Drupal maintenance — controlled updates and technical ownership

Drupal maintenance keeps the site up to date, tested and recoverable. Security updates, backups, a test environment and monitoring need to be agreed before an issue becomes urgent.

What maintenance actually covers

Drupal core and module security updates arrive on a regular basis. Each update can affect custom code, theme or integrations — which is why we do not simply apply them automatically.

Our maintenance rhythm:

  • Security updates — we monitor Drupal security advisories and apply critical patches as a priority.
  • Version management — Composer-based dependency management, with changes tested in a development environment before release.
  • Automated tests — agreed critical user flows are covered with Playwright tests to detect regressions before release.
  • Monitoring — uptime monitoring, error reporting and log review.
  • Change log — we maintain a platform history so changes and the reasoning behind decisions remain traceable.

When maintenance matters most

A Drupal maintenance agreement is especially useful when:

  • the previous developer has left and the system has no technical owner;
  • core or contrib security updates have not been applied for several months;
  • there is no test environment, or restoring a backup has never been tested;
  • the site has recurring errors with no known cause;
  • a larger change or migration is planned, but the platform's state is unclear;
  • it is a business-critical platform where downtime costs more than maintenance.

Drupal maintenance packages

The exact scope depends on platform criticality, access and existing test coverage. The table below is a practical framework for agreeing the maintenance scope.

PackageFits whenIncludesNeeds to be defined
BasicSmaller Drupal site where the main risk is missed security updatesMonitoring, tracking Drupal core and contrib security updates, backup existence check, short maintenance logUpdate frequency, backup restore test cadence, response time
GrowthActive site where maintenance also needs small ongoing improvementsBasic + agreed development capacity, test environment use, priority review, smaller fixesMonthly development capacity, prioritisation process, test scope
CriticalBusiness-critical Drupal platform where downtime or security risk affects operationsGrowth + priority support, proactive technical ownership, critical workflow tests, release planSLA, response times, on-call need, escalation channel

Prices and response times should not be promised before reviewing the system. They are agreed after an initial audit or maintenance onboarding check.

How we start

We begin with a platform review — checking version, modules, code risks and current maintenance state. This gives a clear picture of what to address immediately and what to plan for the longer term.

Briefly describe the situation: website address, main concerns, when updates were last done and whether code and server access are available.

Next step: briefly describe the situation — website address, main concerns, when updates were last done.

Fill in the contact form