Somewhere in a proposal you've received, there's a line that says "monthly maintenance" with a number next to it and no explanation underneath. Maybe you signed it. Most business owners do, because the alternative — a hacked site, a dead contact form, a ranking that quietly evaporates — sounds worse than the fee. The fee might even be fair. But you can't know that until you know what maintenance actually is, and what it isn't.
What maintenance actually includes
Strip the jargon away and website maintenance is four jobs:
- Security. Keeping the software your site runs on patched, so known vulnerabilities get closed before someone walks through them.
- Backups. Keeping copies of your site and its data somewhere that isn't your site, so a bad day costs you an hour of restoration instead of a rebuild.
- Updates. Keeping the platform and its dependencies current, so things keep working as browsers, payment gateways and hosting environments move on without you.
- Monitoring. Knowing the site is up, fast and behaving — before your customers are the ones who tell you it isn't.
That's the whole list. Everything else sold under the maintenance banner is either a different service wearing a costume, or padding.
The padding hiding inside "maintenance packages"
Here's the padding you should learn to spot, because it's where most of the cost lives:
- "Content updates included" — a monthly allowance of text changes you'll rarely use, priced as if you'll use it every week.
- "SEO monitoring" — often an automated report emailed to you, generated in seconds, billed like a consultant read it.
- Hosting resold at a markup — the plan costs the agency a small amount; you're charged several times that with "management" as the justification.
- "Priority support" — sometimes a fee for fixing problems the original build created. You're paying insurance against your own supplier.
None of these are scams by definition. Some businesses genuinely want a hands-off arrangement and happily pay for it. The problem is when the padding is bundled invisibly, so you can't see which dirhams buy real work and which buy a line item.
Security, backups and updates, in plain language
The maintenance load of a site is decided when it's built, not after. A site assembled from thirty plugins has thirty things that need patching every month, thirty things that can conflict with each other, and thirty ways for an update to break the layout. A lean build — the kind of web design we argue for — has almost none of that surface area. Fewer moving parts means fewer patches, fewer emergencies, and a smaller honest maintenance bill.
On backups, ask any provider three questions: how often are they taken, where are they stored (it must not be the same server as the site), and when did anyone last test a restore. A backup that's never been restored is a hope, not a backup.
Updates exist because software ages even when you touch nothing. PHP versions retire, browser behaviour shifts, an API you depend on changes its rules. Skipping updates doesn't save money; it defers a bigger invoice and adds interest.
A maintenance quote you can't itemise is a subscription, not a service. Ask what each line does, what happens if you skip it, and who holds the backups and the passwords. If the answers are vague, so is the work.
Why our builds come with a year of free bug fixes
Every project on our services list ships with one year of free bug fixes after launch. That's not generosity — it's incentive alignment. If we pay for our own bugs, we're motivated to build things that don't have many. It also means your first year of "maintenance" anxiety is largely handled: if something we built stops doing what we agreed it would do, we fix it, without a support package, at no charge.
What that does not cover: new features. A bug is "it doesn't do what we agreed." A feature is "I'd like it to do something new." The second one is new scope — and like all scope with us, it gets defined, priced and put in writing before any work starts, on the same 30% upfront, 70% on completion terms as the original build. That line matters in both directions. It stops you being billed for defects, and it stops "can you just add..." from quietly becoming unpaid, unplanned work that nobody budgeted for.
Retainer or pay-as-you-go: how to decide
Ignore what anyone claims "the market rate" is. Decide based on how your site actually lives:
- A retainer makes sense if your content changes weekly, you run e-commerce with real revenue on the line, your platform is plugin-heavy, or nobody on your team can be the person who notices when something breaks. You're buying response time and a standing relationship.
- Pay-as-you-go makes sense if you have a brochure site that changes a few times a year, a lean build with little to patch, or a first year already covered by a bug-fix warranty. Paying monthly for work that doesn't happen monthly is just donation.
Whichever you choose, insist on three things in writing: an itemised list of what's delivered, a short monthly note of what was actually done, and your own access to hosting, domain and backups. Ownership is not a premium feature.
And if you're comparing maintenance quotes for a site that doesn't exist yet, remember the cheapest maintenance decision is made at build time. Get a build that doesn't need life support — see your price in under a minute, or message us on WhatsApp at +971 56 160 8606 and ask exactly what your site would need to stay healthy. We'll tell you, line by line.