Read the exclusions, they are published
Managed Hosting Already Updates My Site. Do I Still Need Cover?
Decide whether managed WordPress hosting already covers you or leaves a gap. Hosts patch the server stack and often core. What they exclude is plugins, themes, your own customisations and the breakage an update causes - and every one of them writes those exclusions into its own documentation. The table quotes them side by side, in the provider's own words.
Managed WordPress hosting covers the server, PHP, the database and usually core updates. It excludes plugins, themes, custom code and any breakage an update causes. A maintenance service covers the application layer the host explicitly does not.
What will this cost me?
Second and further sites are 20% off. Excludes the cost of one bad release.
30-day money-back guarantee · No setup fee · Cancel anytime

How the options compare
| Responsibility | Managed host | Maintenance service |
|---|---|---|
| Server, PHP and database | Yes | No |
| WordPress core updates | Usually, automatically | Yes, staged and tested |
| Plugin and theme updates | Rarely, and unattended where offered | Yes, staged and tested |
| Testing after an update | No | Yes |
| Fixing what an update broke | Explicitly excluded | Yes |
| Custom code and integrations | Explicitly excluded | Yes |
| Malware cleanup | Sometimes, at extra cost | Included on most plans |
| Who you call when the site is broken but the server is fine | Nobody | The service |
The boundary is published, and rarely read
Managed WordPress hosts are clear about what they cover. The information is in the documentation, it is unambiguous, and almost nobody reads it before assuming maintenance is included.
The boundary is consistent across providers: they own everything below WordPress – the server, PHP, the database, the network – and usually core updates on top. Plugins, themes, custom code and any consequence of an update are outside the line.
That is a reasonable division. It becomes a problem only when both parties assume the other side is handling the application.
Where the gap opens
The gap has a recognisable shape, and it produces the same support conversation on thousands of sites.
An update applies overnight. The checkout stops completing. The owner contacts the host, who checks the server and reports correctly that everything is healthy – CPU normal, PHP running, database responding. Both statements are true: the platform is fine and the site is broken.
Nobody is at fault and nobody is responsible, which is exactly the outcome the responsibility boundary produces when nothing covers the other side of it.
Auto-updating is not the same as maintaining
The strongest argument for hosting-as-maintenance is automatic core updates, and it is worth taking seriously – unattended security patching is genuinely better than patching that never happens.
What it does not include is anybody looking afterwards. The update succeeds, the version number changes, the platform reports success. Whether the site still works is not a question the host is asking, and on a site with a page builder and a store it is the only question that matters.
The same boundary question scales differently for an agency holding a portfolio, where it becomes a hiring decision rather than a supplier one – in-house versus outsourced maintenance sets out where the crossover sits.
What to judge it on
- What does the host's own documentation exclude?Read it rather than assuming. Every managed host publishes a responsibility boundary, and plugins, themes and custom code sit outside it on all of them.
- Who tests after core updates?Hosts that auto-update core do not open the site afterwards. The update succeeds at the platform level and the checkout breaks at the application level, and both statements are true.
- What happens when the server is fine and the site is broken?The most common support conversation there is. The host is correct that the infrastructure is healthy, and the site is still down. That gap is what this comparison is about.
- Are plugins updated at all?Some hosts offer it, unattended, with no testing. That is closer to the maintenance plugin comparison than to a service, and it carries the same failure mode.
- Is malware cleanup included?Occasionally, frequently at extra cost, and often limited to restoring a backup - which returns the site and the vulnerability together.
The short answer
- Host alone is enoughOn a brochure site with a stock theme and few plugins, where core auto-updates and nothing customised exists to break. The realistic failure modes are covered.
- You need bothOn any site with a page builder, a store, custom code or integrations. The host owns the platform, the service owns the application, and neither substitutes for the other.
- Neither is optionalGood hosting is not a maintenance strategy and a maintenance service cannot fix an oversold server. They are different layers with different failure modes.
Plans that include this
- Starter$39/monthor $390 a year — two months freeBlogs, portfolios and brochure sites
- UpdatesMonthly
- BackupsWeekly, 30-day retention
- Uptime5-minute checks
- Malware removalNot included
- Most chosenProfessional$79/monthor $790 a year — two months freeSmall businesses and lead-generation sites
- UpdatesWeekly + PHP version management
- BackupsDaily, 60-day retention
- Uptime1-minute checks
- Malware removalIncluded
- Business$149/monthor $1490 a year — two months freeStores, membership sites, anywhere downtime costs money
- UpdatesWeekly, tested on staging first
- BackupsDaily, 90-day, multi-location
- Uptime1-minute + 2-hour restore
- Malware removalIncluded
Questions people ask before calling
Does managed WordPress hosting include maintenance?
It includes server maintenance and usually core updates. It excludes plugins, themes, custom code and anything an update breaks - and every provider states this in its own documentation.
My host auto-updates everything. Is that enough?
It covers the applying. It does not cover the testing, and no host opens your checkout after an update to confirm it still completes. Unattended updating is where most update breakage originates.
Why did my host say the site is not their problem?
Because the server is healthy and the application failed, which is a real distinction rather than an evasion. That is precisely the gap a maintenance service occupies.
Am I paying twice for the same thing?
No, provided you read both scopes. Overlap is limited to core updates. Everything else the service does sits outside what hosting covers by definition.
More comparisons