After the post on WordPress maintenance costs, the most common follow-up question was: “Okay, but what actually goes in the contract?” Fair question - because that’s exactly where it’s decided whether a maintenance contract actually helps in an emergency or just looks good on paper. Over the years I’ve read, written, and renegotiated a number of these contracts. Here’s what really matters.
Why a WordPress maintenance contract makes sense in the first place
At its core, a maintenance contract is an agreement about who takes care of what, how fast they respond, and what happens when something breaks. Without clear rules, you get exactly the situations I see regularly: the site is down, nobody knows who’s responsible, and communication is spread across three different email addresses. A clean contract prevents that - for both sides.
1. A clearly defined scope of service
The most important point, and the one most often left too vague. “We’ll take care of your website” is not a service description. Concretely, it should include:
- Which updates are performed (core, theme, plugins) and on what schedule?
- Are backups created, how often, and where are they stored?
- Is security monitoring included, or only on request?
- Are minor content changes included, or billed separately?
- What is explicitly not included (e.g. design changes, new features, SEO work)?
Without these points, the contract is essentially a statement of intent - not a reliable promise of service.
2. Response times and availability
A maintenance contract without a response time is like insurance without a coverage amount. Key questions: How quickly is an incident report responded to? Are there different timeframes for “site is completely down” versus “minor bug”? Is this only covered on business days during office hours, or is there emergency availability? Especially for hotel or shop websites, where downtime directly costs bookings or revenue, it’s worth getting this wording exactly right.
3. Term and notice period
Long minimum terms aren’t automatically a red flag, but they should be transparent and fairly negotiable. Watch for: the regular term (often 12 months), the notice period (one to three months before the end of the term is typical), automatic renewal clauses, and whether extraordinary termination is possible in case of repeatedly poor performance.
4. Price adjustment clause
Prices rise - that’s normal. It becomes a problem when a price adjustment can happen without prior notice or consent. A fair contract either states a fixed period for which the price is guaranteed, or a clear notice period plus the right to object before any increase.
5. Liability and responsibilities
Important, but often overlooked: what happens if something goes wrong despite maintenance - say, an update that breaks the site? A good contract defines the process for that case (typically: restoring the last working backup) and limits liability realistically. Nobody can guarantee 100% error-free operation - but a defined recovery process is something you can expect.
6. Access credentials, backups, and ownership
A point that often causes disputes at the end of a contract: who “owns” the access credentials, the hosting account, and the backups? As a rule, the domain, hosting, and all access should be registered in the client’s name - not the provider’s. The contract should also state that upon termination, all access credentials and a current backup are handed over in full.
7. Data protection and a data processing agreement (DPA)
As soon as a provider has access to personal data (e.g. via contact forms, a newsletter tool, or a WooCommerce database), a data processing agreement (DPA) under Art. 28 GDPR is required. That’s not an optional extra - in most cases it’s a legal obligation, and a sign that the provider takes the topic seriously.
8. Communication and point of contact
Who gets in touch when something breaks, through which channel, and how is the work documented? Especially with larger teams on the client side, a dedicated point of contact plus a traceable ticket or log system helps make sure nothing gets lost in an email thread.
Frequently asked questions
Does a WordPress maintenance contract have to be in writing?
Legally, a verbal or email-confirmed agreement is generally sufficient, but without something in writing it’s hard to prove what was actually agreed if a dispute arises. For an ongoing business relationship, a written contract is always the safer choice.
What’s the difference between a maintenance contract and a hosting contract?
A hosting contract only covers providing server space, a domain, and infrastructure. A maintenance contract covers actively caring for the WordPress installation itself - updates, backups, security monitoring, and support. The two can come from the same provider, but don’t have to.
Can I cancel a maintenance contract at any time?
That depends on the agreed notice period. One to three months before the end of the term is common. Extraordinary termination is usually possible if the provider repeatedly and demonstrably fails to meet its contractual obligations.
What happens to my data if I switch providers?
With a properly drafted contract, you’re entitled to a handover of all access credentials and a current backup at any time. That’s why point 6 (ownership of access and backups) is one of the most important - it determines how easily you can switch providers later.
Conclusion
A good WordPress maintenance contract isn’t ultimately a document born out of distrust - it creates clarity for both sides: what’s delivered, how fast the response is, and what happens in an emergency. If you’re currently looking at an offer and aren’t sure whether it covers the points above, check out my post on what WordPress maintenance costs - it puts the price ranges into context.
If you’d like, send me your current contract offer - via my contact form I’ll give you an honest read on whether the key points are covered.


