Somebody has quoted you a monthly fee to look after your website, or something on the site has just stopped working and you are wondering who was supposed to be watching it. Here is the short answer. A website maintenance service is a standing monthly job list: the software behind the site is updated, a full copy of the site is taken every day, the site is scanned for malware, and somebody watches whether it is still up. Our own plan, Website Care, is S$218 per site a month for a WordPress site with no shop, and S$545 a month if the site sells. Both prices include GST and sit on a twelve-month term. Hosting is billed separately, and whether the quote in front of you splits the two is the first thing to check. The job list is the easy part to match. The harder answers are how fast a critical security fix goes on, how far back the backups reach, and who picks up the phone when the site is dark. Those are the three to ask about.
One thing to declare before the detail. We sell this. xSquare has built and looked after WordPress sites for Singapore businesses since 2008, and Website Care is our own service with its own price page. So read the last section of this piece as the one that matters most: it is a list of questions to put to any provider, and we have written it so that it can be put to us.
Our own prices checked 20 September 2026. Every government figure below carries its issuer and its year where it appears.
What actually breaks when nobody is looking after a site
An unmaintained site does not fail loudly. That is the whole problem with pricing this decision. Plugins fall one version behind, then five. The PHP underneath ages out of support, PHP being the programming language a WordPress site runs on. Nobody notices until the day it is a white screen, a defaced homepage, or a contact form that stopped sending weeks ago. None of those announce themselves on the morning they begin.
The Cyber Security Agency of Singapore puts the same finding in its own words. Reviewing 2024 in its Singapore Cyber Landscape 2024/2025 publication, dated 3 September 2025, CSA wrote that most local infections involved old malware strains, “underscoring a troubling fact that even as ransomware and other cyber threats grew, users were still failing to update and patch vulnerable software”. Old software, known holes, nobody patching. That is the sentence a care plan is answering, and we have set out what keeping a site safe and secure actually costs in more detail elsewhere.
Defacement is the version of this that a small business actually sees, because it happens on the public page rather than inside the server. CSA counted 108 ‘.sg’ websites defaced in 2023, which it reported as a fall of 68 per cent from 340 in 2022. Read that trend honestly: on CSA’s own count the number fell, so a plan sold to you on the back of a rising defacement threat is being sold on something those figures do not show. What the figure does establish is that Singapore sites got defaced in the hundreds in both of the years CSA has counted, 2022 and 2023.
What a website maintenance service covers, and what it does not
Here is the job list, with what each item is actually doing and what it looks like on a site where nobody does it. The right-hand column is our own experience of taking on neglected sites, not a measured figure.
| On the list | What it is actually doing | What it looks like when nobody does it |
|---|---|---|
| Core and plugin updates | WordPress itself and every plugin moved forward on a monthly schedule, with critical security releases going on as soon as they are out rather than waiting for the schedule | Plugins one version behind, then five. The site still loads, so nothing prompts anyone to act |
| Daily backups, kept 30 days | A full copy of the site taken every day and kept for a month, so the site can be put back to any day in the last thirty | The only copy is from the last redesign, which is also the only version anyone can restore |
| Daily malware scans | The site checked every day for malware and injected code | The compromise is reported to you by a customer, or by a browser warning, rather than caught |
| Uptime monitoring | The site watched continuously, so an outage reaches the people who can fix it first | You find out the site is down when someone mentions it, which may be the next morning |
| Hosting management | The server environment and its housekeeping handled by the same people who maintain the site | Two suppliers who each believe the other one is handling it |
| Paid plugin licences | Paid plugins covered under the provider’s own subscriptions, so the renewals are theirs to remember | A licence lapses, the plugin stops receiving security updates, and the first sign is a nag in the dashboard nobody logs in to see |
Maintenance is not hosting, and you are paying for both. This one is worth settling before you compare anything else. Hosting is the rented space the site lives in. Maintenance is the work done to the site inside it. On our own plan we manage the hosting side, but the hosting bill itself stays separate and is not inside the S$218. If a quote you are holding does not say plainly which of the two it is, that is the first thing to ask, because the answer changes what the monthly figure means by a factor you cannot guess. Where a Singapore site should be hosted is its own question, and our notes on the local hosting options cover it.
What a website maintenance service costs in Singapore
We publish two prices and no tiers, and the reason is worth saying out loud: a tier with features held back can make a plan look cheaper than the coverage it actually gives, so we do not sell one. Every site on our plan gets everything in the table above, and the full coverage sits on our Website Care page.
| Plan | For | Price |
|---|---|---|
| Website Care | WordPress sites with no shop, cart or checkout | S$218 per site a month |
| Website Care, E-commerce | WordPress sites that sell | S$545 per site a month |
| Static site plan | A brochure site that is not WordPress | S$392.40 a year, covering hosting with an SSL certificate, the thing that lets a browser open the site over a secure connection, plus uptime monitoring, a kept backup and up to two small content changes a year |
The gap between the two WordPress prices is not extra work, and we would rather say so than let you assume it is. It is the stakes. A brochure site that goes down loses you enquiries you will never know about. A shop that goes down stops taking money on a clock you can read.
We are not going to print a market range here. Any figure we gave you for what other Singapore studios charge would be a number we had not measured, and this page would then be doing the thing it is arguing against. Collect two or three quotes and compare them on the questions further down instead.
A monthly plan, or pay someone when it breaks?
This is the real decision, and it is not obvious. Paying by the incident is genuinely cheaper on a site that never has an incident. The case for the monthly fee is not that it is cheaper on average. It is that two of the things that go wrong cannot be bought back afterwards at any price.
The first is the backup. If malware went into the site in March and you discover it in June, the fix is a clean copy from before March. Nobody can create one after the fact. Either it exists or the answer is a rebuild, and a rebuild is quoted as a project, not as a repair.
The second is time in the browser’s bad books. If a site is compromised and used to host phishing or malware, Google can show a warning label in search results or an interstitial warning page in the browser when a visitor tries to open it. Getting out of that is not a matter of cleaning the site and refreshing. Google’s own Search Console documentation says that once you have fixed the problem and requested a review, “a review can take from a few days to a few weeks to complete”, and that fixing the issue on some pages only “will not earn you a partial return to search results”.
There is a third cost that only applies to some sites, and it is worth checking whether yours is one of them. If the site holds customer details, an enquiry database, a login, an order history, then a compromise is also a personal data question. Singapore’s Personal Data Protection Commission publishes a Guide on Managing and Notifying Data Breaches Under the PDPA, the PDPA being the Personal Data Protection Act, the law that governs what a business here may do with other people’s details. The guide was published on 13 September 2021, and it covers exactly what its title says: managing a data breach, and notifying one. We are not lawyers and this page does not tell you whether a given incident is notifiable. We are telling you that the question exists, that it lands on the business rather than on whoever built the site, and that it is worth reading that guide once before you need it.
Can a grant pay for it?
This is the question where the answer changed recently, so the date matters more than usual.
The Productivity Solutions Grant, PSG, helps Singapore companies adopt IT solutions and equipment, at up to 50 per cent of eligible costs for local SMEs, and up to $30,000, according to Enterprise Singapore’s own PSG page, checked 20 September 2026. The same page sets conditions a company has to meet to be eligible at all, among them that the business entity is registered and operating in Singapore, that the company has at least 30 per cent local equity held by Singaporeans or Singapore permanent residents, and that group annual sales turnover does not exceed S$100 million or group employment size does not exceed 200 employees. Its own Eligibility section is where to check them against your company. The solutions it covers are the ones “pre-approved by EnterpriseSG and other participating agencies”, they can be “purchased, leased, or subscribed to”, and the full list of them sits on GoBusiness Gov Assist. That list is the thing to check, and we are not going to tell you what is on it today, because it changes and we have not counted it.
The dated part. The same page states that EDG, MRA and PSG will cease on 29 September 2026, and that from 30 September onwards businesses apply for support under the EDGE Grant instead. If you were planning to route anything through PSG, that is nine days from 20 September 2026, when this was written, not months.
One rule on that page is worth knowing whichever grant you end up under, because it catches people out. PSG does not support retrospective applications: the applicant must not have made payment, or any form of deposit, before the application is submitted. So the order is check, apply, then pay. Paying a provider first and applying afterwards is how a grant stops being available.
The questions to put to any provider, us included
Take these to every quote you are holding. They are ordered so that the ones that separate providers come first, and the answers that should worry you are named as we go.
- How fast does a critical security update go on? A monthly schedule is fine for routine updates. A critical security release should not wait for it. If the answer is “monthly” for both, the plan is a calendar, not a response.
- How many days of backups do you keep, and where are they kept? A number, in days, and a location that is not the same server as the site. If the only copy lives beside the site, it is not a backup from anything that reaches the server.
- Have you ever restored one of your backups? An untested backup is a hope. Ask when they last put one back and what it took.
- Is hosting inside this fee, or separate? Get it in writing. This single line is the biggest reason two quotes that look the same are not the same.
- Who holds the logins? Ask for a named owner of the domain, the hosting account and the WordPress administrator account. If the provider holds all three and you hold none, changing provider later is a negotiation rather than a decision.
- What is not covered? Design changes, new pages, content edits, a plugin the site already uses going out of support. Every plan has a boundary. A plan that claims none has one it has not told you about.
- What happens when the site is down at 9pm on a Saturday? You are asking for a person and a channel, not a target. A ticket queue that opens on Monday is a legitimate answer to hear, as long as you hear it now rather than then.
- Will you take on a site somebody else built, and will you look at it first? The right answer includes an assessment before a price, and the willingness to say the site needs work before it can go on a plan. A provider who takes on any site sight unseen is pricing an unknown, and the unknown is yours.
Who should not buy a plan
Questions we get asked
Is website maintenance the same thing as web hosting?
No. Hosting is the space the site lives in. Maintenance is the work done to the site: updates, backups, scans, monitoring. They are commonly sold by the same supplier, which is why they get confused, and they are commonly billed separately, which is why the total surprises people. On our own plan we manage the hosting side but the hosting bill stays outside the fee. Ask any provider to split the two figures for you before you compare quotes.
Do care plans only cover WordPress?
Ours is built around WordPress specifically, because its update cycle, its plugin economy and its particular ways of breaking are what the coverage is shaped around. Staying narrow is what lets it go deep. A static brochure site with no content management system is a different shape and sits on a lighter plan instead, at S$392.40 a year, covering hosting with an SSL certificate, uptime monitoring, a kept backup and up to two small content changes a year. Ask any other provider where their own line falls, because nothing obliges two providers to draw it in the same place.
Can you take over a site somebody else built?
Yes, once we have looked at it. We check how the site was put together and what condition it is in, then tell you whether it can go on the plan as it stands or needs work first. We would rather say that before we take it on than discover it a month later, and you should expect the same honesty from anyone else you ask.
What if the site is already compromised?
Then the order of work changes. The site gets cleaned first and goes on a plan afterwards, because putting a maintenance schedule on top of an active compromise maintains the compromise. If the site is also showing a browser or search warning, expect the clean-up to be the fast part and the review to be the slow part: Google’s own documentation puts a security review at a few days to a few weeks once you request it.
What to do next
Book a short call with us. Send the site address and anything about it that already worries you. On the call we look at what the site runs on, what is already out of date, and which of the two plans fits, and we tell you plainly if the answer is that the site does not need one. If you would rather read before you talk to anyone, the checklist above works on us as well as on everybody else.
Sources
- xSquare, Website Care
- Cyber Security Agency of Singapore, Singapore Cyber Landscape 2024/2025
- Cyber Security Agency of Singapore, press release on the Singapore Cyber Landscape 2023
- Google Search Console Help, Security issues report
- Personal Data Protection Commission, Guide on Managing and Notifying Data Breaches Under the PDPA
- Enterprise Singapore, Productivity Solutions Grant
