address nobody checks
PerformanceMonthly Core Web Vitals and image weight check, database cleanupA screenshot of a score with no action taken
Response windowA stated number of hours for a critical CVE, including weekends“Best effort” or no mention at all
LicencesNamed licences, held in your name or transferable on exitAgency-held licences that die when the relationship does
ReportingWhat was updated, what broke, what was fixedAn automated PDF listing plugin version numbers

What is not maintenance

  • Hosting. Managed hosting overlaps with maintenance but does not replace it. Your host will not test whether a plugin update broke your booking form.
  • SEO. A separate discipline with separate deliverables.
  • New features or design changes. Those are project work, and a plan that promises “unlimited changes” is either capped in the small print or priced for it.
  • Content updates, unless the scope names them and defines what counts as a small task.

What does a WordPress maintenance plan cost in Canada in 2026?

Answer first. Published Canadian rates for a professional managed plan sit at roughly $120 to $500 CAD per month. Below about $75 CAD per month you are buying automation with no human review. Above about $1,000 CAD per month you are into enterprise scope with dedicated security resourcing.

TierPublished monthly range (CAD)What you actually getSuits
DIY$0 to $50Auto-updates, a free security plugin, a backup plugin you configured onceA hobby site you can afford to lose
Budget managed$50 to $120Automated updates, offsite backups, basic monitoring. Little or no human testingBrochure sites with no forms, no bookings, no checkout
Professional$120 to $500Staging-tested updates, tested restores, monitoring, small tasks, a stated response window, and often premium plugin licences includedAny site that generates enquiries or revenue
Enterprise$1,000+Daily or continuous updates, dedicated security, contractual SLAEcommerce at scale, regulated sectors, high traffic

These are published market rates, not quotes. Verify current pricing directly with any provider before budgeting. As a reference point, the Canadian provider Web321 publishes a professional tier at $123 to $321 CAD per month with a $250 CAD onboarding fee for complex ecommerce or LMS migrations, and estimates that the premium plugin licences bundled into a plan would cost $1,500+ CAD a year bought individually.

Three Canadian cost factors most guides skip

  1. Currency. A plan advertised at $99 USD is not $99. Add the exchange rate and any foreign transaction fee and compare like for like. Ask every provider to quote in CAD.
  2. GST and provincial tax. A Canadian provider invoices with GST or HST, which matters for your input tax credits. A foreign provider generally does not, which is not automatically cheaper once your accountant is involved.
  3. Time zone and data residency. If your provider’s business hours end when yours begin, your response window is theoretical. Hosting inside Canada also simplifies your PIPEDA position, though it is not by itself a compliance answer.

The clause nobody quantifies: the response window

Every maintenance page on the internet says “we keep your site updated.” Almost none say how fast, and speed is the entire product.

Stopwatch on a brushed steel surface beside a closed laptop
Patchstack puts the median time to mass exploitation of a high-impact WordPress vulnerability at roughly five hours. A weekly update cycle is not a security control.

The number that should reframe your thinking

In June 2026 WordPress.org launched Protect the Shire, an initiative that holds every new plugin and theme release before the update system distributes it. The hold started at up to 24 hours and was reduced to roughly six hours by mid-July 2026. Its purpose is to stop supply chain attacks, and it is a reasonable trade.

Here is the part almost nobody has connected for site owners. Patchstack has argued that the hold applies to security patches at the same duration as routine releases, and puts the median time to mass exploitation of a high-impact vulnerability at around five hours. The analysis is covered by The Repository.

Read those two numbers together. If the distribution hold is six hours and mass exploitation begins around five, then for a serious flaw the patch is not necessarily arriving ahead of the attack. Waiting passively for auto-updates to fire is no longer a plan. Somebody has to be watching the vulnerability feeds and pulling the update manually when it matters.

What to ask for, in writing

  • What is your response window for a CVSS 9.0 or higher vulnerability affecting a plugin on my site?
  • Does that window apply on evenings, weekends and statutory holidays?
  • Which vulnerability feeds do you monitor, and who reads them?
  • Will you apply an emergency patch without waiting for my approval, and is that authorisation documented?
  • If a patch breaks the site, what is the rollback procedure and who pays for the fix?

An honest provider will answer all five in a paragraph. A provider that cannot answer question one is selling you plugin updates, not protection.

The second clause nobody quantifies: who owns your plugin licences

Answer first. If the commercial plugin and theme licences on your site are registered to your agency rather than to you, then on the day that relationship ends your update button stops working. Not gradually. Immediately, on the licences that lapse.

Folder of licence paperwork with a payment card and a small key on a slate desk
Commercial plugins update through a registered licence. If the licence is not yours, the security patch is not available to you.

This is not theoretical and it is not rare. The premium builder and forms layer that a typical small business WordPress site is actually made of is commercially licensed. Page builders, form plugins, membership plugins, booking plugins and premium themes usually update through a dashboard registration tied to a valid purchase token or subscription. No host can push those updates for you, because the update does not come from WordPress.org.

The three questions that surface it

  1. List every commercial plugin and theme on my site and tell me whose account each licence sits in. Get the list, not a reassurance.
  2. Which of those licences are currently active, and when does each renew? A lapsed licence is the single most common reason a client site is running an unpatched premium plugin.
  3. If we part ways, which licences transfer to me and which do I have to repurchase? Get this answered before you sign, not during an exit.

A note on accuracy, because this claim circulates in a distorted form. For marketplace themes, item support is time-limited, while item updates generally are not. The practical failure mode is dashboard registration with a valid purchase token, not an expired download right. Check the registration state on the site, not the purchase date on the receipt.

What “we update plugins weekly” actually bought you in August 2026

Maintenance is usually argued in the abstract. It does not have to be. August 2026 supplied a stack of dated, named, extremely severe examples in the exact plugin layer small business sites run on. We covered the full owner’s runbook in six critical WordPress flaws landed in three weeks, and the Elementor Pro case separately in the CVE-2026-32475 runbook.

The pattern worth extracting for this article is not the CVE numbers. It is these four points.

  1. Severity clustered at the top of the scale. Multiple flaws in that window scored 9.8, and one scored 10.0. These were unauthenticated, meaning an attacker needs no account on your site.
  2. Several led to administrator takeover rather than file upload. That matters enormously for how you verify you are clean. Checking plugin version numbers is not sufficient. You also have to check for administrator accounts you did not create.
  3. One flaw in the sweep set was confirmed exploited in the wild, with a security vendor reporting hundreds of blocked attempts within a single 24 hour period. Exploitation is not hypothetical.
  4. The commercially licensed plugins were the hardest to patch, for exactly the licence reason above.

So when a maintenance provider says “we update plugins weekly”, the honest translation is: on a bad week, your site was exposed for up to six days on a flaw that requires no login to exploit. That may be an acceptable risk for a brochure site. It is not acceptable for a site taking bookings or payments.

Backups: the one line that disqualifies a plan

Two external solid state drives connected beside a closed laptop on a concrete desk
If the backup lives on the same server as the site, it is not a backup. It is a second copy of the same risk.

If a maintenance plan does not include offsite backups, walk away. A backup stored on the same server as the website dies with the server, and is equally available to anyone who compromises it. Ransomware operators look for local backups first.

The four backup questions

  • Frequency. Daily is the baseline. If your site takes orders or bookings, ask for real-time or hourly database backups.
  • Location. A different provider, not just a different folder.
  • Retention. Thirty days minimum. A site can be quietly compromised for weeks, so a three-day retention window can mean every backup you hold is already infected.
  • Restore testing. The only question that matters. Has anyone actually restored this site from a backup, and when? An untested backup is a belief, not a control.

Should you just do it yourself?

Sometimes, honestly, yes. Here is the decision without the sales pitch.

Do it yourselfPay a provider
Direct cost$0 to $50 CAD a month plus your time$120 to $500 CAD a month
Realistic time cost2 to 4 hours a month, plus emergenciesRoughly 30 minutes reading reports
Works well whenBrochure site, few plugins, no forms or payments, you are comfortable with staging and FTPThe site generates enquiries or revenue, or uses commercial plugins
Main failure modeYou are on holiday when the critical CVE landsYou bought a cheap plan that only automates updates
Hidden costA malware cleanup and the ranking damage that follows itScope creep billed as project work

Pros and cons of a managed plan

Pros: somebody is watching vulnerability feeds so you do not have to; updates are tested before they reach customers; backups are offsite and tested; premium licences are often bundled, which offsets a meaningful part of the fee; and there is a named person to call at 9pm on a Friday.

Cons: it is a recurring cost on a site that may go months without incident; scope boundaries can be vague; a cheap plan can create false confidence, which is worse than no plan because you stop checking; and if the provider holds your licences you have created a dependency you did not intend.

Founder closing a laptop in an office at dusk after finishing an out of hours patch
The maintenance fee is not buying plugin updates. It is buying somebody who is already awake when the advisory drops.

Audit your current plan in fifteen minutes

Send this to your current provider. The quality of the answers tells you more than any sales page.

  1. List every commercial plugin and theme on my site and whose account holds each licence.
  2. Which of those licences are active, and when does each renew?
  3. What is your response window for a CVSS 9.0+ vulnerability, including weekends?
  4. Where are my backups stored, how long are they retained, and when was a restore last tested?
  5. Are updates applied on staging first, and what is the rollback procedure?
  6. How many administrator accounts exist on my site right now, and who are they?
  7. What is explicitly out of scope, and what is your rate for that work?
  8. If we part ways, what do you hand over, and in what format?

Question six is the sleeper. Several 2026 vulnerabilities produced administrator takeover, so an unexplained admin account is a stronger signal than a plugin version number. If nobody can answer it in a day, that is your answer.

Common mistakes

MistakeWhat it costs
Buying on price aloneA $40 plan and a $3,000 malware cleanup is not a saving
Assuming managed hosting is maintenanceYour host will not notice that a plugin update broke your contact form
Leaving licences in the agency’s nameYou cannot patch your own site the week you switch providers
Never testing a restoreYou discover the backup is broken on the worst day of the year
Enabling auto-updates and calling it doneUntested updates break live sites, and the distribution hold means auto-updates may not beat exploitation anyway
Comparing a USD plan to a CAD planYou choose the more expensive option believing it is cheaper
No documented owner for the security decisionEveryone assumes someone else is watching the feeds

Frequently asked questions

How much should a WordPress maintenance plan cost in Canada?

Published Canadian rates for a professional managed plan run roughly $120 to $500 CAD per month. Budget plans sit at $50 to $120 CAD and typically automate updates without human testing. Enterprise scope starts around $1,000 CAD. Verify current pricing with each provider, and insist on CAD quotes so you are comparing like for like.

Do I need a maintenance plan if my host does automatic updates?

Usually yes. Hosts update WordPress core and sometimes free plugins. They do not update commercially licensed plugins and themes, which is where the most severe 2026 vulnerabilities were, and they do not test whether an update broke your forms, checkout or booking flow.

What is a reasonable response time for a critical WordPress vulnerability?

For a CVSS 9.0 or higher flaw affecting a plugin on your site, ask for hours rather than days, and ask whether that window covers evenings and weekends. Context: Patchstack puts median time to mass exploitation of a high-impact flaw at around five hours, and WordPress.org’s distribution hold currently sits at around six hours.

Who should own my premium plugin licences?

You should, or the agreement should state clearly that they transfer to you on exit. Licences held only in an agency account mean that when the relationship ends, the update mechanism for those plugins stops working on your site until you repurchase.

How often should WordPress plugins be updated?

Routine updates weekly on staging is a reasonable baseline. Security updates for actively exploited or CVSS 9.0+ vulnerabilities should be applied on discovery, not on the schedule. Those are two different processes and a plan should describe both.

Are Canadian providers worth paying more for?

They are frequently not more expensive once the exchange rate is included. The practical advantages are CAD invoicing with GST or HST for your input tax credits, overlapping business hours so your response window is real, and Canadian data residency if that matters to your privacy position.

What happens if I do nothing?

Most months, nothing. The risk is not gradual, it is a step function: one unauthenticated critical vulnerability in a plugin you forgot you installed. The downstream costs are cleanup, potential data exposure, and search visibility damage that outlasts the technical fix.

The bottom line

Most maintenance plans are sold on a list of tasks. Tasks are the easy part. The two clauses that decide what actually happens to your business are the response window on a critical vulnerability and the ownership of your plugin licences, and those are precisely the two that almost nobody puts in writing.

Ask for both in writing before you sign anything. If your current provider will not answer, you have learned what you are paying for.

Wise Media builds and maintains WordPress sites for Canadian businesses. Scope, response windows and licence ownership are stated up front, in CAD. See our website packages and website growth packages.

Tell us about your site and get a scoped quote. We will start with the licence list and the last tested restore.

This article is general information about website operations and is not legal or security advice for your specific site.