GuidesThe 500-a-month care plan that costs you an hour
By the NibWP team·August 13, 2026·9 min read
Five hundred a month for website maintenance sounds either obviously fair or faintly outrageous, depending on which side of the invoice you sit — and both sides are usually reasoning from the wrong number. The client compares it to hosting (twenty a month, what's the other 480 for?); the agency compares it to the hours it eats. Here's the honest anatomy of the 500-a-month care plan: what the money actually buys, what it costs to deliver when the checklist runs on autopilot, and why the well-built version is the best deal on both sides of the table.
The premise to get out of the way: a care plan is not insurance theater. Sites rot measurably — links die at a steady rate, updates pile up with security consequences, content drifts stale, and the one form that matters silently breaks on a Tuesday. The plan is the difference between finding out from a report and finding out from a customer.
What 500 a month actually buys
- The weekly drumbeat: broken-link crawl, security scan, update collection and a safe database cleanup — scheduled jobs that run whether anyone remembers them.
- The monthly update pass: core, plugins and theme updated as a reviewed batch, riskiest last, with rollback thinking done before the yes.
- The monthly SEO health check: meta regressions, heading breaks, new 404s, index anomalies — caught while they're one line in a report.
- A content/change allowance: two to four hours of edits, new sections or a landing tweak — the valve that keeps small requests from becoming invoices.
- The report that writes the renewal: what ran, what was found, what was fixed, what's recommended — in the client's language, evidence attached.
- Priority when it matters: something breaks, they're at the front of the queue. This is half of what they're really buying.
The delivery engine: why this costs you an hour
Delivered by hand, that list is 4–6 hours per site per month — 500 a month at cost. Delivered on the NibWP engine, the recurring layer runs itself: scheduled jobs do the drumbeat and queue anything that would change the site into an approvals inbox; playbooks run the monthly passes identically every time; the report assembles from the audit log of what actually ran. The full machinery is in maintenance plans on autopilot — here's the shape of your month per site:
- Mornings, twice a week, five minutes: the approvals inbox with coffee — mostly empty, occasionally a queued fix to approve.
- One monthly session, 20–30 minutes: review the update batch plan, approve, skim the post-update checks.
- The allowance work as it arrives: real requests, done by instruction, logged.
- Month end, ten minutes: read the generated report before it goes out under your name.
Call it 60–90 minutes of attention per site per month, with the allowance on top when clients use it (most months, most don't). At 500 a month, the plan runs at 80%+ margin while delivering more checks than the hand-built version ever did — that's the part clients rarely see: automation didn't thin the service, it thickened it.
The client's side of the math
- The alternative bundle: a developer on retainer for updates (150+), an SEO tool subscription nobody reads (100+), and emergency fixes at crisis rates when rot compounds (unbudgetable). The plan replaces all three.
- One prevented incident — a hacked outdated plugin, a broken checkout discovered on day four — costs more than a year of the plan.
- The report is the visible dividend: clients don't renew for the work, they renew for the evidence of it.
Where 500 sits in a plan lineup
- 250 — Essential: the drumbeat plus the monthly report. No allowance, no passes. For brochure sites that must simply stay healthy.
- 500 — Standard: everything above: passes, allowance, priority. The default for any site that generates business.
- 900+ — Premium: adds quarterly performance and content-cleanup projects, same-day priority, and stores or directories with operational needs — the tier system sites genuinely require.
Selling it without apologizing
- Attach it to every build: the two-week watch after launch is the plan's first month in disguise — convert it before the goodwill cools.
- Lead with the incident math, not the task list: clients buy prevented disasters and priority access, not “updates.”
- Show a real (anonymized) monthly report in the pitch — it does more than any brochure.
- Put the allowance in hours on the contract; unused hours don't roll (that's what makes it a valve, not a debt).
- Review the roster yearly: sites that grew into stores or directories move up a tier because their blast radius did.
The plan launch checklist, per site
- The four core jobs scheduled to the tier's cadence.
- Approvals inbox routing to the person who'll actually read it.
- Update batching order set — riskiest last, with post-update checks named.
- The forms list documented: every form, its destination inbox, its test cadence.
- Allowance hours in the contract, non-rolling, with the request channel named.
- Report template carrying the client's vocabulary — leads, bookings, orders, not HTTP jargon.
- Escalation path written: what pages the client immediately, what waits for Monday.
- The first month's report includes the launch-state baseline — before/after starts now.
- Renewal date and the year-one roster review in the calendar.
- The audit log's client-visible summary agreed — evidence by default.
What the plan is not: the boundary list that protects it
Care plans die from scope osmosis — the slow absorption of adjacent work until the margin is gone and resentment does the accounting. The boundary list, said out loud at signing, keeps the product a product. The plan is not a development retainer: new sections and pages beyond the allowance are quoted work, cheerfully and fast, but quoted. It is not a content agency: the allowance places and polishes; it doesn't write the monthly blog. It is not hosting support: server, DNS and email deliverability live with the host, and the plan's job is to know when to call them and with what evidence. It is not incident insurance: the plan makes incidents rare and diagnosis fast, and response is its own billable event at plan-client priority. Clients respect boundaries that come with speed — “that's outside the plan, here's the quote, I can start Thursday” lands as professionalism. The plans that collapse are the ones where the boundary was never spoken and got discovered, angrily, on both sides at once.
FAQ
Isn't 500 a month expensive for maintenance?
Against hosting, yes; against a retainer developer plus tooling plus one emergency a year, it's the cheap option. The plan prices the outcome — a site that stays healthy, with proof — not the tasks.
What if nothing breaks all month?
Then the plan worked. The report still shows the crawls that came back clean, the updates applied calmly, the checks that ran — prevention leaves a paper trail now.
Can clients do this themselves with the same tools?
The engine, yes — the judgment, usually not. What they buy from you is the approvals: knowing which update to hold, which finding matters, which fix to make. Tools plus judgment is the product.
How many plans can one person run?
At an hour to ninety minutes per site: thirty to forty plans alongside project work is realiztic — which is 15–20K of monthly recurring on one seat. That math is the agency's real business model.
A real month on the plan, day by day
Abstract deliverable lists hide the texture, so here's an actual month for one Standard-tier client — a 40-page services site with a blog and two lead forms:
- Week 1: Monday's crawl finds 3 broken outbound links (a partner rebranded); queued, approved, fixed by instruction — 12 minutes. Security scan clean. Tuesday: client emails asking for a new testimonial on the home page — allowance work, 20 minutes, logged.
- Week 2: crawl clean; update collection shows 6 plugin updates, one flagged (the forms plugin — changelog mentions a rewrite). Update pass scheduled for week 3 with that one last, after a form test plan.
- Week 3: the update batch runs — five routine, then the forms plugin with a test submission after; all clean, 25 minutes including the reading. The SEO check flags two pages whose meta descriptions vanished (a plugin conflict from last month, caught by trend, not crisis).
- Week 4: database cleanup approved (2,100 revisions, 340 transients); month-end report generates from the log — crawls, updates, the fixes, the allowance work — read, one line added by hand (“recommend refreshing the 2023 case-study next month”), sent.
- Total human time: 68 minutes. The client's perception: someone competent watches their site every week. Both things are true — that's the product.
The four objections, and the answers that hold
- “Our hosting includes maintenance.” Hosting maintains the server; nobody at the host knows your forms exist, let alone tests them after updates. Different layer, different product — and the report proves the layer.
- “We'll call you when something breaks.” Break-fix means discovering the checkout died on day four, from a customer. The plan's whole value is the gap between when things break and when someone notices — bought down to hours.
- “Can we do quarterly instead?” Rot is weekly — links die and updates land on their schedule, not a quarterly one. Quarterly is break-fix with an appointment. The honest downshift is the Essential tier, not a slower Standard.
- “My nephew can do the updates.” Sincerely: maybe. The plan's engine is judgment at the approval gate — knowing which update to hold and which finding matters. If the nephew has it, bless the arrangement; the plan will be here after the semester ends.
The roster at scale: what 30 plans feels like
The per-site hour is the unit; the roster is the business. At 30 Standard plans, the shape of your week: Monday's fleet pass across every approvals inbox (one sweep, most empty, 40 minutes), update batches distributed across the month so no week stacks (the calendar does this; you approve), and report week — the month's real workload — reading 30 generated reports and adding the one human line each (a focused half-day). Call it 30–35 hours a month servicing 15K of recurring revenue; the engine holds the checklist, you hold the judgment. The failure mode at scale isn't workload — it's rubber-stamping the approvals. The Monday pass is a reading job; the day it becomes a clicking job, quality has left and just hasn't told you yet.
Converting the existing roster
- List every site you've launched in three years; mark who has any maintenance arrangement (usually: almost none).
- Run the free health check on five of them — the crawl and audit produce a findings report that is its own sales letter.
- Send it with two sentences: “Ran a health check on your site — 14 findings, 3 worth fixing this month. This is what the care plan handles monthly; here's what it costs.”
- Expect a third to convert on the first pass — the report does the selling because the rot is real and now it's visible.
- Every future launch includes the plan's first month framed as the watch window; the roster compounds from there.
What happens when a client cancels?
A clean offboarding is part of the product: final report, credentials review, the audit log's history exported, jobs unscheduled, credential revoked. Clients who leave well come back well — and the ones who cancel to 'handle it internally' are next year's health-check letter.
Do plans cover emergencies like hacks?
The plan makes them rare (updates applied, scans running) and cheaper (the audit trail and snapshots shrink diagnosis), but incident response is its own billable event, at plan-client priority and rates. Say this in the contract — ambiguity here is where plan margins go to die.
The bottom line
The 500-a-month plan is honest on both sides when the engine is real: more checks than hand delivery, an hour of human judgment, evidence in every report — and margin that turns projects into a business. The engine is maintenance on autopilot; the packaged offer is care plans with AI doing the work; scale it white-label via your own brand. Toolset: pricing.