Hyvä Bronze Partner Corefinity Silver Partner Platinum Certified WooExpert
Specialists in
Free Online Shop Audit
ITQ Always Current

Nobody should pay to stand still.

250 new plugin vulnerabilities land every week.Five hours from disclosure to mass exploitation.When did you last update your plugins?One outdated plugin. One unauthenticated attacker. Full site takeover.

The average WooCommerce store runs twenty to thirty plugins, each shipping updates on its own schedule. Keeping on top of them leaves you exactly where you already were. So we stopped charging for it — core, WooCommerce, plugin and theme updates and every security patch are included in every ITQ support contract, at no extra cost.

Support packages from £500 + VAT per month, with free upgrades and security patches for as long as you are in contract.
11,334
New WordPress ecosystem vulnerabilities disclosed in 2025, up 42% on the year before
91%
Of them found in plugins, not in WordPress core
5 hrs
Median time from public disclosure to mass exploitation

Patchstack, State of WordPress Security in 2026, published March 2026.

Core, WooCommerce and plugin updates, 2026What ITQ support clients pay to have them applied
Jan£0
Feb£0
Mar£0
Apr£0
May£0
Jun£0
Jul£0
Aug£0
Sep£0
Oct£0
Nov£0
Dec£0

WooCommerce ships a new release roughly every five weeks, WordPress core several times a year, and your plugins whenever their authors decide. May brought WordPress 7.0, which put every plugin and theme on your site back under compatibility review. There is no quiet month.

Why we changed this

Maintenance is not an investment. It is the price of the door staying shut.

WordPress core is not the weak point. Of the vulnerabilities disclosed across the ecosystem in 2025, nine in ten were found in plugins and the rest almost entirely in themes. Only six were in core, and all of them were rated low risk. The exposure sits in the twenty to thirty extensions your store actually depends on, each maintained by a different author, each updating on its own schedule.

The volume is the problem. More than eleven thousand new vulnerabilities were disclosed in 2025, a 42 per cent rise on the previous year, and 2026 has been running at over 250 a week. Around 43 per cent of them need no login at all to exploit. And in nearly half of cases the plugin author had not shipped a fix by the time the flaw was made public, so being up to date is not the same as being safe.

Speed makes it worse. The median time from public disclosure to the first wave of mass exploitation is roughly five hours. Advice to simply keep your plugins updated assumes you have time to react, and for the heavily targeted flaws you do not.

So merchants end up funding a treadmill, paying a care plan whose main activity is clicking update. In our experience a mid-sized WooCommerce store spends the equivalent of ten to fifteen developer days a year on updates, compatibility testing and the occasional rollback. That is a meaningful share of a support budget, and not one pound of it makes the store faster, easier to buy from, or better at converting the traffic already arriving.

The old model

Updates pile up. The agency quotes, or bills the hours from your retainer. You approve or you defer. The site ends up where it started, and the invoice competes with the roadmap.

What it costs you

Deferred updates, abandoned plugins nobody has replaced, and a support budget that quietly funds standing still instead of the merchandising, speed and conversion work that pays for itself.

Always Current

Updates are applied on our schedule, not on the back of a quote. No approval loop, no line item, no argument about whether this week’s release is worth the money. It is simply done.

Where the money goes instead

Spend the budget on the things that move revenue

Removing updates from your bill does not shrink your support spend. It redirects it. The same retainer now buys work with a return attached, measured against benchmarks you agree up front.

Conversion

Checkout and basket flow, product page structure, search and filtering, mobile journeys. The changes that lift revenue from the traffic you already pay for.

Speed

Core Web Vitals, caching and asset delivery, image handling, and cutting the plugin bloat that slows a WooCommerce store down. Faster stores rank better and convert more.

Operations

ERP and stock integrations, subscriptions and B2B pricing, order and fulfilment automation. Less manual work behind the scenes, more margin retained.

Book your free ecommerce clinic to get started

The offer

Included with every WordPress and WooCommerce support contract

Every package, from £500 + VAT per month upward. Not an add-on, not a premium tier, not a fixed allowance of hours that runs out in October.

Included at no additional cost
  • WordPress core updates, major and minor
  • WooCommerce version upgrades, including major releases
  • Plugin and theme updates across your whole estate, on a tested schedule
  • Security patches applied within 24 hours, and emergency patching for anything actively exploited
  • Virtual patching at the firewall where the plugin author has not yet shipped a fix
  • Replacing abandoned plugins that no longer receive security updates, with a like-for-like alternative
  • PHP version upgrades and the compatibility work that goes with them
  • Regression testing on staging against your critical customer journeys
  • Scheduled out-of-hours deployment, with a pre-update backup and a tested rollback
  • Daily backups, uptime monitoring and malware scanning
  • Post-release monitoring, and a written record of what changed
  • A platform health report showing core, WooCommerce and plugin versions, and anything unsupported
Quoted separately, and always up front
  • Plugin, theme and licence renewals paid to their vendors
  • Hosting, CDN and firewall subscription costs
  • Rebuilding bespoke plugins written against an unsupported architecture, where replacing beats patching
  • Front-end rebuilds, such as moving from a page builder to a block theme
  • New features, design changes and integrations introduced alongside an update
  • Remedial work identified in the onboarding health check, on code we did not write
  • Cleaning up a site that is already compromised at the point we take it on
  • Replatforming to another system
Book your free ecommerce clinic to get started

What your retainer buys

Our support is not just about keeping the lights on

It is about making sure your store works harder for you, every day. Here is what you can expect from us every month, on top of the updates and patching you no longer pay for.

Free upgrades and security patches, on top of all of it. Every core release, every WooCommerce version, every plugin update and every security patch is applied for you at no extra cost, and never comes out of the hours below.

WordPress and WooCommerce support

  • General troubleshooting
  • Plugin conflicts and vendor liaison
  • Theme updates and small enhancements
  • Ongoing bug fixes and issue resolution

Growth and optimisation

  • Conversion rate audits and improvements
  • UX and mobile journey enhancements
  • Checkout and cart flow optimisation
  • Speed and Core Web Vitals work

Reporting and strategic reviews

  • Regular review calls
  • KPI tracking: bounce rate, page speed, abandonment
  • Strategic prioritisation of tasks against your roadmap

Marketing and SEO support

  • Technical SEO checks
  • Structured data fixes
  • Landing page or blog setup
  • Digital marketing partner liaison and introductions

Growth & Optimisation

The same promise on every package

Packages differ on how much development capacity you hold each month. They do not differ on whether your site stays secure and supported, or on how fast a critical patch reaches you.

From
4 hours
of development capacity per month

For smaller stores and content sites that need to stay secure, supported and steadily improving without a large monthly commitment.

Updates and security patches
Included
Critical patch applied within
24 hours
Support hours
Business hours
Platform health report
Quarterly
Roadmap and KPI review
Quarterly call
Named account manager
Included
From
10 hours
of development capacity per month

For stores with an active roadmap, where the retainer is funding real conversion, speed and merchandising work each month.

Updates and security patches
Included
Critical patch applied within
24 hours
Support hours
Extended hours
Platform health report
Quarterly
Roadmap and KPI review
Monthly call
Named account manager
Included
From
15 hours
of development capacity per month

For high-volume, subscription and B2B stores where downtime is expensive and integrations, pricing logic and trading calendars need close attention.

Updates and security patches
Included
Critical patch applied within
24 hours
Support hours
Extended, with escalation contact
Platform health report
Monthly
Roadmap and KPI review
Monthly, with an ITQ founder
Named account manager
Included

On every package starting from only £500 + VAT per month. Free upgrades and security patches for as long as you are in contract, critical patches applied within 24 hours, daily backups, uptime and malware monitoring, and no contract tie-in beyond a three month notice period.

Book your free ecommerce clinic to get started

Getting started

How ITQ’s growth and optimisation service works

Five steps, then you stop thinking about updates altogether.

1

We understand your business and your needs

We organise a free 45 minute ecommerce clinic to start with, to take the time to fully understand your online business. We want to learn about your goals and objectives, and your proposition in the market.

Alongside it we run a free platform health check: your WordPress and WooCommerce versions, your full plugin and theme inventory, anything abandoned or unsupported, your PHP version and your hosting setup.

2

We develop a roadmap of support, growth and optimisation initiatives

Based on your input in the clinic, ITQ prepares a proposal showing tasks and effort estimates for a minimum of a three month period, prioritised around what will move revenue first.

3

We present our proposal with costs, KPIs and ROI

  • A month by month timeline of activities
  • A set baseline retainer fee for your platform, from £500 + VAT per month
  • Relevant references and client testimonials
  • KPIs highlighted, so all effort is measured against benchmarks such as page load speed, conversion rate and basket abandonment
  • If your site has drifted a long way behind, a one-off baseline remediation cost to bring core, WooCommerce and every plugin back to a supported version, quoted once and in advance
4

We onboard you as an ITQ client

  • Set up on the ITQ ticketing system
  • Introductions to the ITQ team and your account manager
  • Staging environment, backups and monitoring put in place
  • Regular monthly calls arranged
  • We start to grow and optimise your business in line with the agreed roadmap

From day one, every update and patch from that point forward is included, and it does not come out of your development hours.

5

We keep you current, and keep adding value

There are no contracts for our retainers. We just ask for a three month termination notice period, and you continue for as long as it is working for you.

Throughout the engagement you have monthly calls with your account manager and the ITQ Commerce founders, focused on sharing KPI results and prioritising activity on a month by month roadmap. We watch the vulnerability feeds and the release calendars so you do not have to: you approve the deployment window, never the spend.

Our commitments

What you can hold us to

Included has to mean something, so here is what we are signing up to.

You will never be quoted for an update

No line item, no approval request, no change order for applying a core, WooCommerce, plugin or security update while your contract is live.

Your retained hours stay yours

Update and patching work is not drawn from your monthly development capacity. It sits outside the allowance entirely.

You will never be left running an abandoned plugin

If a plugin stops receiving security updates we tell you, find a supported replacement, and carry the cost of the swap.

Actively exploited flaws are treated as emergencies

Anything under active attack is patched within 24 hours on every package, or shielded at the firewall if the vendor fix is not out yet.

Nothing ships untested

Every update goes to staging first, is checked against your critical journeys, and deploys with a fresh backup and a rollback ready.

You always know where you stand

Your health report lists every version running on your site and flags anything unsupported. No guessing, no unpleasant discoveries.

Book your free ecommerce clinic to get started
— Verified reviews

Rated Excellent on Trustpilot.

4.7 / 5
based on 36 reviews · Trustpilot
★★★★★
“A great team to work with.” — Not only do they help us complete web development needs, but also advise us on strategic decisions that save us time and money.
Mackenzie Blinn PerioSciences
★★★★★
"Outstanding understanding and service." — The team went above and beyond to understand our business, challenged our thinking where it mattered, and delivered results that exceeded expectations.
Charlie Russell Synapse
★★★★★
“Significantly improved our store.” — ITQ’s attention to detail has taken our store to the next level — a refreshing change from previous agencies.
Roberto Solimene Emporio Italia
★★★★★
“High level of professionalism.” — The level of work, input and advice from ITQ has been most enlightening — and very welcome.
Lisa Whitty The Hay Experts

The obvious questions

Answered plainly

How can this be free? Someone has to pay for the time.

We are not pretending the work is costless. We have priced it into the retainer instead of billing it as it arises, because keeping every client current is far more efficient than firefighting sites that have drifted years behind. We update across a portfolio on one tested schedule, which costs a fraction of doing it site by site on request, and clients who spend their budget on growth stay with us longer. The economics work because the incentives finally point the same way.

My site has forty plugins and half of them are out of date. Is that a problem?

It is common, and it is exactly what the health check is for. We tell you what is out of date, what is abandoned, and what is duplicating work another plugin already does. If the gap is large there is a one-off baseline remediation cost to bring everything back to a supported version, quoted once and in advance. After that it is included.

Does this cover WordPress sites that are not WooCommerce?

Yes. Brochure sites, content sites and membership sites are covered on exactly the same terms. The update burden is the same problem whether or not you are taking payments.

What happens if an update breaks the site?

Updates go to staging first and are tested against your critical journeys before anything reaches production. Deployments run out of hours with a fresh backup taken beforehand and a rollback ready. If something does slip through, fixing it is our problem, not a billable ticket.

What if a plugin is vulnerable and the author has not released a fix?

That happens in roughly half of disclosures, which is why updating alone is not a security strategy. Where no vendor fix exists we apply a virtual patch at the firewall to block the attack path, monitor for exploitation, and move you to a supported alternative if the author never ships a fix.

Can I still defer an update if it clashes with peak trading?

Yes. We will not push a major version into your peak season without agreement. Security patches still go on immediately by the fastest safe path, and the larger version work is scheduled around your trading calendar.

Is there a minimum term?

No. There are no contracts for our retainers and they run on a rolling monthly basis. We ask only for a three month termination notice period. The value does build over time, though: the longer you stay current, the smaller each update becomes.

What if I leave?

You leave with a site on supported, fully patched versions, a documented plugin inventory and a record of everything that was done to it. There is no exit fee and no clawback for the update work already carried out.

Book your clinic

Find out how far behind you actually are.

Book a free 45 minute ecommerce clinic and we will run a platform health check alongside it: every version running on your site, anything abandoned or unsupported, and what it would take to move you onto Always Current. No obligation, and useful even if you never speak to us again.

Book your free ecommerce clinic
Platinum Certified WooExpert

Always Current applies to WordPress and WooCommerce sites under an active ITQ Commerce support retainer, and is subject to our support terms. Vulnerability figures are from Patchstack’s State of WordPress Security in 2026 and were correct at the time of publication. WordPress and WooCommerce are trademarks of their respective owners.

Excellent 4.7/5 Based on 36 reviews on Trustpilot