Care plans are the most reliable revenue most WordPress agencies have. They are also the service clients understand least. The work is invisible when it goes well, and the tools that do the work were never designed to explain it.
This guide covers the full picture: what a care plan should protect, which fleet management tools handle the mechanics, where those tools stop, and how to add the analytics and ecommerce reporting that turns a maintenance invoice into a retainer clients keep.
Who this is for: agencies managing ten or more WordPress sites who already run — or are choosing — a fleet management tool, and want to send clients a report that covers more than plugin updates.
If you’re still deciding how to package and pitch the offer, start with our playbook on how to sell website care plans. This guide is about what comes after the sale: the tools that run a WordPress care plan, and how to make the reporting you send clients worth more than the maintenance it documents.
What a WordPress care plan actually is
A care plan is a fixed monthly fee for keeping a site healthy and supported. No hourly invoices for updates. No panicked call when a plugin breaks the checkout. One accountable partner who knows the site and watches it.
What it is not:
- Hosting. Hosting is a server. A care plan is the person responsible for what runs on it. Many agencies bundle both, and the value in bundling is a single point of contact: the client calls you, not the host, not the plugin vendor, not the domain registrar. They never chase down three parties to find out whose problem it is.
- A retainer of hours. Hours make the client audit your time. A care plan makes them value your access. Scope the small requests, keep them unlimited, and price the plan on outcomes.
- A dashboard subscription. WP Umbrella or Modular DS costs you a few dollars per site. The client isn’t buying the tool. They’re buying an insurance policy: the site stays updated, backed up, and watched, and when something goes wrong, someone who knows the site is already on it.
The economics work because most of the work is automatable and most of the risk is preventable. Your fleet tool handles the first part. The second part — proving that the risk was prevented — is the delivery problem this guide is about.
The eight layers of a care plan
Every serious care plan covers the same ground. Use this as the spec when you package tiers and when you decide what to report on.
| Layer | What it covers | Who does the work |
|---|---|---|
| Updates | WordPress core, plugins, themes, PHP version | Fleet tool (safe updates, rollback) |
| Backups | Offsite, scheduled, restore-tested | Fleet tool, host, or a dedicated backup service |
| Security | Vulnerability alerts, malware scans, firewall, login hardening | Fleet tool plus a WAF (Cloudflare, Patchstack, MalCare) |
| Uptime | Downtime alerts, SSL and domain expiry, DNS changes | Fleet tool or a monitor like Oh Dear |
| Performance | Core Web Vitals, caching, image and database cleanup | Fleet tool checks plus manual work |
| Forms and leads | Are submissions arriving and delivering? | Almost nobody — this is the gap |
| Content and commerce | Traffic, conversions, orders, abandoned carts | Checked separately in analytics and WooCommerce |
| Support and reporting | Small requests, priority response, monthly report | You, with request history pulled from a ticketing system |
The first five layers are what every fleet tool sells. They are table stakes. The bottom three are where care plans differentiate, and where agencies most often go quiet because the data lives somewhere else.
Updates
Run updates on a schedule, never all at once across the fleet, and always with a rollback path. Visual regression testing — screenshots before and after each update — is now standard in WP Umbrella and Modular DS and is worth paying for. A broken layout that nobody noticed for a week is a care plan cancellation waiting to happen.
Backups
A backup you haven’t restored is a hope, not a backup. Store them offsite, keep at least 30 days, and restore one per client per quarter to a staging site. Record that you did. It goes in the report.
Security
Vulnerability disclosure moves fast. A Patchstack or WPScan feed tied to the fleet tool tells you which client sites run a plugin with a published CVE, usually before the patch is even released. Pair that with a firewall in front of the site and two-factor auth on every admin account.
Uptime
Monitor more than “is it up.” SSL expiry, domain expiry, DNS record changes, and broken links are all things a client will eventually blame on you. Catching them first is most of the value.
Performance
Monthly checks are enough for most sites: Core Web Vitals, cache hit rates, database bloat, oversized images. Ecommerce sites deserve weekly attention because slow checkouts cost real money.
Forms and leads
This layer is the one that generates the angriest client email — “we haven’t had a lead in a week” — and the one no fleet tool monitors. A form that renders and says “thank you” but never sends the email looks healthy to every uptime check. We come back to this in where fleet tools stop.
Content and commerce
Traffic and revenue are the numbers your client actually cares about. If your report never mentions them, the client mentally files you under “IT cost” instead of “growth partner.” You don’t have to become a marketing agency. You do have to put the numbers next to the work.
Support and reporting
Unlimited small requests, priority response, and a monthly report that documents everything above. The requests usually live in a ticketing system or a shared inbox, which means the record of what you handled has to be extracted from there every month before it makes the report. The report is the product the client sees. Everything else is the product the client assumes.
The fleet management tools
These are the tools agencies use to run care plans across dozens or hundreds of sites. They all do the core job well. The differences are in hosting model, how they handle backups and security, and how much they think about the client-facing side.
WP Umbrella
A hosted dashboard built specifically around care plans. Safe updates with visual regression, encrypted backups hosted in the EU, Patchstack vulnerability monitoring with CVSS scores, uptime and performance monitoring, and white-label client reports. Priced per site at EUR 1.99, with a security add-on (firewall, virtual patching, malware scanning) at EUR 2 and hourly backups at EUR 2.49. It also ships a public API and an official Claude skill for querying maintenance data.
Best fit: agencies that want a polished, care-plan-first product and don’t want to host anything themselves.
Modular DS
A hosted dashboard from Spain that has grown quickly with agencies, especially in Europe and Latin America. It covers updates with visual comparison, backups, uptime, vulnerability monitoring, a fleet-wide overview, and client reports that can include Google Analytics and Search Console data. Priced in tiers by site count, from $16/mo for 10 sites, with malware scanning added in the 3.0 release in May 2026. Its client reporting is one of the more developed in this category, which is why it comes up in almost every care plan conversation now. One gap: no public API yet — an official API and MCP server are planned for fall 2026.
Best fit: agencies that want strong built-in reporting and a modern UI, and manage a fleet large enough for per-site pricing to matter.
WP Remote
The agency dashboard from the BlogVault and MalCare team. Its strengths are the strengths of those products: incremental backups with a track record for restores and staging, and malware scanning through MalCare (cleanups are a per-incident add-on). Safe updates with visual regression, uptime, and client reports are included, there’s a free tier for dev sites, and it shipped an API and an MCP server in the last year. If backups and security are the part of the care plan you lose sleep over, this is the one built around them.
Best fit: agencies that already use BlogVault or MalCare, or that sell security as the headline of their plan.
MainWP
Self-hosted. You install the MainWP dashboard on your own WordPress site and a child plugin on each client site, and your data never leaves your server. Uptime monitoring with incident history, updates, client management, and a REST API are in the core dashboard; regression testing, security scanning, and pro reports come through extensions. It also shipped an open-source MCP server in July 2026. Pricing is a flat fee for unlimited sites — $199/yr or $29/mo for Pro, with a free Essentials tier — which makes it the cheapest option at scale.
Best fit: agencies with a technical team that wants control over data and cost, and doesn’t mind maintaining the dashboard.
ManageWP
The original. Owned by GoDaddy, free for the basics, with per-site paid add-ons at $1–$2 for premium backups, uptime, and white-label reports, and an all-in-one bundle at $150/mo for up to 100 sites. It is stable and widely used, and after a quiet stretch following the acquisition it picked back up in 2025–2026 with a relaunched roadmap, a UI refresh, and Patchstack vulnerability protection. Still no public API.
Best fit: agencies with an established ManageWP setup that works and no pressing reason to migrate.
At a glance
| WP Umbrella | Modular DS | WP Remote | MainWP | ManageWP | |
|---|---|---|---|---|---|
| Hosting model | Hosted | Hosted | Hosted | Self-hosted | Hosted |
| Safe updates with visual check | Yes | Yes | Yes | Pro extension (HTML diff, not screenshots) | Yes (screenshot compare, needs premium backups) |
| Backups | Included, EU-hosted | Included | BlogVault | Your backup plugin, managed from the dashboard | Free monthly; premium $2/site for hourly–weekly |
| Security | Patchstack alerts, security add-on | Vulnerability alerts | MalCare | Via extension | Free scan; Patchstack protection $2/site |
| Uptime | Included | Included | Included | Built in, with incident history | $1/site add-on |
| Client reports | White-label | White-label, with GA and Search Console | White-label | Pro Reports extension | Basic free; advanced and white-label $1/site each |
| Public API | Yes | Planned, fall 2026 | Yes (REST + MCP server) | Yes (REST + MCP server) | No — outbound Slack webhooks only |
| Pricing shape | Per site | Per-site tiers | Per site | Flat annual | Free plus add-ons |
Pricing and features shift often. Verify current numbers on each vendor’s site before you build a cost model around them.
Choosing a fleet tool
Three questions settle it for most agencies.
Do you want to host the dashboard? If no, MainWP is out. If yes, MainWP is probably in — the cost advantage at 100+ sites is real.
Which layer worries you most? Backups and malware: WP Remote. Update safety and vulnerability response: WP Umbrella or Modular DS. Cost at scale: MainWP.
How much do you rely on the built-in client report? If the maintenance report is the only report you send, weight this heavily; Modular DS and WP Umbrella are ahead here. If you’re going to send a broader report anyway, the built-in one matters less, and you can pick on the other two questions.
For a deeper comparison — all eight major tools, a feature scorecard, and what each costs at 10, 50, and 200 sites — see our guide to managing multiple WordPress sites.
One thing not to optimize for: whichever tool you choose, don’t plan to switch often. Migrating a fleet is a week of work, and the tools are close enough that the switch rarely pays for itself. Pick one, run it, and build the reporting layer on top of it.
Where fleet tools stop
Fleet tools are built to answer one question: are the WordPress sites maintained? They answer it well. But a care plan client is paying for more than maintenance, and the moment they ask about anything else, the fleet tool goes quiet.
Here’s what none of them see.
Forms. A contact form that silently stops sending email is the most common “the site is broken” call an agency gets. The site is up, plugins are current, the backup ran. Every fleet check is green. The client has lost a week of leads. No fleet tool monitors submission volume, because the WordPress management APIs don’t expose it.
The bigger miss is what’s inside the submissions. Most client forms carry structured fields — a service dropdown, a budget range, a “how did you hear about us” checkbox, a location. That’s the data a client would actually use: which services people ask for, where leads come from, how the mix shifts month to month. No fleet tool reports on submission volume, let alone breaks it down by field, shows the deltas, or keeps the history in one place.
Ecommerce. WooCommerce orders, cart abandonment, checkout completion rates. If a plugin update on Friday drops checkout conversion by half, the fleet tool reports a successful update. The store owner notices on Monday. And beyond the incident, none of them give the client a view of how the store is performing — revenue trend, order volume, conversion through the funnel, best sellers, abandoned carts — alongside the maintenance that keeps it running.
Analytics. Modular DS can put Google Analytics numbers in a report. That’s useful. What it can’t do is put them next to what happened on the site — the deploy, the update, the form fix — so the client sees cause and effect instead of a chart.
Everything that isn’t WordPress. Most agencies have a Craft build, a headless site, a Shopify store, or a Laravel app somewhere in the portfolio. None of it exists in a WordPress dashboard. A client with a WordPress marketing site and a separate store is two problems in two tools.
Code. Commits, pull requests, and deploys are where the real development work shows up. A care plan that includes development hours has no way to document them through a fleet tool.
Billing. Which care plan clients are current, which are overdue, and which are consuming far more support than they pay for. Fleet tools track sites, not the economics of the client.
This is the reporting gap. Fleet tools produce a maintenance report, and a maintenance report still has value: it proves the updates ran, the backups exist, and the site stayed up. Keep sending it if it’s working. But maintenance is one part of the client’s website, not the whole of it. The win is a report where maintenance sits inside the bigger picture — traffic, leads with the fields behind them, store performance — so the client sees their site as a working asset you’re running, not a list of plugins you updated.
Adding the reporting layer
The answer is not to replace the fleet tool. It’s to put a layer above it that reads from the fleet tool and from everything else, organized by client. That’s what Burrow does.
How the connection works
Burrow connects to the fleet tools with a read-only API key. Nothing is installed on client sites. Sites and clients import automatically, and your fleet tool stays exactly as it is.
| Fleet tool | Status | What imports into Burrow | What stays in the fleet tool |
|---|---|---|---|
| WP Umbrella | Available | Sites and clients, update status and history with visual-regression diffs, Patchstack vulnerabilities with CVSS scores | Pushing updates, backup storage, uptime workflows, care-plan automation |
| WP Remote | Available | Sites and clients, backup history (every snapshot, pass or fail), security detections, update status | Updates and staging, backup restores, malware cleanup, uptime workflows |
| MainWP | Available | Sites and clients, update status across the fleet, uptime monitors with incident history | Bulk updates and child-site control, backups, security scanning |
| Modular DS | In development | Planned: sites and clients, update and uptime status | Everything Modular DS does today |
| ManageWP | No native connection | Use the Burrow WordPress plugin per site | Everything |
Each integration is deliberately narrow: Burrow imports what the vendor’s API exposes and doesn’t pretend to have the rest. WP Umbrella’s API doesn’t share backup or uptime history, so Burrow doesn’t show it. WP Remote’s uptime is current status, not incident history. The integration pages say exactly what crosses over.
The Modular DS integration is being built alongside the public API Modular DS has planned for fall 2026. If you run Modular DS and want it early, start a trial and tell us — it helps prioritize.
Going deeper with the Burrow WordPress plugin
The fleet connection covers the maintenance layer. For forms and WooCommerce, install the Burrow WordPress plugin. If you run a fleet tool, push it across every site in one pass the same way you’d deploy any plugin. Then open each site’s onboarding, pick the forms you want tracked — Gravity Forms, Fluent Forms, Ninja Forms, Contact Form 7 — and, if the site runs WooCommerce, switch that on too. A few config settings per site and it’s capturing:
- Form submissions with form ID, page, timestamp, and the structured fields inside them. When volume drops to zero after an update, it shows up in the timeline next to the update.
- WooCommerce events — orders placed, items added, checkouts started, payments completed, refunds. The Ecommerce channel turns them into revenue trends, funnels, best sellers, and abandoned carts per store.
- Plugin and system events with from/to version numbers, so update proof exists even for sites outside the fleet tool.
- History backfill on install, so the first report isn’t empty.
The install is fleet-wide; the tracking is opt-in per site. Turn it on where the depth earns its keep and leave the rest alone.
The rest of the client’s stack
Once the WordPress fleet is in, the other connections are each a few minutes:
- Analytics — Google Analytics, Plausible, and Fathom sync nightly into one normalized shape: visitors, pageviews, referrers, devices, locations, goals. Portfolio-wide and per site.
- Code — GitHub commits, pull requests, and deploys per client.
- Monitoring — Oh Dear if you run it in addition to the fleet tool’s checks.
- Invoicing — Stripe, FreshBooks, Harvest, and Tillage, so each client’s card shows what was billed next to what was delivered.
- Non-WordPress projects — Craft CMS, Statamic, ExpressionEngine, or anything else through the API.
Everything lands in one timeline per client. The fleet tool’s update event sits next to the form-volume drop, the GitHub fix, the traffic recovery, and the invoice.
Division of labor
| Layer | Tool | Answers |
|---|---|---|
| Maintenance | WP Umbrella, Modular DS, WP Remote, MainWP | Are the WordPress sites updated, backed up, and secure? |
| Operations and reporting | Burrow | What happened across this client’s whole engagement this month — and what did it cost them? |
Run both. The fleet tool does the work. Burrow is where you and the client look.
What a care plan report should contain
A good report has one job: make the invisible work visible, and put it next to the numbers the client cares about. Here’s the structure we recommend. Every line maps to a Burrow channel, so the report assembles itself from the month’s events instead of from a Friday afternoon of screenshots.
If you’d rather see one than read about one, open the sample client report Burrow generates — it follows this structure.
1. Summary
Three or four sentences. What was done, what was caught, what changed. Write this one by hand — it’s where your judgment shows.
2. Maintenance performed
From the fleet tool via the System channel:
- Core, plugin, and theme updates with version numbers and dates
- Visual regression passes and any rollbacks
- Vulnerabilities disclosed for installed plugins, and when each was patched
3. Protection and availability
- Backups completed, with the last restore test date (Backups channel)
- Uptime percentage and any incidents with time to resolution (Monitoring channel)
- SSL and domain status
4. Leads and forms
From the Burrow plugin via the Forms channel:
- Submissions per form, month over month
- Breakdowns of the structured fields — service requested, budget range, lead source — with deltas against last month
- Any period where volume dropped and what was done about it
This section alone changes how clients read the report. “Your contact form delivered 43 leads this month, up from 31” is a sentence no fleet tool can write.
5. Traffic
From the Analytics channel, nightly-synced:
- Visitors, pageviews, and the trend
- Top pages and referrers
- Goal completions
Keep it to what matters. The client can open GA4 if they want a hundred reports. You’re showing them the five numbers and how they moved.
6. Commerce (where applicable)
From the Ecommerce channel:
- Revenue and order count with period deltas
- Checkout completion rate
- Best sellers and abandoned carts
7. Development and requests
- Commits, pull requests, and deploys (Code channel)
- Support requests handled, with a short list
8. Next month
What’s planned, what’s recommended, and anything the client needs to decide. This is where upsells belong — a PHP upgrade, a checkout redesign, a form rebuild — with evidence from the sections above.
In Burrow, sections 2 through 7 come from the month’s event stream. The monthly digest compiles them per client; you review, write the summary and next steps, and send or schedule it. Clients with portal access can see the same timeline between reports, so “what’s been happening?” stops being an email.
Tiering plans by reporting depth
Most agencies tier care plans on support hours or response time. A better axis is what you monitor and report on, because that’s what the client can see, and it maps to the client’s actual risk.
| Essential | Growth | Commerce | |
|---|---|---|---|
| Who it’s for | Brochure sites, low change | Lead-generation sites | WooCommerce stores |
| Fleet tool layers | Updates, backups, security, uptime | Same, plus performance | Same, weekly performance |
| Burrow plugin | Optional | Yes — form monitoring | Yes — forms and WooCommerce |
| Analytics in report | Summary line | Full traffic section | Full traffic plus conversion |
| Report sections | 1–3, 8 | 1–5, 7–8 | All eight |
| Client portal | No | Yes | Yes |
| Support | Small requests, 2-day response | Unlimited small requests, next-day | Unlimited, same-day |
The cost to you of moving a client from Essential to Growth is a plugin install and a few minutes of setup. The value to the client is a report that talks about leads instead of plugins. Price the gap accordingly.
For pricing itself, the short version from our selling guide: start higher than feels comfortable, tier by the client’s risk, and raise rates every year until someone leaves. Don’t price off your tool costs. A fleet tool runs a few dollars per site and Burrow is $39/mo for five projects, $3 per project after. Spread across a plan priced at a few hundred dollars a month, the tooling is a small fraction of what the client pays.
Rollout checklist
If you’re adding the reporting layer to an existing care plan business, this is the order that works.
- Audit the fleet. Every site in the fleet tool, mapped to a client. Fix the ones that are orphaned or mislabeled first — the import will mirror your structure.
- Connect the fleet tool to Burrow. One read-only API key. Sites and clients import. Confirm the client mapping.
- Install the Burrow plugin on the sites that need depth. Start with every WooCommerce site and every site where the client has ever asked about leads. Backfill fills in history.
- Connect analytics. GA4, Plausible, or Fathom per site. The first nightly sync lands the next morning.
- Connect GitHub and invoicing. Optional, but this is what makes the client card show economics, not just health.
- Run one month. Let the timeline fill. Don’t send anything yet.
- Send the first new report to three clients. Pick one per tier. Ask what they read and what they skipped. Adjust the sections.
- Roll it out and re-tier. Move clients to the tier that matches what you’re now reporting on, and price the move.
The fleet tool doesn’t change. What changes is that the report you send stops being a list of plugin versions and starts being the reason the client stays.
If you’re running WP Umbrella, WP Remote, or MainWP today, the connection takes an afternoon, and you can preview the report your clients would get before you connect anything. If you’re on Modular DS, the integration is in development — start a trial and we’ll let you know when it lands. Start your free trial or read how the maintenance reporting workflow fits your plan.