Nobody should pay to stand still.
The average WooCommerce store runs twenty to thirty plugins, each shipping updates on its own schedule. Keeping on top of them leaves you exactly where you already were. So we stopped charging for it — core, WooCommerce, plugin and theme updates and every security patch are included in every ITQ support contract, at no extra cost.
Patchstack, State of WordPress Security in 2026, published March 2026.
WooCommerce ships a new release roughly every five weeks, WordPress core several times a year, and your plugins whenever their authors decide. May brought WordPress 7.0, which put every plugin and theme on your site back under compatibility review. There is no quiet month.
Why we changed this
Maintenance is not an investment. It is the price of the door staying shut.
WordPress core is not the weak point. Of the vulnerabilities disclosed across the ecosystem in 2025, nine in ten were found in plugins and the rest almost entirely in themes. Only six were in core, and all of them were rated low risk. The exposure sits in the twenty to thirty extensions your store actually depends on, each maintained by a different author, each updating on its own schedule.
The volume is the problem. More than eleven thousand new vulnerabilities were disclosed in 2025, a 42 per cent rise on the previous year, and 2026 has been running at over 250 a week. Around 43 per cent of them need no login at all to exploit. And in nearly half of cases the plugin author had not shipped a fix by the time the flaw was made public, so being up to date is not the same as being safe.
Speed makes it worse. The median time from public disclosure to the first wave of mass exploitation is roughly five hours. Advice to simply keep your plugins updated assumes you have time to react, and for the heavily targeted flaws you do not.
So merchants end up funding a treadmill, paying a care plan whose main activity is clicking update. In our experience a mid-sized WooCommerce store spends the equivalent of ten to fifteen developer days a year on updates, compatibility testing and the occasional rollback. That is a meaningful share of a support budget, and not one pound of it makes the store faster, easier to buy from, or better at converting the traffic already arriving.
The old model
Updates pile up. The agency quotes, or bills the hours from your retainer. You approve or you defer. The site ends up where it started, and the invoice competes with the roadmap.
What it costs you
Deferred updates, abandoned plugins nobody has replaced, and a support budget that quietly funds standing still instead of the merchandising, speed and conversion work that pays for itself.
Always Current
Updates are applied on our schedule, not on the back of a quote. No approval loop, no line item, no argument about whether this week’s release is worth the money. It is simply done.
Where the money goes instead
Spend the budget on the things that move revenue
Removing updates from your bill does not shrink your support spend. It redirects it. The same retainer now buys work with a return attached, measured against benchmarks you agree up front.
Conversion
Checkout and basket flow, product page structure, search and filtering, mobile journeys. The changes that lift revenue from the traffic you already pay for.
Speed
Core Web Vitals, caching and asset delivery, image handling, and cutting the plugin bloat that slows a WooCommerce store down. Faster stores rank better and convert more.
Operations
ERP and stock integrations, subscriptions and B2B pricing, order and fulfilment automation. Less manual work behind the scenes, more margin retained.
The offer
Included with every WordPress and WooCommerce support contract
Every package, from £500 + VAT per month upward. Not an add-on, not a premium tier, not a fixed allowance of hours that runs out in October.
- WordPress core updates, major and minor
- WooCommerce version upgrades, including major releases
- Plugin and theme updates across your whole estate, on a tested schedule
- Security patches applied within 24 hours, and emergency patching for anything actively exploited
- Virtual patching at the firewall where the plugin author has not yet shipped a fix
- Replacing abandoned plugins that no longer receive security updates, with a like-for-like alternative
- PHP version upgrades and the compatibility work that goes with them
- Regression testing on staging against your critical customer journeys
- Scheduled out-of-hours deployment, with a pre-update backup and a tested rollback
- Daily backups, uptime monitoring and malware scanning
- Post-release monitoring, and a written record of what changed
- A platform health report showing core, WooCommerce and plugin versions, and anything unsupported
- Plugin, theme and licence renewals paid to their vendors
- Hosting, CDN and firewall subscription costs
- Rebuilding bespoke plugins written against an unsupported architecture, where replacing beats patching
- Front-end rebuilds, such as moving from a page builder to a block theme
- New features, design changes and integrations introduced alongside an update
- Remedial work identified in the onboarding health check, on code we did not write
- Cleaning up a site that is already compromised at the point we take it on
- Replatforming to another system
What your retainer buys
Our support is not just about keeping the lights on
It is about making sure your store works harder for you, every day. Here is what you can expect from us every month, on top of the updates and patching you no longer pay for.
Free upgrades and security patches, on top of all of it. Every core release, every WooCommerce version, every plugin update and every security patch is applied for you at no extra cost, and never comes out of the hours below.
WordPress and WooCommerce support
- General troubleshooting
- Plugin conflicts and vendor liaison
- Theme updates and small enhancements
- Ongoing bug fixes and issue resolution
Growth and optimisation
- Conversion rate audits and improvements
- UX and mobile journey enhancements
- Checkout and cart flow optimisation
- Speed and Core Web Vitals work
Reporting and strategic reviews
- Regular review calls
- KPI tracking: bounce rate, page speed, abandonment
- Strategic prioritisation of tasks against your roadmap
Marketing and SEO support
- Technical SEO checks
- Structured data fixes
- Landing page or blog setup
- Digital marketing partner liaison and introductions
Growth & Optimisation
The same promise on every package
Packages differ on how much development capacity you hold each month. They do not differ on whether your site stays secure and supported, or on how fast a critical patch reaches you.
For smaller stores and content sites that need to stay secure, supported and steadily improving without a large monthly commitment.
- Updates and security patches
- Included
- Critical patch applied within
- 24 hours
- Support hours
- Business hours
- Platform health report
- Quarterly
- Roadmap and KPI review
- Quarterly call
- Named account manager
- Included
For stores with an active roadmap, where the retainer is funding real conversion, speed and merchandising work each month.
- Updates and security patches
- Included
- Critical patch applied within
- 24 hours
- Support hours
- Extended hours
- Platform health report
- Quarterly
- Roadmap and KPI review
- Monthly call
- Named account manager
- Included
For high-volume, subscription and B2B stores where downtime is expensive and integrations, pricing logic and trading calendars need close attention.
- Updates and security patches
- Included
- Critical patch applied within
- 24 hours
- Support hours
- Extended, with escalation contact
- Platform health report
- Monthly
- Roadmap and KPI review
- Monthly, with an ITQ founder
- Named account manager
- Included
On every package starting from only £500 + VAT per month. Free upgrades and security patches for as long as you are in contract, critical patches applied within 24 hours, daily backups, uptime and malware monitoring, and no contract tie-in beyond a three month notice period.
Getting started
How ITQ’s growth and optimisation service works
Five steps, then you stop thinking about updates altogether.
1
We understand your business and your needs
We organise a free 45 minute ecommerce clinic to start with, to take the time to fully understand your online business. We want to learn about your goals and objectives, and your proposition in the market.
Alongside it we run a free platform health check: your WordPress and WooCommerce versions, your full plugin and theme inventory, anything abandoned or unsupported, your PHP version and your hosting setup.
2
We develop a roadmap of support, growth and optimisation initiatives
Based on your input in the clinic, ITQ prepares a proposal showing tasks and effort estimates for a minimum of a three month period, prioritised around what will move revenue first.
3
We present our proposal with costs, KPIs and ROI
- A month by month timeline of activities
- A set baseline retainer fee for your platform, from £500 + VAT per month
- Relevant references and client testimonials
- KPIs highlighted, so all effort is measured against benchmarks such as page load speed, conversion rate and basket abandonment
- If your site has drifted a long way behind, a one-off baseline remediation cost to bring core, WooCommerce and every plugin back to a supported version, quoted once and in advance
4
We onboard you as an ITQ client
- Set up on the ITQ ticketing system
- Introductions to the ITQ team and your account manager
- Staging environment, backups and monitoring put in place
- Regular monthly calls arranged
- We start to grow and optimise your business in line with the agreed roadmap
From day one, every update and patch from that point forward is included, and it does not come out of your development hours.
5
We keep you current, and keep adding value
There are no contracts for our retainers. We just ask for a three month termination notice period, and you continue for as long as it is working for you.
Throughout the engagement you have monthly calls with your account manager and the ITQ Commerce founders, focused on sharing KPI results and prioritising activity on a month by month roadmap. We watch the vulnerability feeds and the release calendars so you do not have to: you approve the deployment window, never the spend.
Our commitments
What you can hold us to
Included has to mean something, so here is what we are signing up to.
You will never be quoted for an update
No line item, no approval request, no change order for applying a core, WooCommerce, plugin or security update while your contract is live.
Your retained hours stay yours
Update and patching work is not drawn from your monthly development capacity. It sits outside the allowance entirely.
You will never be left running an abandoned plugin
If a plugin stops receiving security updates we tell you, find a supported replacement, and carry the cost of the swap.
Actively exploited flaws are treated as emergencies
Anything under active attack is patched within 24 hours on every package, or shielded at the firewall if the vendor fix is not out yet.
Nothing ships untested
Every update goes to staging first, is checked against your critical journeys, and deploys with a fresh backup and a rollback ready.
You always know where you stand
Your health report lists every version running on your site and flags anything unsupported. No guessing, no unpleasant discoveries.
Rated Excellent on Trustpilot.
“A great team to work with.” — Not only do they help us complete web development needs, but also advise us on strategic decisions that save us time and money.
"Outstanding understanding and service." — The team went above and beyond to understand our business, challenged our thinking where it mattered, and delivered results that exceeded expectations.
“Significantly improved our store.” — ITQ’s attention to detail has taken our store to the next level — a refreshing change from previous agencies.
“High level of professionalism.” — The level of work, input and advice from ITQ has been most enlightening — and very welcome.
The obvious questions
Answered plainly
How can this be free? Someone has to pay for the time.
We are not pretending the work is costless. We have priced it into the retainer instead of billing it as it arises, because keeping every client current is far more efficient than firefighting sites that have drifted years behind. We update across a portfolio on one tested schedule, which costs a fraction of doing it site by site on request, and clients who spend their budget on growth stay with us longer. The economics work because the incentives finally point the same way.
My site has forty plugins and half of them are out of date. Is that a problem?
It is common, and it is exactly what the health check is for. We tell you what is out of date, what is abandoned, and what is duplicating work another plugin already does. If the gap is large there is a one-off baseline remediation cost to bring everything back to a supported version, quoted once and in advance. After that it is included.
Does this cover WordPress sites that are not WooCommerce?
Yes. Brochure sites, content sites and membership sites are covered on exactly the same terms. The update burden is the same problem whether or not you are taking payments.
What happens if an update breaks the site?
Updates go to staging first and are tested against your critical journeys before anything reaches production. Deployments run out of hours with a fresh backup taken beforehand and a rollback ready. If something does slip through, fixing it is our problem, not a billable ticket.
What if a plugin is vulnerable and the author has not released a fix?
That happens in roughly half of disclosures, which is why updating alone is not a security strategy. Where no vendor fix exists we apply a virtual patch at the firewall to block the attack path, monitor for exploitation, and move you to a supported alternative if the author never ships a fix.
Can I still defer an update if it clashes with peak trading?
Yes. We will not push a major version into your peak season without agreement. Security patches still go on immediately by the fastest safe path, and the larger version work is scheduled around your trading calendar.
Is there a minimum term?
No. There are no contracts for our retainers and they run on a rolling monthly basis. We ask only for a three month termination notice period. The value does build over time, though: the longer you stay current, the smaller each update becomes.
What if I leave?
You leave with a site on supported, fully patched versions, a documented plugin inventory and a record of everything that was done to it. There is no exit fee and no clawback for the update work already carried out.
Find out how far behind you actually are.
Book a free 45 minute ecommerce clinic and we will run a platform health check alongside it: every version running on your site, anything abandoned or unsupported, and what it would take to move you onto Always Current. No obligation, and useful even if you never speak to us again.
Book your free ecommerce clinic
Always Current applies to WordPress and WooCommerce sites under an active ITQ Commerce support retainer, and is subject to our support terms. Vulnerability figures are from Patchstack’s State of WordPress Security in 2026 and were correct at the time of publication. WordPress and WooCommerce are trademarks of their respective owners.

