MONTHLY RETAINERS · INCLUDING SITES WE DID NOT BUILD

The part that decides whether the build was worth it.

A platform is at its best on launch day and gets slowly worse from there. Not through neglect exactly, but through accumulation. A plugin that stopped being updated. A PHP version that moved on. Six small changes made in a hurry that nobody wrote down.

A retainer is not insurance against that, it is maintenance of it. Patches applied before an advisory becomes an incident, upgrades planned rather than forced, and a named engineer who already knows the codebase when something does break.

WHAT A RETAINER COVERS
EVERY MONTH
  • Security patches, tested on staging
  • Core, module and plugin updates
  • Uptime and error monitoring
  • Verified, restorable backups
  • Performance checks as traffic grows
AS NEEDED
  • Bug fixes and small features
  • Major version upgrade planning
  • Incident response and rollback
  • Advice before you commission work
Why it matters

Nothing breaks all at once.

Every platform we are asked to rescue got there the same way. These are the four causes, roughly in order of how often we see them.

01

Abandoned dependencies

A plugin or contrib module stops being maintained. It keeps working, so nobody notices, until a vulnerability is published and there is no patch coming.

02

Deferred upgrades

A major version upgrade gets postponed because there is no budget this quarter. Two years later it is not an upgrade any more, it is a migration, and it costs several times more.

03

Undocumented changes

Small fixes made under pressure and never written down. Individually harmless, collectively the reason nobody wants to touch the site.

04

Performance drift

Content grows, a few more scripts get added, an index that was fine at ten thousand rows is not fine at two hundred thousand. Nothing broke, it just got slow enough to lose people.

Onboarding

How we adopt a platform we did not build.

WEEK 1

Audit before anything else

We go through the codebase, dependencies, hosting, backups and security exposure, and write up what is actually there. If there is something urgent, you hear about it in week one rather than at the end.

WEEK 1–2

Get the safety net in place

Version control if there is none, a staging environment if there is none, backups verified by actually restoring one, and error monitoring so problems surface rather than being reported by a customer.

WEEK 2

Clear the urgent queue

Outstanding security patches applied and tested, abandoned dependencies flagged with replacements proposed, and any live incident dealt with before routine work starts.

MONTH 2 ONWARD

Settle into the rhythm

Monthly patching and updates, monitoring, backup verification, performance checks, and the development allowance used for whatever is most useful that month. Upgrades that need budget get flagged early enough to plan.

Questions

What clients ask about retainers.

Will you support a site you did not build?
Yes, and a good share of our retainers are exactly that. It starts with an audit so we understand what we are taking on: the code, the dependencies, the hosting, the backup situation and the security exposure. You get that in writing before either of us commits to anything ongoing.
What is actually included each month?
Security patching and updates tested on staging first, uptime and error monitoring, backup verification, a performance check, and an agreed allowance of development time for bug fixes and small features. Work beyond the monthly allowance is billed by the day at an agreed rate, quoted before it starts rather than appearing on an invoice afterwards. Anything larger is quoted separately so the retainer does not quietly absorb project work.
How quickly do you respond to problems?
Response times are agreed per client rather than sold as a tier, because a brochure site and a store taking orders overnight need different commitments. What we do consistently is treat a site being down or a critical security advisory as immediate work rather than next-sprint work.
Do you handle major version upgrades under a retainer?
Planning and small upgrades yes, large ones no. A Drupal 10 to 11 move or a significant WooCommerce upgrade is a project with its own scope, and pretending otherwise means it either never happens or eats the retainer. We flag them well ahead so they are budgeted rather than urgent.
What happens if the site goes down at 2am?
We agree the escalation path before it happens rather than improvising during it: who is contacted, through which channel, and what we are authorised to do without waiting for approval. Being in Pakistan means our working day covers hours when US and European teams are asleep, which for some clients is the main reason they choose us.
Are backups included, and are they actually tested?
Yes, and the second half matters more. A backup nobody has ever restored is a hope rather than a backup. We restore periodically to a scratch environment and confirm the result, because the moment you discover a broken backup should not be the moment you need it.
Can we use retainer hours for new features?
Yes, within the monthly allowance. Most clients use them for small improvements rather than emergencies, which is a healthy sign. Larger pieces get scoped and quoted separately so the maintenance work does not get squeezed out.
What if we barely use the retainer one month?
Then it was a quiet month, which is the outcome you are paying for. We do not roll hours indefinitely, because that turns a maintenance arrangement into a bank of project time and the maintenance stops happening. If a retainer is consistently oversized we will tell you and reduce it.
Can you take over from our current developer or agency?
Yes, and we try to make it uneventful. Ideally there is a handover call and documentation. Often there is not, and we work from the code, the hosting and whatever access we can recover. Either way we do not comment on the previous team’s work beyond what you need to make decisions.
Which platforms do you support?
Drupal 7 through 11, WordPress and WooCommerce, Shopify, Joomla 1.5 through 5, and custom applications in Laravel, Symfony and Node.js.
Get in touch

Tell us what you are running, and who looks after it now.

Platform, rough traffic, and whether anyone is currently maintaining it. Within one working day you get a reply from the engineer who would take it on.

Before anything is signed, you get a written technical assessment: the real scope, where the risk sits, what we would build differently and why, and a fixed price against it. It costs nothing and it is yours to keep either way.

Reply within one working day, from an engineer Free written technical assessment Fixed scope and price before you commit