[ The Guide ]

The agency guide to WordPress care plans

What a WordPress care plan should include, how WP Umbrella, Modular DS, WP Remote, MainWP, and ManageWP compare for managing a fleet, and how to add analytics and ecommerce reporting on top of the maintenance tools you already run.

  • WP Umbrella
  • Modular DS
  • WP Remote
  • MainWP
  • ManageWP

Updated August 27, 2026 · 18 min read · Free, no email required

Care plans are the most reliable revenue most WordPress agencies have. They are also the service clients understand least. The work is invisible when it goes well, and the tools that do the work were never designed to explain it.

This guide covers the full picture: what a care plan should protect, which fleet management tools handle the mechanics, where those tools stop, and how to add the analytics and ecommerce reporting that turns a maintenance invoice into a retainer clients keep.

Who this is for: agencies managing ten or more WordPress sites who already run — or are choosing — a fleet management tool, and want to send clients a report that covers more than plugin updates.

If you’re still deciding how to package and pitch the offer, start with our playbook on how to sell website care plans. This guide is about what comes after the sale: the tools that run a WordPress care plan, and how to make the reporting you send clients worth more than the maintenance it documents.

What a WordPress care plan actually is

A care plan is a fixed monthly fee for keeping a site healthy and supported. No hourly invoices for updates. No panicked call when a plugin breaks the checkout. One accountable partner who knows the site and watches it.

What it is not:

  • Hosting. Hosting is a server. A care plan is the person responsible for what runs on it. Many agencies bundle both, and the value in bundling is a single point of contact: the client calls you, not the host, not the plugin vendor, not the domain registrar. They never chase down three parties to find out whose problem it is.
  • A retainer of hours. Hours make the client audit your time. A care plan makes them value your access. Scope the small requests, keep them unlimited, and price the plan on outcomes.
  • A dashboard subscription. WP Umbrella or Modular DS costs you a few dollars per site. The client isn’t buying the tool. They’re buying an insurance policy: the site stays updated, backed up, and watched, and when something goes wrong, someone who knows the site is already on it.

The economics work because most of the work is automatable and most of the risk is preventable. Your fleet tool handles the first part. The second part — proving that the risk was prevented — is the delivery problem this guide is about.

The eight layers of a care plan

Every serious care plan covers the same ground. Use this as the spec when you package tiers and when you decide what to report on.

LayerWhat it coversWho does the work
UpdatesWordPress core, plugins, themes, PHP versionFleet tool (safe updates, rollback)
BackupsOffsite, scheduled, restore-testedFleet tool, host, or a dedicated backup service
SecurityVulnerability alerts, malware scans, firewall, login hardeningFleet tool plus a WAF (Cloudflare, Patchstack, MalCare)
UptimeDowntime alerts, SSL and domain expiry, DNS changesFleet tool or a monitor like Oh Dear
PerformanceCore Web Vitals, caching, image and database cleanupFleet tool checks plus manual work
Forms and leadsAre submissions arriving and delivering?Almost nobody — this is the gap
Content and commerceTraffic, conversions, orders, abandoned cartsChecked separately in analytics and WooCommerce
Support and reportingSmall requests, priority response, monthly reportYou, with request history pulled from a ticketing system

The first five layers are what every fleet tool sells. They are table stakes. The bottom three are where care plans differentiate, and where agencies most often go quiet because the data lives somewhere else.

Updates

Run updates on a schedule, never all at once across the fleet, and always with a rollback path. Visual regression testing — screenshots before and after each update — is now standard in WP Umbrella and Modular DS and is worth paying for. A broken layout that nobody noticed for a week is a care plan cancellation waiting to happen.

Backups

A backup you haven’t restored is a hope, not a backup. Store them offsite, keep at least 30 days, and restore one per client per quarter to a staging site. Record that you did. It goes in the report.

Security

Vulnerability disclosure moves fast. A Patchstack or WPScan feed tied to the fleet tool tells you which client sites run a plugin with a published CVE, usually before the patch is even released. Pair that with a firewall in front of the site and two-factor auth on every admin account.

Uptime

Monitor more than “is it up.” SSL expiry, domain expiry, DNS record changes, and broken links are all things a client will eventually blame on you. Catching them first is most of the value.

Performance

Monthly checks are enough for most sites: Core Web Vitals, cache hit rates, database bloat, oversized images. Ecommerce sites deserve weekly attention because slow checkouts cost real money.

Forms and leads

This layer is the one that generates the angriest client email — “we haven’t had a lead in a week” — and the one no fleet tool monitors. A form that renders and says “thank you” but never sends the email looks healthy to every uptime check. We come back to this in where fleet tools stop.

Content and commerce

Traffic and revenue are the numbers your client actually cares about. If your report never mentions them, the client mentally files you under “IT cost” instead of “growth partner.” You don’t have to become a marketing agency. You do have to put the numbers next to the work.

Support and reporting

Unlimited small requests, priority response, and a monthly report that documents everything above. The requests usually live in a ticketing system or a shared inbox, which means the record of what you handled has to be extracted from there every month before it makes the report. The report is the product the client sees. Everything else is the product the client assumes.

The fleet management tools

These are the tools agencies use to run care plans across dozens or hundreds of sites. They all do the core job well. The differences are in hosting model, how they handle backups and security, and how much they think about the client-facing side.

WP Umbrella

A hosted dashboard built specifically around care plans. Safe updates with visual regression, encrypted backups hosted in the EU, Patchstack vulnerability monitoring with CVSS scores, uptime and performance monitoring, and white-label client reports. Priced per site at EUR 1.99, with a security add-on (firewall, virtual patching, malware scanning) at EUR 2 and hourly backups at EUR 2.49. It also ships a public API and an official Claude skill for querying maintenance data.

Best fit: agencies that want a polished, care-plan-first product and don’t want to host anything themselves.

Modular DS

A hosted dashboard from Spain that has grown quickly with agencies, especially in Europe and Latin America. It covers updates with visual comparison, backups, uptime, vulnerability monitoring, a fleet-wide overview, and client reports that can include Google Analytics and Search Console data. Priced in tiers by site count, from $16/mo for 10 sites, with malware scanning added in the 3.0 release in May 2026. Its client reporting is one of the more developed in this category, which is why it comes up in almost every care plan conversation now. One gap: no public API yet — an official API and MCP server are planned for fall 2026.

Best fit: agencies that want strong built-in reporting and a modern UI, and manage a fleet large enough for per-site pricing to matter.

WP Remote

The agency dashboard from the BlogVault and MalCare team. Its strengths are the strengths of those products: incremental backups with a track record for restores and staging, and malware scanning through MalCare (cleanups are a per-incident add-on). Safe updates with visual regression, uptime, and client reports are included, there’s a free tier for dev sites, and it shipped an API and an MCP server in the last year. If backups and security are the part of the care plan you lose sleep over, this is the one built around them.

Best fit: agencies that already use BlogVault or MalCare, or that sell security as the headline of their plan.

MainWP

Self-hosted. You install the MainWP dashboard on your own WordPress site and a child plugin on each client site, and your data never leaves your server. Uptime monitoring with incident history, updates, client management, and a REST API are in the core dashboard; regression testing, security scanning, and pro reports come through extensions. It also shipped an open-source MCP server in July 2026. Pricing is a flat fee for unlimited sites — $199/yr or $29/mo for Pro, with a free Essentials tier — which makes it the cheapest option at scale.

Best fit: agencies with a technical team that wants control over data and cost, and doesn’t mind maintaining the dashboard.

ManageWP

The original. Owned by GoDaddy, free for the basics, with per-site paid add-ons at $1–$2 for premium backups, uptime, and white-label reports, and an all-in-one bundle at $150/mo for up to 100 sites. It is stable and widely used, and after a quiet stretch following the acquisition it picked back up in 2025–2026 with a relaunched roadmap, a UI refresh, and Patchstack vulnerability protection. Still no public API.

Best fit: agencies with an established ManageWP setup that works and no pressing reason to migrate.

At a glance

WP UmbrellaModular DSWP RemoteMainWPManageWP
Hosting modelHostedHostedHostedSelf-hostedHosted
Safe updates with visual checkYesYesYesPro extension (HTML diff, not screenshots)Yes (screenshot compare, needs premium backups)
BackupsIncluded, EU-hostedIncludedBlogVaultYour backup plugin, managed from the dashboardFree monthly; premium $2/site for hourly–weekly
SecurityPatchstack alerts, security add-onVulnerability alertsMalCareVia extensionFree scan; Patchstack protection $2/site
UptimeIncludedIncludedIncludedBuilt in, with incident history$1/site add-on
Client reportsWhite-labelWhite-label, with GA and Search ConsoleWhite-labelPro Reports extensionBasic free; advanced and white-label $1/site each
Public APIYesPlanned, fall 2026Yes (REST + MCP server)Yes (REST + MCP server)No — outbound Slack webhooks only
Pricing shapePer sitePer-site tiersPer siteFlat annualFree plus add-ons

Pricing and features shift often. Verify current numbers on each vendor’s site before you build a cost model around them.

Choosing a fleet tool

Three questions settle it for most agencies.

Do you want to host the dashboard? If no, MainWP is out. If yes, MainWP is probably in — the cost advantage at 100+ sites is real.

Which layer worries you most? Backups and malware: WP Remote. Update safety and vulnerability response: WP Umbrella or Modular DS. Cost at scale: MainWP.

How much do you rely on the built-in client report? If the maintenance report is the only report you send, weight this heavily; Modular DS and WP Umbrella are ahead here. If you’re going to send a broader report anyway, the built-in one matters less, and you can pick on the other two questions.

For a deeper comparison — all eight major tools, a feature scorecard, and what each costs at 10, 50, and 200 sites — see our guide to managing multiple WordPress sites.

One thing not to optimize for: whichever tool you choose, don’t plan to switch often. Migrating a fleet is a week of work, and the tools are close enough that the switch rarely pays for itself. Pick one, run it, and build the reporting layer on top of it.

Where fleet tools stop

Fleet tools are built to answer one question: are the WordPress sites maintained? They answer it well. But a care plan client is paying for more than maintenance, and the moment they ask about anything else, the fleet tool goes quiet.

Here’s what none of them see.

Forms. A contact form that silently stops sending email is the most common “the site is broken” call an agency gets. The site is up, plugins are current, the backup ran. Every fleet check is green. The client has lost a week of leads. No fleet tool monitors submission volume, because the WordPress management APIs don’t expose it.

The bigger miss is what’s inside the submissions. Most client forms carry structured fields — a service dropdown, a budget range, a “how did you hear about us” checkbox, a location. That’s the data a client would actually use: which services people ask for, where leads come from, how the mix shifts month to month. No fleet tool reports on submission volume, let alone breaks it down by field, shows the deltas, or keeps the history in one place.

Ecommerce. WooCommerce orders, cart abandonment, checkout completion rates. If a plugin update on Friday drops checkout conversion by half, the fleet tool reports a successful update. The store owner notices on Monday. And beyond the incident, none of them give the client a view of how the store is performing — revenue trend, order volume, conversion through the funnel, best sellers, abandoned carts — alongside the maintenance that keeps it running.

Analytics. Modular DS can put Google Analytics numbers in a report. That’s useful. What it can’t do is put them next to what happened on the site — the deploy, the update, the form fix — so the client sees cause and effect instead of a chart.

Everything that isn’t WordPress. Most agencies have a Craft build, a headless site, a Shopify store, or a Laravel app somewhere in the portfolio. None of it exists in a WordPress dashboard. A client with a WordPress marketing site and a separate store is two problems in two tools.

Code. Commits, pull requests, and deploys are where the real development work shows up. A care plan that includes development hours has no way to document them through a fleet tool.

Billing. Which care plan clients are current, which are overdue, and which are consuming far more support than they pay for. Fleet tools track sites, not the economics of the client.

This is the reporting gap. Fleet tools produce a maintenance report, and a maintenance report still has value: it proves the updates ran, the backups exist, and the site stayed up. Keep sending it if it’s working. But maintenance is one part of the client’s website, not the whole of it. The win is a report where maintenance sits inside the bigger picture — traffic, leads with the fields behind them, store performance — so the client sees their site as a working asset you’re running, not a list of plugins you updated.

Adding the reporting layer

The answer is not to replace the fleet tool. It’s to put a layer above it that reads from the fleet tool and from everything else, organized by client. That’s what Burrow does.

How the connection works

Burrow connects to the fleet tools with a read-only API key. Nothing is installed on client sites. Sites and clients import automatically, and your fleet tool stays exactly as it is.

Fleet toolStatusWhat imports into BurrowWhat stays in the fleet tool
WP UmbrellaAvailableSites and clients, update status and history with visual-regression diffs, Patchstack vulnerabilities with CVSS scoresPushing updates, backup storage, uptime workflows, care-plan automation
WP RemoteAvailableSites and clients, backup history (every snapshot, pass or fail), security detections, update statusUpdates and staging, backup restores, malware cleanup, uptime workflows
MainWPAvailableSites and clients, update status across the fleet, uptime monitors with incident historyBulk updates and child-site control, backups, security scanning
Modular DSIn developmentPlanned: sites and clients, update and uptime statusEverything Modular DS does today
ManageWPNo native connectionUse the Burrow WordPress plugin per siteEverything

Each integration is deliberately narrow: Burrow imports what the vendor’s API exposes and doesn’t pretend to have the rest. WP Umbrella’s API doesn’t share backup or uptime history, so Burrow doesn’t show it. WP Remote’s uptime is current status, not incident history. The integration pages say exactly what crosses over.

The Modular DS integration is being built alongside the public API Modular DS has planned for fall 2026. If you run Modular DS and want it early, start a trial and tell us — it helps prioritize.

Going deeper with the Burrow WordPress plugin

The fleet connection covers the maintenance layer. For forms and WooCommerce, install the Burrow WordPress plugin. If you run a fleet tool, push it across every site in one pass the same way you’d deploy any plugin. Then open each site’s onboarding, pick the forms you want tracked — Gravity Forms, Fluent Forms, Ninja Forms, Contact Form 7 — and, if the site runs WooCommerce, switch that on too. A few config settings per site and it’s capturing:

  • Form submissions with form ID, page, timestamp, and the structured fields inside them. When volume drops to zero after an update, it shows up in the timeline next to the update.
  • WooCommerce events — orders placed, items added, checkouts started, payments completed, refunds. The Ecommerce channel turns them into revenue trends, funnels, best sellers, and abandoned carts per store.
  • Plugin and system events with from/to version numbers, so update proof exists even for sites outside the fleet tool.
  • History backfill on install, so the first report isn’t empty.

The install is fleet-wide; the tracking is opt-in per site. Turn it on where the depth earns its keep and leave the rest alone.

The rest of the client’s stack

Once the WordPress fleet is in, the other connections are each a few minutes:

  • AnalyticsGoogle Analytics, Plausible, and Fathom sync nightly into one normalized shape: visitors, pageviews, referrers, devices, locations, goals. Portfolio-wide and per site.
  • CodeGitHub commits, pull requests, and deploys per client.
  • MonitoringOh Dear if you run it in addition to the fleet tool’s checks.
  • Invoicing — Stripe, FreshBooks, Harvest, and Tillage, so each client’s card shows what was billed next to what was delivered.
  • Non-WordPress projectsCraft CMS, Statamic, ExpressionEngine, or anything else through the API.

Everything lands in one timeline per client. The fleet tool’s update event sits next to the form-volume drop, the GitHub fix, the traffic recovery, and the invoice.

Division of labor

LayerToolAnswers
MaintenanceWP Umbrella, Modular DS, WP Remote, MainWPAre the WordPress sites updated, backed up, and secure?
Operations and reportingBurrowWhat happened across this client’s whole engagement this month — and what did it cost them?

Run both. The fleet tool does the work. Burrow is where you and the client look.

What a care plan report should contain

A good report has one job: make the invisible work visible, and put it next to the numbers the client cares about. Here’s the structure we recommend. Every line maps to a Burrow channel, so the report assembles itself from the month’s events instead of from a Friday afternoon of screenshots.

If you’d rather see one than read about one, open the sample client report Burrow generates — it follows this structure.

1. Summary

Three or four sentences. What was done, what was caught, what changed. Write this one by hand — it’s where your judgment shows.

2. Maintenance performed

From the fleet tool via the System channel:

  • Core, plugin, and theme updates with version numbers and dates
  • Visual regression passes and any rollbacks
  • Vulnerabilities disclosed for installed plugins, and when each was patched

3. Protection and availability

  • Backups completed, with the last restore test date (Backups channel)
  • Uptime percentage and any incidents with time to resolution (Monitoring channel)
  • SSL and domain status

4. Leads and forms

From the Burrow plugin via the Forms channel:

  • Submissions per form, month over month
  • Breakdowns of the structured fields — service requested, budget range, lead source — with deltas against last month
  • Any period where volume dropped and what was done about it

This section alone changes how clients read the report. “Your contact form delivered 43 leads this month, up from 31” is a sentence no fleet tool can write.

5. Traffic

From the Analytics channel, nightly-synced:

  • Visitors, pageviews, and the trend
  • Top pages and referrers
  • Goal completions

Keep it to what matters. The client can open GA4 if they want a hundred reports. You’re showing them the five numbers and how they moved.

6. Commerce (where applicable)

From the Ecommerce channel:

  • Revenue and order count with period deltas
  • Checkout completion rate
  • Best sellers and abandoned carts

7. Development and requests

  • Commits, pull requests, and deploys (Code channel)
  • Support requests handled, with a short list

8. Next month

What’s planned, what’s recommended, and anything the client needs to decide. This is where upsells belong — a PHP upgrade, a checkout redesign, a form rebuild — with evidence from the sections above.

In Burrow, sections 2 through 7 come from the month’s event stream. The monthly digest compiles them per client; you review, write the summary and next steps, and send or schedule it. Clients with portal access can see the same timeline between reports, so “what’s been happening?” stops being an email.

Tiering plans by reporting depth

Most agencies tier care plans on support hours or response time. A better axis is what you monitor and report on, because that’s what the client can see, and it maps to the client’s actual risk.

EssentialGrowthCommerce
Who it’s forBrochure sites, low changeLead-generation sitesWooCommerce stores
Fleet tool layersUpdates, backups, security, uptimeSame, plus performanceSame, weekly performance
Burrow pluginOptionalYes — form monitoringYes — forms and WooCommerce
Analytics in reportSummary lineFull traffic sectionFull traffic plus conversion
Report sections1–3, 81–5, 7–8All eight
Client portalNoYesYes
SupportSmall requests, 2-day responseUnlimited small requests, next-dayUnlimited, same-day

The cost to you of moving a client from Essential to Growth is a plugin install and a few minutes of setup. The value to the client is a report that talks about leads instead of plugins. Price the gap accordingly.

For pricing itself, the short version from our selling guide: start higher than feels comfortable, tier by the client’s risk, and raise rates every year until someone leaves. Don’t price off your tool costs. A fleet tool runs a few dollars per site and Burrow is $39/mo for five projects, $3 per project after. Spread across a plan priced at a few hundred dollars a month, the tooling is a small fraction of what the client pays.

Rollout checklist

If you’re adding the reporting layer to an existing care plan business, this is the order that works.

  1. Audit the fleet. Every site in the fleet tool, mapped to a client. Fix the ones that are orphaned or mislabeled first — the import will mirror your structure.
  2. Connect the fleet tool to Burrow. One read-only API key. Sites and clients import. Confirm the client mapping.
  3. Install the Burrow plugin on the sites that need depth. Start with every WooCommerce site and every site where the client has ever asked about leads. Backfill fills in history.
  4. Connect analytics. GA4, Plausible, or Fathom per site. The first nightly sync lands the next morning.
  5. Connect GitHub and invoicing. Optional, but this is what makes the client card show economics, not just health.
  6. Run one month. Let the timeline fill. Don’t send anything yet.
  7. Send the first new report to three clients. Pick one per tier. Ask what they read and what they skipped. Adjust the sections.
  8. Roll it out and re-tier. Move clients to the tier that matches what you’re now reporting on, and price the move.

The fleet tool doesn’t change. What changes is that the report you send stops being a list of plugin versions and starts being the reason the client stays.

If you’re running WP Umbrella, WP Remote, or MainWP today, the connection takes an afternoon, and you can preview the report your clients would get before you connect anything. If you’re on Modular DS, the integration is in development — start a trial and we’ll let you know when it lands. Start your free trial or read how the maintenance reporting workflow fits your plan.

Frequently asked questions

What is a WordPress care plan?
A WordPress care plan is a fixed-price monthly service an agency sells to keep a client's site updated, backed up, secure, monitored, and supported — with a report that documents the work. It replaces ad-hoc hourly maintenance with one accountable partner and one predictable invoice.
What should a WordPress care plan include?
At minimum: core, plugin, and theme updates; offsite backups you have tested restoring; uptime monitoring; security scanning and a firewall; performance checks; a support window for small requests; and a monthly report. Higher tiers add analytics review, form-health monitoring, ecommerce reporting, and development time.
Which tool is best for managing a fleet of WordPress sites?
It depends on how you work. WP Umbrella and Modular DS are hosted dashboards built around care plans, with safe updates and client reports. WP Remote pairs with BlogVault backups and MalCare security. MainWP is self-hosted and extension-based. ManageWP is the long-standing GoDaddy-owned option. All of them handle the maintenance mechanics; none of them see beyond WordPress.
Do I still need a fleet management tool if I use Burrow?
Yes. Burrow does not push plugin updates, store backups, or run malware scans. Keep WP Umbrella, Modular DS, WP Remote, or MainWP for the work. Burrow connects to those tools with a read-only API key and adds analytics, form submissions, WooCommerce data, code activity, and invoicing to the client's record — so the report covers the whole engagement, not just maintenance.
How does Burrow connect to WordPress fleet management tools?
WP Umbrella, WP Remote, and MainWP connect today with one read-only API token — sites and clients import automatically and nothing is installed on client sites. A Modular DS integration is in development alongside the public API Modular DS has planned for fall 2026. For any WordPress site, the optional Burrow plugin adds form submissions and WooCommerce events that no maintenance API exposes.
How much should I charge for a WordPress care plan?
Price on the client's risk and the depth of what you deliver, not on your tool costs. A brochure site with a contact form is a different plan from a WooCommerce store doing five figures a month. Tier the plan by what you monitor and report on, and revisit pricing every year. Our playbook on selling care plans covers packaging and pricing in detail.
Can care plan reports include Google Analytics and WooCommerce data?
Yes. Burrow pulls Google Analytics, Plausible, and Fathom data on a nightly sync and captures WooCommerce orders, carts, and checkout events through its WordPress plugin. Both land in the same client timeline as the maintenance events imported from your fleet tool, so one monthly report can show updates, uptime, traffic, leads, and revenue together.

Care plans sold. Now show the work.

Burrow gives your care plan clients real-time visibility into deploys, backups, uptime, and monthly reports — automatically.

Self-funded · Independent · Built for the long term