The hidden costs nobody quotes: hosting, domains, maintenance

The quote covers the build. It is one number, it appears once, and it is the number everyone argues about. What it does not cover is the next three years, and the next three years are what decide whether the site is still doing its job when someone finally goes looking for it.
This is the part of a web project that gets discussed last, usually in a single line near the bottom of a proposal, and then not at all. Then something breaks quietly. A certificate lapses. A domain renewal bounces off an expired company card. A plugin nobody remembers installing gets a critical advisory. The site does not go down with a bang. It degrades, and the first person to notice is a buyer who never tells you.
So it is worth being specific about what the ongoing website running costs actually are, what each one buys, and what happens if you decline them.
Where website running costs actually come from
Six things, and every site has all six whether or not anyone is paying for them.
Hosting. The machine and the software stack the site runs on, plus whoever is responsible when it stops responding.
The domain. Rented annually from a registry through a registrar. Not owned, rented.
A TLS certificate. The thing that makes the padlock appear and stops a browser throwing a full-page warning in front of your homepage.
The CMS, theme and plugin licences. Most commercial WordPress components are sold as an annual licence. When the licence lapses the plugin keeps running and stops receiving updates, which is the worst of both outcomes.
Backups and monitoring. A backup you have never restored is not a backup. Monitoring that emails an address nobody reads is not monitoring.
Someone applying all of it. This is the cost people actually resist, and it is the one that makes the other five worth anything.
None of those disappear if you ignore them. They just move from a line item into a risk.
Hosting is not a commodity, and the cheap tier is the expensive one
Hosting is sold as though it were electricity, priced per unit and identical everywhere. It is not. What you are buying is a combination of resources, isolation, and a support relationship, and the three cheapest tiers on any Singapore host’s pricing page are cheap because at least one of those is missing.
The visible difference is speed under load. A shared plan running several hundred sites per machine is fine at nine in the morning and slow when three of your neighbours get traffic. The invisible difference matters more: whether backups exist, whether they are stored off the same machine, whether anyone would notice an outage before you did, and whether there is a human to escalate to when a database table corrupts at eleven at night.
Ours starts from S$200 a year for managed hosting with SSL, and that is a starting figure rather than a price. What moves it is traffic, storage, whether the site needs a staging environment for testing changes before they go live, and whether it is doing anything beyond serving pages. A site with a quotation form and a few thousand monthly visitors is not the same load as one running product data and a customer portal, and pretending otherwise is how hosting gets undersold and then quietly rationed.
You can also host it yourself, and for some firms with an internal IT function that is the right answer. Either way, the site and the accounts belong to you. The question is not who owns it, it is who is responsible at two in the morning.
Domains: the renewal that ends companies
A domain is the cheapest thing on this list and the only one that can take the entire business offline in a single afternoon.
Pricing depends entirely on the extension. A .com sits at the bottom of the range. A .sg or .com.sg is quoted separately because registry and registrar pricing differ, and a .com.sg carries a local presence requirement that a .com does not. Country and specialist extensions vary widely. We pass registrar cost through rather than marking it up, because a markup on a domain is one of the few genuinely indefensible line items in this industry.
The cost is trivial. The failure mode is not. Registrars are required under ICANN’s Expired Registration Recovery Policy to send a renewal notice about a month before expiry and another about a week before, and to notify again after expiry. Those notices go to whatever address is on the registrant record, which in a business that has changed hands, changed IT providers or lost a marketing manager is frequently an inbox nobody opens. Once the registration is deleted there is a redemption grace period of 30 days in which it can be restored at a restoration fee, and after that the name is released to anyone.
This is not hypothetical. Across 54 Singapore B2B sites we reviewed in August 2026, 2 had a domain that did not resolve at all while still ranking in Google under the company name. The businesses were trading. The search results were live. Anyone who clicked got a connection error, then went to a competitor. Six more answered on only one of the www and non-www forms of their own domain, which is the same failure at half strength.
Three things prevent all of it. Registrant contact details on a role address rather than a person’s mailbox. Auto-renew on, with a card that has not expired. Registrar lock enabled so the name cannot be transferred out without an explicit unlock.
Certificates, licences and the software underneath
Certificates used to be a once-a-year administrative job. They are not any more, and the direction of travel is worth understanding before you decide to manage them by hand.
Let’s Encrypt certificates, which secure a large share of the web, are valid for 90 days by default. Commercial certificates have been shrinking too. The CA/Browser Forum has adopted a schedule that takes the maximum validity period for a public TLS certificate from 398 days down to 47 days between March 2026 and March 2029. A certificate you renew manually once a year becomes a certificate you renew manually eight times a year, which nobody does reliably, which is precisely the point of the change. Automated renewal is now the only sane approach, and it is a hosting decision rather than a design one.
When it lapses, the failure is total and public. A browser does not show a smaller padlock. It shows a full-page interstitial telling the visitor the connection is not private, which for an industrial buyer checking a supplier reads as a security incident. In the same review, 5 of the 54 sites had a certificate failure of exactly that kind.
Plugins are the other recurring cost, and the one most often cancelled to save money. Patchstack’s 2026 whitepaper recorded 11,334 new vulnerabilities in the WordPress ecosystem during 2025, 91% of them in plugins rather than core. More usefully for anyone deciding whether maintenance is worth paying for: 46% of those vulnerabilities did not receive a fix from the developer before public disclosure. Updating on a schedule is necessary and it is not sufficient, which is why a maintenance plan that consists solely of clicking update is not maintenance.
The corpus bears this out at the blunt end. 12 of the 54 sites were running an outdated or end-of-life CMS or plugin, including two separate Joomla 1.5 installations, a platform that reached end of life in September 2012. Those are not sites that got unlucky. They are sites where nobody was responsible.
What does it cost to not maintain a website?
The honest answer is that most of the time it costs nothing, right up until it costs everything, and the distribution is what makes it hard to budget for.
The measurable version is about speed. Patchstack’s exploitation data shows that roughly half of high-impact vulnerabilities are attacked within 24 hours of disclosure, and for the most heavily targeted the weighted median time to first exploitation is five hours. That is the window a quarterly update habit is working inside. The usual outcome on a B2B brochure site is not a ransom note, it is injected spam. Pages selling something unrelated, indexed under your domain, found weeks later when a customer asks why your website is advertising counterfeit goods. Cleaning that costs more than a year of maintenance, and the search damage outlasts the cleanup.
The unmeasurable version is worse and more common. Nothing gets hacked. The site simply drifts. A contact form silently stops delivering because a mail plugin changed its defaults, and nobody notices because the failure looks identical to a quiet month. Across the same 54 sites, 7 had a contact page or navigation link returning a server error or a 404, and 19 of the 23 sites whose footer we examined carried an out-of-date copyright year, with the oldest sitting at 2012. A stale footer is cosmetic on its own. What it reliably indicates is that nobody has looked.
Our plans start from S$200 a month on six or twelve month terms, covering security and plugin updates, backups, uptime monitoring and minor page and layout changes. What moves that number is how often the site changes and how much of it there is. A five-page capability site that gets a project added twice a year is not the same commitment as a fifty-page site with a product catalogue and three languages, and quoting them the same way would be dishonest to one of them.
Not every site needs a plan. A brochure site that rarely changes can run for a long time on occasional attention. A site handling enquiries, bookings or product data is worth maintaining properly, because a broken form is invisible until someone tells you, and industrial buyers do not tell you. They email your competitor.
How to budget for it without being sold a subscription
Ask for the running costs in writing at proposal stage, not at handover. Any studio that cannot tell you what the site will cost to run in year two has not thought about year two.
Then ask four things. Where are the backups stored and when was a restore last tested. Who holds the domain registrar account and the DNS. Which plugins carry annual licences and what breaks when one lapses. And what specifically is excluded from the maintenance scope, because the exclusions are the honest part of any plan.
We present hosting, domain and maintenance together rather than as separate upsells because they are one decision, not three. The site is a piece of infrastructure that happens to look like a marketing asset. When we rebuilt Towa Marine, whose entire proposition rests on being reachable when a vessel has a refrigeration failure, the ongoing question was never design. It was whether the thing stays up. Same for Hong Hock Global, where the site carries prequalification content that a PUB officer or main contractor may open at any point in a tender window.
Every figure here is a starting point and every one of them moves. What does not move is that they exist. You are paying them either as a line item you chose or as a problem you did not.

