Website Maintenance Costs in New Zealand: The Bills That Start After Launch
Two deadlines already sit in your website's calendar, and your web designer set neither of them. PHP 8.2 stops receiving security patches on 31 December 2026. From 15 March 2026, no publicly trusted certificate authority may issue a TLS certificate lasting longer than 200 days, down from 398.
Both generate work on a site that has not changed a pixel since launch. Neither appears in a build quote.
Most maintenance advice starts with a percentage of build cost, usually 15 to 20% a year, which tells you nothing about the months the money lands in. Start with the calendar instead: dates other organisations published years ahead, licences that renew whether you touch them or not, and the gap between what a care plan covers and what it bills for.
The expiry dates already on your site
Someone else decides when your site's foundations retire. The current schedule:
- PHP 8.1 stopped receiving patches on 31 December 2025. 8.2 runs security-only until 31 December 2026, 8.3 until 31 December 2027, and 8.4 until 31 December 2028 (HeroDevs PHP end-of-life timeline). The PHP project publishes these years in advance.
- WordPress 7.0, released in April 2026, raised the minimum supported PHP to 7.4 and keeps 8.3 as the recommended version. Sites still on PHP 7.2 or 7.3 stay behind on the 6.9 branch rather than receiving the major update (Make WordPress Core).
- Shopify ships an API version each quarter and supports each stable version for at least 12 months, with at least nine months of overlap. An app still calling unsupported resources past the deadline gets delisted from the App Store (Shopify).
- Node.js retires each even-numbered line about 30 months after release. Node 20 ended on 30 April 2026 and Node 22 ends on 30 April 2027 (HeroDevs Node.js support timeline).
- TLS certificates shrink on a published schedule: 200 days from 15 March 2026, 100 days from 15 March 2027, and 47 days by March 2029 (CA/Browser Forum ballot SC-081v3).
The sequence that follows is predictable. Your host announces a PHP upgrade, a theme function that has worked for four years throws a fatal error, and someone bills hours to fix it. That invoice arrives 18 months after launch, which is why the build quote never mentioned it.
One trap catches sites on an old stack. WordPress supporting PHP 7.4 does not make PHP 7.4 safe. The WordPress project retires a PHP version once usage drops below roughly 5% of monitored installations, long after the PHP project stops patching it. Your host, not WordPress, decides whether the version you run receives security fixes.
Certificate renewal turned into an automation job
The 47-day endpoint gets the headlines, and the 2026 step is the one that changes how sites get managed. A 200-day maximum means renewal twice a year. The 2027 step means four times.
Let's Encrypt has gone further than the minimum. Six-day certificates, valid for 160 hours, became generally available in January 2026, and the recommendation is to renew them every three days (Let's Encrypt). Their standard lifetime is moving from 90 days to 45 (Let's Encrypt).
Manual renewal has no future at that cadence. Two questions settle whether your provider has caught up: name the ACME client that renews your certificate, and name the person who gets the alert when a renewal fails. A provider still charging an annual SSL line item and renewing by hand is billing you for a task that automation performs for nothing, which our breakdown of hidden costs in cheap website quotes covers alongside the other recurring line items with a published floor price.
A monthly update cycle is not a security control
Patchstack recorded 11,334 new vulnerabilities across the WordPress ecosystem in 2025, up 42% on 2024's 7,966. Plugins accounted for 91% of them, themes 9%, and WordPress core six (Patchstack, State of WordPress Security in 2026).
The timing numbers matter more than the volume. Among heavily exploited vulnerabilities, the weighted median time to first exploitation was five hours. Attackers hit 45% within 24 hours of disclosure and 70% within seven days. Separately, 46% of vulnerabilities went public without a fix from the developer.
Put that beside a care plan promising monthly updates. Thirty days of exposure against a five-hour median is not a security control, whatever the plan calls it. Monthly updates keep your software current, which is a maintenance outcome rather than a protective one.
WordPress ships minor core updates automatically and has since version 3.7. Plugin and theme auto-updates stayed opt-in when they arrived in 5.5, so somebody has to switch them on (WordPress). Leaving them off buys you the chance to test before deploying. It also buys you the thirty-day window.
Neither setting solves the 46% that ship no fix at disclosure. The lever that does is plugin count. Every plugin you remove takes its future vulnerabilities and its licence renewal with it.
Published NZ care plan prices, and the line where they stop
New Zealand providers publish their numbers, so the market rate is easy to check:
- Website Maintenance Services NZ starts at $39 a month, with a basic tier at $32 (WMS NZ).
- Aotearoa Web Design lists plans from $40 plus GST a month (Aotearoa Web Design).
- Dear John runs three tiers at $59, $89 and $159 a month (Dear John).
- Website4U lists $79, $149 and $229 a month excluding GST (Website4U).
Inclusions cluster around the same items: backups, software updates, uptime monitoring, security scanning, and an hour or two of content changes. Those are the predictable costs, and the plan prices them accurately.
The expensive work sits outside that list. Migrating a site to a new PHP major version, replacing a plugin whose developer walked away, rebuilding a theme after a breaking update, moving a store onto a supported Shopify API version: none of these are monthly tasks, and none are covered by a monthly fee. Ask for the exclusion list in writing, and ask for the hourly rate that applies when the exclusions arrive. A provider who has thought about this hands over both.
Licence renewals are the running total that stays off the quote
Premium plugins bill annually, in US dollars, and each vendor treats expiry differently.
WP Rocket costs US$59 a year for one site and renews automatically. Let it lapse and the plugin keeps caching, though the cloud features stop 15 days after expiry (WP Rocket). Gravity Forms runs US$59 for Basic, US$159 for Pro across three sites, and US$259 for Elite (Gravity Forms). ACF Pro sits at US$249 a year for unlimited sites, and an ended subscription costs you updates and the Pro features inside the plugin (Advanced Custom Fields).
Two things catch people out. Expiry behaviour varies by vendor, so a lapsed licence might quietly stop shipping security updates or might disable a feature your booking form depends on. And these prices are in USD, so your New Zealand cost moves with the exchange rate without anyone sending you a notice.
Check whose account holds the licences. An agency renewing plugins on its own credit card belongs on the same list as the domain registrant and the hosting login, all of which decide how easily you can leave.
A contact form makes you the holder of personal information
A form plugin that stores entries builds a database of names, email addresses, phone numbers, and often job details or addresses. That puts your site inside the Privacy Act 2020.
If a breach has caused or is likely to cause serious harm, you must notify the Privacy Commissioner and the affected people, and the expectation is that you do so within 72 hours of identifying it as notifiable (Office of the Privacy Commissioner). Failing to notify the Commissioner without reasonable excuse is an offence under section 118, carrying a fine of up to $10,000 (Privacy Act 2020, s 118).
The maintenance question underneath the law: name the person who assesses a breach on your site and files the notification. Most care plans stay silent on it, and the obligation sits with you as the agency holding the information, not with whoever hosts the server. For scale on the reporting environment, the NCSC responded to 1,164 incidents in the first quarter of 2026, with phishing and credential harvesting the largest category at 437 (NCSC). Those figures cover the whole economy rather than websites, so read them as context.
Platform-hosted and self-hosted sites decay in different places
On Shopify or Squarespace, the vendor upgrades the runtime for you, and the cost surfaces as subscriptions plus app churn. Shopify's 12-month API windows push app developers to keep pace, and the ones who stop get delisted, which turns into a migration you fund. Our Shopify versus custom store comparison prices that trade-off.
Self-hosted WordPress puts the patch cadence, the licence renewals and the PHP migration on your side of the line. The care plan market above exists because that work is real and recurring.
A custom build with a static or pre-rendered front end has no server-side runtime executing on each request, so the weekly patch treadmill mostly disappears. The cost moves rather than vanishing: dependency and toolchain refreshes every year or two, and a developer needed for changes a CMS would let your staff make. We build this way, so treat that paragraph as a stated bias and test it against your own quotes. Our platform comparison sets out where each ceiling sits.
Build the annual number from line items
Take a five-page WordPress site on a mid-tier plan. The care plan at $89 a month totals $1,068 a year. Add a forms licence at US$59 and a caching licence at US$59, near NZ$200 combined once converted, plus the domain renewal. That gives you a running cost around $1,300 in a year where nothing breaks.
Then price the irregular item. Ask your provider what they charged their last client for a PHP major migration, and add that figure to every second or third year. Providers leave it out of the plan page because they cannot date it precisely. You can still budget for it, because this article lists the end-of-life dates that trigger it.
For the build side of that arithmetic, our breakdown of NZ website costs covers what the upfront number should include.
Six questions before you sign a maintenance plan
- Ask which PHP or Node version the site requires, and what your provider does on that branch's end-of-life date.
- Ask which ACME client renews the certificate and who receives the alert when a renewal fails.
- Ask for the update cadence in writing, and whether updates run on staging before production.
- Ask for the exclusion list, plus the hourly rate that applies to it.
- Ask whose account holds the plugin licences, the hosting login and the domain.
- Ask who assesses a privacy breach and files the notification.
Every date in this article came from a public schedule that anyone can read months ahead. Print them, put them beside your renewal dates, and the maintenance conversation turns into a shared calendar instead of a question of trust. The questions in our guide to hiring a web agency cover the rest of that conversation before the build starts.
Sources
- HeroDevs, PHP end-of-life dates: support timeline for every version (2026)
- HeroDevs, Node.js version support: EOL dates and latest releases (July 2026)
- Make WordPress Core, "Dropping support for PHP 7.2 and 7.3" (9 January 2026)
- WordPress Advanced Administration Handbook, upgrading WordPress
- Shopify, about Shopify API versioning
- CA/Browser Forum, Ballot SC081v3: schedule of reducing validity and data reuse periods
- DigiCert, "TLS certificate lifetimes will officially reduce to 47 days"
- Let's Encrypt, "6-day and IP address certificates are generally available" (15 January 2026)
- Let's Encrypt, "Decreasing certificate lifetimes to 45 days" (2 December 2025)
- Patchstack, State of WordPress Security in 2026
- Website Maintenance Services NZ, maintenance packages
- Aotearoa Web Design, WordPress support and maintenance plans
- Dear John, website maintenance and support prices
- Website4U, packages and pricing
- WP Rocket, pricing and licences
- Gravity Forms, pricing
- Advanced Custom Fields, ACF PRO
- Office of the Privacy Commissioner, notify us of a serious privacy breach
- Privacy Act 2020, section 118: offence to fail to notify Commissioner
- NCSC, "Quarter One sees significant cyber incidents"