Drupal maintenance — controlled updates and technical ownership
Drupal maintenance keeps the site up to date, tested and recoverable. Security updates, backups, a test environment and monitoring need to be agreed before an issue becomes urgent.
What maintenance actually covers
Drupal core and module security updates arrive on a regular basis. Each update can affect custom code, theme or integrations — which is why we do not simply apply them automatically.
Our maintenance rhythm:
- Security updates — we monitor Drupal security advisories and apply critical patches as a priority.
- Version management — Composer-based dependency management, with changes tested in a development environment before release.
- Automated tests — agreed critical user flows are covered with Playwright tests to detect regressions before release.
- Monitoring — uptime monitoring, error reporting and log review.
- Change log — we maintain a platform history so changes and the reasoning behind decisions remain traceable.
When maintenance matters most
A Drupal maintenance agreement is especially useful when:
- the previous developer has left and the system has no technical owner;
- core or contrib security updates have not been applied for several months;
- there is no test environment, or restoring a backup has never been tested;
- the site has recurring errors with no known cause;
- a larger change or migration is planned, but the platform's state is unclear;
- it is a business-critical platform where downtime costs more than maintenance.
Drupal maintenance packages
The exact scope depends on platform criticality, access and existing test coverage. The table below is a practical framework for agreeing the maintenance scope.
| Package | Fits when | Includes | Needs to be defined |
|---|---|---|---|
| Basic | Smaller Drupal site where the main risk is missed security updates | Monitoring, tracking Drupal core and contrib security updates, backup existence check, short maintenance log | Update frequency, backup restore test cadence, response time |
| Growth | Active site where maintenance also needs small ongoing improvements | Basic + agreed development capacity, test environment use, priority review, smaller fixes | Monthly development capacity, prioritisation process, test scope |
| Critical | Business-critical Drupal platform where downtime or security risk affects operations | Growth + priority support, proactive technical ownership, critical workflow tests, release plan | SLA, response times, on-call need, escalation channel |
Prices and response times should not be promised before reviewing the system. They are agreed after an initial audit or maintenance onboarding check.
How we start
We begin with a platform review — checking version, modules, code risks and current maintenance state. This gives a clear picture of what to address immediately and what to plan for the longer term.
Briefly describe the situation: website address, main concerns, when updates were last done and whether code and server access are available.
Next step: briefly describe the situation — website address, main concerns, when updates were last done.
Fill in the contact form